control-api is hosted outside the cloud and validators reach it directly,
so it sees the floating IP as the connection's source address. New open
route GET /api/v1/agents/{id}/observed-ip returns that address (taken only
from the TCP peer; forwarding headers are ignored so a validator cannot
forge it).
The agent gets self_check.methods, a priority-ordered list of ip_echo
(unchanged) and control_api; the default stays [ip_echo]. The self-check
passes when any method confirms the address; the next method is tried on
no answer and on a mismatch. Each method has its own timeout so a hung
first method cannot starve the fallback, and control_api uses a new TCP
connection per call (a connection opened before the floating IP was
attached would keep reporting the old address).
Also: docker agent template/env, example config, docs, plan in
docs/changes, e2e script switch E2E_SELF_CHECK_METHODS, rebuilt
bin/control-api and bin/validator-agent.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
122 lines
4.2 KiB
Go
122 lines
4.2 KiB
Go
package config
|
|
|
|
import (
|
|
"bytes"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
func TestLoadControlAPIScanDefaults(t *testing.T) {
|
|
path := filepath.Join(t.TempDir(), "c.yaml")
|
|
if err := os.WriteFile(path, []byte("server:\n listen_addr: \":8080\"\n"), 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
c, err := LoadControlAPI(path)
|
|
if err != nil {
|
|
t.Fatalf("load: %v", err)
|
|
}
|
|
if c.OpenStack.ListPageSize != 200 || c.OpenStack.RequestTimeoutSeconds != 60 ||
|
|
c.OpenStack.ListPageRetries != 5 || c.Orchestrator.FIPScanTimeoutSeconds != 1800 {
|
|
t.Fatalf("unexpected defaults: openstack=%+v orchestrator=%+v", c.OpenStack, c.Orchestrator)
|
|
}
|
|
}
|
|
|
|
func TestLoadControlAPIScanOverrides(t *testing.T) {
|
|
path := filepath.Join(t.TempDir(), "c.yaml")
|
|
yaml := "openstack:\n list_page_size: 50\n request_timeout_seconds: 10\n list_page_retries: -1\n" +
|
|
"orchestrator:\n fip_scan_timeout_seconds: 99\n"
|
|
if err := os.WriteFile(path, []byte(yaml), 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
c, err := LoadControlAPI(path)
|
|
if err != nil {
|
|
t.Fatalf("load: %v", err)
|
|
}
|
|
if c.OpenStack.ListPageSize != 50 || c.OpenStack.RequestTimeoutSeconds != 10 ||
|
|
c.OpenStack.ListPageRetries != -1 || c.Orchestrator.FIPScanTimeoutSeconds != 99 {
|
|
t.Fatalf("overrides lost: openstack=%+v orchestrator=%+v", c.OpenStack, c.Orchestrator)
|
|
}
|
|
}
|
|
|
|
// The shipped example must load and carry the scan settings, and the rxprod
|
|
// copy must stay byte-identical to it.
|
|
func TestControlAPIExampleConfigs(t *testing.T) {
|
|
c, err := LoadControlAPI("../../configs/control-api.example.yaml")
|
|
if err != nil {
|
|
t.Fatalf("load example: %v", err)
|
|
}
|
|
if c.OpenStack.ListPageSize != 200 || c.Orchestrator.FIPScanTimeoutSeconds != 1800 {
|
|
t.Fatalf("example scan settings: %+v %+v", c.OpenStack, c.Orchestrator)
|
|
}
|
|
a, err := os.ReadFile("../../configs/control-api.example.yaml")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
b, err := os.ReadFile("../../rxprod-compose/sources/control-api.example.yaml")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !bytes.Equal(a, b) {
|
|
t.Fatalf("rxprod-compose/sources/control-api.example.yaml differs from configs/control-api.example.yaml")
|
|
}
|
|
if _, err := LoadControlAPI("../../deploy/docker/control-api/control-api.docker.example.yaml"); err != nil {
|
|
t.Fatalf("load docker example: %v", err)
|
|
}
|
|
}
|
|
|
|
func writeAgentConfig(t *testing.T, selfCheck string) string {
|
|
t.Helper()
|
|
path := filepath.Join(t.TempDir(), "agent.yaml")
|
|
body := "validator_id: v1\ncontrol_api_url: http://x\nself_check:\n" + selfCheck
|
|
if err := os.WriteFile(path, []byte(body), 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return path
|
|
}
|
|
|
|
func TestLoadValidatorAgentSelfCheckMethods(t *testing.T) {
|
|
// No methods key: the historical behaviour, ip_echo only.
|
|
c, err := LoadValidatorAgent(writeAgentConfig(t, " timeout_seconds: 5\n"))
|
|
if err != nil {
|
|
t.Fatalf("load: %v", err)
|
|
}
|
|
if len(c.SelfCheck.Methods) != 1 || c.SelfCheck.Methods[0] != SelfCheckIPEcho {
|
|
t.Fatalf("default methods = %v, want [ip_echo]", c.SelfCheck.Methods)
|
|
}
|
|
|
|
// Order is the priority and must be kept.
|
|
c, err = LoadValidatorAgent(writeAgentConfig(t, " methods: [control_api, ip_echo]\n"))
|
|
if err != nil {
|
|
t.Fatalf("load: %v", err)
|
|
}
|
|
if got := c.SelfCheck.Methods; len(got) != 2 || got[0] != SelfCheckControlAPI || got[1] != SelfCheckIPEcho {
|
|
t.Fatalf("methods = %v, want [control_api ip_echo]", got)
|
|
}
|
|
|
|
// An unknown method is a configuration error, not a silent no-op.
|
|
if _, err := LoadValidatorAgent(writeAgentConfig(t, " methods: [control_api, ipecho]\n")); err == nil {
|
|
t.Fatal("expected an error for an unknown self-check method")
|
|
}
|
|
}
|
|
|
|
// The shipped agent example must load, and the rxprod copy must stay
|
|
// byte-identical to it.
|
|
func TestValidatorAgentExampleConfig(t *testing.T) {
|
|
c, err := LoadValidatorAgent("../../configs/validator-agent.example.yaml")
|
|
if err != nil {
|
|
t.Fatalf("load example: %v", err)
|
|
}
|
|
if got := c.SelfCheck.Methods; len(got) != 2 || got[0] != SelfCheckControlAPI {
|
|
t.Fatalf("example methods = %v", got)
|
|
}
|
|
a, _ := os.ReadFile("../../configs/validator-agent.example.yaml")
|
|
b, err := os.ReadFile("../../rxprod-compose/sources/validator-agent.example.yaml")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !bytes.Equal(a, b) {
|
|
t.Fatal("rxprod-compose/sources/validator-agent.example.yaml differs from configs/validator-agent.example.yaml")
|
|
}
|
|
}
|