Add tomswall agent (control-plane pull mode)

Add `tomswall agent`: it pulls this device's compiled config from tomswallapi,
differentially applies it, and reports the applied generation. It caches the
last known-good config and, when the control plane is unreachable, keeps
applying that cache — it never fails closed.

- internal/agent: rendered-config types, HTTP client (fetch + status report),
  on-disk cache, on-device DNS resolver for dns sets (honors the device's
  configured resolver, fail-safe on lookup failure), and the pull-apply-report
  loop behind a mockable Applier.
- Translate the interface-agnostic, address-matched rendered model into native
  tomswall config using the "all:<cidr>" any-interface source/dest form, reusing
  the existing differential engine. Named-set members are inlined as concrete
  addresses (native nft set references are a tracked follow-up).
- cmd/tomswall: wire the `agent` subcommand (flags + TOMSWALL_* env, --once).
- Unit tests: translation, cache, and the don't-fail-closed fallback loop.
- Add DESIGN.md documenting the control-plane architecture.
This commit is contained in:
benvin
2026-07-20 20:05:49 +10:00
parent 8d9a76c751
commit e0f54ef320
20 changed files with 1414 additions and 82 deletions
+6 -6
View File
@@ -915,9 +915,9 @@ func TestCompile_RateLimit(t *testing.T) {
{
Action: config.RuleAccept,
Source: "net",
Dest: "fw",
Proto: "tcp",
DPort: config.PortSpec{"22"},
Dest: "fw",
Proto: "tcp",
DPort: config.PortSpec{"22"},
RateLimit: "10/sec:5",
},
},
@@ -1353,9 +1353,9 @@ func TestCompile_ConnLimit(t *testing.T) {
{
Action: config.RuleAccept,
Source: "net",
Dest: "fw",
Proto: "tcp",
DPort: config.PortSpec{"22"},
Dest: "fw",
Proto: "tcp",
DPort: config.PortSpec{"22"},
ConnLimit: "20",
},
},