Add tomswall agent (control-plane pull mode)

Add `tomswall agent`: it pulls this device's compiled config from tomswallapi,
differentially applies it, and reports the applied generation. It caches the
last known-good config and, when the control plane is unreachable, keeps
applying that cache — it never fails closed.

- internal/agent: rendered-config types, HTTP client (fetch + status report),
  on-disk cache, on-device DNS resolver for dns sets (honors the device's
  configured resolver, fail-safe on lookup failure), and the pull-apply-report
  loop behind a mockable Applier.
- Translate the interface-agnostic, address-matched rendered model into native
  tomswall config using the "all:<cidr>" any-interface source/dest form, reusing
  the existing differential engine. Named-set members are inlined as concrete
  addresses (native nft set references are a tracked follow-up).
- cmd/tomswall: wire the `agent` subcommand (flags + TOMSWALL_* env, --once).
- Unit tests: translation, cache, and the don't-fail-closed fallback loop.
- Add DESIGN.md documenting the control-plane architecture.
This commit is contained in:
benvin
2026-07-20 20:05:49 +10:00
parent 8d9a76c751
commit e0f54ef320
20 changed files with 1414 additions and 82 deletions
+13 -13
View File
@@ -32,15 +32,15 @@ type Config struct {
ProxyNDP []ProxyNDP `yaml:"proxyndp,omitempty"`
Routes []StaticRoute `yaml:"routes,omitempty"`
ArpRules []ArpRule `yaml:"arprules,omitempty"`
Accounting []AccountingRule `yaml:"accounting,omitempty"`
Mangle []MangleRule `yaml:"mangle,omitempty"`
Maclist []MaclistEntry `yaml:"maclist,omitempty"`
TCDevices []TCDevice `yaml:"tcdevices,omitempty"`
TCClasses []TCClass `yaml:"tcclasses,omitempty"`
TCFilters []TCFilter `yaml:"tcfilters,omitempty"`
TCInterfaces []TCInterface `yaml:"tcinterfaces,omitempty"`
TCPriorities []TCPriority `yaml:"tcpriority,omitempty"`
Secmarks []SecmarkRule `yaml:"secmarks,omitempty"`
Accounting []AccountingRule `yaml:"accounting,omitempty"`
Mangle []MangleRule `yaml:"mangle,omitempty"`
Maclist []MaclistEntry `yaml:"maclist,omitempty"`
TCDevices []TCDevice `yaml:"tcdevices,omitempty"`
TCClasses []TCClass `yaml:"tcclasses,omitempty"`
TCFilters []TCFilter `yaml:"tcfilters,omitempty"`
TCInterfaces []TCInterface `yaml:"tcinterfaces,omitempty"`
TCPriorities []TCPriority `yaml:"tcpriority,omitempty"`
Secmarks []SecmarkRule `yaml:"secmarks,omitempty"`
}
type AddressFamily string
@@ -52,10 +52,10 @@ const (
)
type Settings struct {
AddressFamily AddressFamily `yaml:"address_family,omitempty"`
IPForwarding bool `yaml:"ip_forwarding"`
LogLevel string `yaml:"log_level"`
TableName string `yaml:"table_name"`
AddressFamily AddressFamily `yaml:"address_family,omitempty"`
IPForwarding bool `yaml:"ip_forwarding"`
LogLevel string `yaml:"log_level"`
TableName string `yaml:"table_name"`
// When true, auto-generate CONTINUE policies for sub-zones to their parent zones.
ImplicitContinue bool `yaml:"implicit_continue,omitempty"`