control-api is hosted outside the cloud and validators reach it directly,
so it sees the floating IP as the connection's source address. New open
route GET /api/v1/agents/{id}/observed-ip returns that address (taken only
from the TCP peer; forwarding headers are ignored so a validator cannot
forge it).
The agent gets self_check.methods, a priority-ordered list of ip_echo
(unchanged) and control_api; the default stays [ip_echo]. The self-check
passes when any method confirms the address; the next method is tried on
no answer and on a mismatch. Each method has its own timeout so a hung
first method cannot starve the fallback, and control_api uses a new TCP
connection per call (a connection opened before the floating IP was
attached would keep reporting the old address).
Also: docker agent template/env, example config, docs, plan in
docs/changes, e2e script switch E2E_SELF_CHECK_METHODS, rebuilt
bin/control-api and bin/validator-agent.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
104 lines
2.6 KiB
Go
104 lines
2.6 KiB
Go
package httpapi
|
|
|
|
// Request/response bodies for the /api/v1 surface. Kept in one file since
|
|
// they're small and mostly 1:1 with a single handler each.
|
|
|
|
type registerAgentRequest struct {
|
|
ValidatorID string `json:"validator_id"`
|
|
Hostname string `json:"hostname"`
|
|
AgentVersion string `json:"agent_version"`
|
|
}
|
|
|
|
type registerAgentResponse struct {
|
|
OK bool `json:"ok"`
|
|
PollIntervalSeconds int `json:"poll_interval_seconds"`
|
|
}
|
|
|
|
type heartbeatRequest struct {
|
|
LocalState string `json:"local_state"`
|
|
CurrentIPAddress string `json:"current_ip_address,omitempty"`
|
|
}
|
|
|
|
type okResponse struct {
|
|
OK bool `json:"ok"`
|
|
}
|
|
|
|
type observedIPResponse struct {
|
|
IP string `json:"ip"`
|
|
Source string `json:"source"`
|
|
}
|
|
|
|
type checkConfigDTO struct {
|
|
Type string `json:"type"`
|
|
Targets []string `json:"targets"`
|
|
}
|
|
|
|
type assignmentResponse struct {
|
|
IPID int64 `json:"ip_id"`
|
|
IPAddress string `json:"ip_address"`
|
|
Phase string `json:"phase"`
|
|
CheckConfig []checkConfigDTO `json:"check_config,omitempty"`
|
|
}
|
|
|
|
type selfCheckRequest struct {
|
|
IPID int64 `json:"ip_id"`
|
|
DetectedEgress string `json:"detected_egress_ip"`
|
|
Success bool `json:"success"`
|
|
Detail string `json:"detail"`
|
|
}
|
|
|
|
type agentEventRequest struct {
|
|
EventType string `json:"event_type"`
|
|
IPID *int64 `json:"ip_id,omitempty"`
|
|
Payload string `json:"payload,omitempty"`
|
|
}
|
|
|
|
type checkResultDTO struct {
|
|
IPID int64 `json:"ip_id"`
|
|
CheckType string `json:"check_type"`
|
|
Target string `json:"target,omitempty"`
|
|
Success bool `json:"success"`
|
|
LatencyMS int64 `json:"latency_ms"`
|
|
Detail string `json:"detail,omitempty"`
|
|
CheckedAt string `json:"checked_at"`
|
|
}
|
|
|
|
type agentResultsRequest struct {
|
|
Results []checkResultDTO `json:"results"`
|
|
}
|
|
|
|
type agentCompleteRequest struct {
|
|
IPID int64 `json:"ip_id"`
|
|
}
|
|
|
|
type registerProberRequest struct {
|
|
SiteID string `json:"site_id"`
|
|
Hostname string `json:"hostname"`
|
|
}
|
|
|
|
type proberAssignment struct {
|
|
IPID int64 `json:"ip_id"`
|
|
IPAddress string `json:"ip_address"`
|
|
Ports []int `json:"ports"`
|
|
ICMP bool `json:"icmp"`
|
|
}
|
|
|
|
type proberResultDTO struct {
|
|
IPID int64 `json:"ip_id"`
|
|
IPAddress string `json:"ip_address"`
|
|
CheckType string `json:"check_type"`
|
|
Success bool `json:"success"`
|
|
LatencyMS int64 `json:"latency_ms"`
|
|
Detail string `json:"detail,omitempty"`
|
|
CheckedAt string `json:"checked_at"`
|
|
Complete bool `json:"complete"`
|
|
}
|
|
|
|
type proberResultsRequest struct {
|
|
Results []proberResultDTO `json:"results"`
|
|
}
|
|
|
|
type errorResponse struct {
|
|
Error string `json:"error"`
|
|
}
|