feat(firewall-apply): gather peers with no cached facts and fail closed #10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/firewall-peer-facts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
A restricted firewall rule (
swarm,gluster,ai-stack) derives itssources from the facts of its
from_groupmembers. A member outside thecurrent play — the rest of a cluster under
-e target=<host>, or everyother member while
serialruns the first host alone — was read from thefact cache, and one with nothing cached was silently filtered out. The
result was a chain rendered without the peers, cutting the host out of
its own cluster, unless someone had warmed the cache by hand first.
What changed
firewall-applygathers every peerwith no facts (never gathered, or expired past
fact_caching_timeout)through a read-only, delegated
ansible.builtin.setup. The facts land inthe per-inventory cache, so later batches and runs need no connection.
It runs under
--checktoo, so the preview shows the real table.naming every missing peer; the table already loaded stays as it was.
firewall_apply_absent_peers(default[], pass with-e) namespeers known to be down: they are neither gathered nor waited for, and
the rules narrow to the peers that remain.
ai-stack READMEs and
ADVANCED_USAGE.md; the firewall-apply README's"Peer addresses" section now owns the mechanism.
Behaviour change: a cluster member that is down and not listed in
firewall_apply_absent_peersnow stops the run instead of being droppedfrom the rules. In the first
serialbatch that ends the play for thebatches after it.
Verification
make checkpasses: lint at the production profile, syntax and allgates. The
peersgate gains two cases: a peer with nothing cached isgathered and cached, and an unreachable peer fails the collect by name.
make test,make verify,make propagation(no podman inthe environment used). Not yet run against a real inventory.
Risks and follow-ups
make verify, then--check --diff --tags firewallwith-e target=<one cluster member>against a real tenant. Expect thegather step for the other members and an unchanged peer chain.
back or passed in
firewall_apply_absent_peers.