Compare commits
12 Commits
a739d87597
..
v0.1.0
| Author | SHA1 | Date | |
|---|---|---|---|
| fff9967da0 | |||
| 4b703f854c | |||
| 8ae09c0941 | |||
| 6d16035a0b | |||
| 09f39ec9fe | |||
| b94cb96510 | |||
| 9fd300652f | |||
| 59e8320dda | |||
| 17b2130047 | |||
| 06928bc150 | |||
| 6f1ac9a1ae | |||
| 66265764df |
@@ -90,6 +90,12 @@ func (a *Agent) applyConfig(ctx context.Context, rc *RenderedConfig, report bool
|
||||
if err := a.Client.ReportStatus(ctx, rc.Generation); err != nil {
|
||||
slog.Warn("agent: reporting status failed", "err", err)
|
||||
}
|
||||
// Report the FIB so the control plane can scope router enforcement.
|
||||
if fib := CollectFIB(ctx); len(fib) > 0 {
|
||||
if err := a.Client.ReportRoutes(ctx, fib); err != nil {
|
||||
slog.Warn("agent: reporting routes failed", "err", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -84,6 +84,41 @@ func TestTranslateBareZone(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestTranslateNATTier(t *testing.T) {
|
||||
prob := 0.5
|
||||
rc := &RenderedConfig{
|
||||
Enforcing: true,
|
||||
SNAT: []RenderedSNAT{
|
||||
{Action: "masquerade", Source: []string{"10.1.0.0/24"}, Egress: []string{"eth0", "eth3"}},
|
||||
{Action: "snat", Source: []string{"10.2.0.0/24"}, Egress: []string{"eth0"}, Address: "203.0.113.1", Probability: &prob},
|
||||
},
|
||||
Netmap: []RenderedNetmap{{Type: "dnat", FromNet: "10.0.0.0/24", ToNet: "192.168.1.0/24", Interface: "eth0"}},
|
||||
NAT: []RenderedNAT{{External: "203.0.113.10", Internal: "10.1.0.10", Interface: "eth0"}},
|
||||
}
|
||||
cfg, err := Translate(rc)
|
||||
if err != nil {
|
||||
t.Fatalf("Translate: %v", err)
|
||||
}
|
||||
|
||||
// masquerade with two egress interfaces expands to two rules; snat adds one.
|
||||
if len(cfg.SNAT) != 3 {
|
||||
t.Fatalf("expected 3 SNAT rules, got %d: %+v", len(cfg.SNAT), cfg.SNAT)
|
||||
}
|
||||
if cfg.SNAT[0].Action != config.SNATMasquerade || cfg.SNAT[0].Source != "10.1.0.0/24" || cfg.SNAT[0].Dest != "eth0" {
|
||||
t.Errorf("unexpected masquerade rule: %+v", cfg.SNAT[0])
|
||||
}
|
||||
if cfg.SNAT[2].Address != "203.0.113.1" || cfg.SNAT[2].Probability != 0.5 {
|
||||
t.Errorf("snat address/probability not carried: %+v", cfg.SNAT[2])
|
||||
}
|
||||
|
||||
if len(cfg.Netmap) != 1 || cfg.Netmap[0].Net1 != "10.0.0.0/24" || cfg.Netmap[0].Net2 != "192.168.1.0/24" || cfg.Netmap[0].Interface != "eth0" {
|
||||
t.Errorf("netmap not translated: %+v", cfg.Netmap)
|
||||
}
|
||||
if len(cfg.StaticNAT) != 1 || cfg.StaticNAT[0].External != "203.0.113.10" || cfg.StaticNAT[0].Internal != "10.1.0.10" {
|
||||
t.Errorf("static nat not translated: %+v", cfg.StaticNAT)
|
||||
}
|
||||
}
|
||||
|
||||
func TestTranslateRejectsUnknownAction(t *testing.T) {
|
||||
rc := &RenderedConfig{Enforcing: true, Rules: []RenderedRule{{Action: "bogus"}}}
|
||||
if _, err := Translate(rc); err == nil {
|
||||
|
||||
@@ -70,6 +70,30 @@ func ParseRendered(body []byte) (*RenderedConfig, error) {
|
||||
return &cfg, nil
|
||||
}
|
||||
|
||||
// ReportRoutes reports the device's reachable prefixes (FIB) so the control
|
||||
// plane can scope which routers enforce a rule.
|
||||
func (c *Client) ReportRoutes(ctx context.Context, prefixes []string) error {
|
||||
url := fmt.Sprintf("%s/api/v1/devices/%s/routes", c.BaseURL, c.Device)
|
||||
payload, _ := json.Marshal(map[string][]string{"prefixes": prefixes})
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, bytes.NewReader(payload))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
req.Header.Set("Authorization", "Bearer "+c.Token)
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
|
||||
resp, err := c.HTTP.Do(req)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
io.Copy(io.Discard, io.LimitReader(resp.Body, 1<<16))
|
||||
if resp.StatusCode >= 400 {
|
||||
return fmt.Errorf("report routes: %d", resp.StatusCode)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// ReportStatus tells the control plane which generation this device has applied.
|
||||
func (c *Client) ReportStatus(ctx context.Context, generation int64) error {
|
||||
url := fmt.Sprintf("%s/api/v1/devices/%s/status", c.BaseURL, c.Device)
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
package agent
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os/exec"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// CollectFIB returns the device's reachable prefixes from the kernel FIB — which
|
||||
// includes FRR-installed routes — by shelling out to `ip route`. The control
|
||||
// plane uses these to scope which routers enforce a rule. On a host without
|
||||
// iproute2 it returns nil, and the control plane falls back to over-approximation.
|
||||
func CollectFIB(ctx context.Context) []string {
|
||||
var prefixes []string
|
||||
for _, spec := range []struct {
|
||||
args []string
|
||||
def string
|
||||
}{
|
||||
{[]string{"route", "show"}, "0.0.0.0/0"},
|
||||
{[]string{"-6", "route", "show"}, "::/0"},
|
||||
} {
|
||||
out, err := exec.CommandContext(ctx, "ip", spec.args...).Output()
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
prefixes = append(prefixes, parseRoutes(string(out), spec.def)...)
|
||||
}
|
||||
return dedup(prefixes)
|
||||
}
|
||||
|
||||
// routeTypeKeywords are leading tokens in `ip route` output that precede the
|
||||
// actual destination (e.g. "unreachable 10.0.0.0/8").
|
||||
var routeTypeKeywords = map[string]bool{
|
||||
"unreachable": true, "blackhole": true, "prohibit": true, "throw": true,
|
||||
"local": true, "broadcast": true, "multicast": true, "anycast": true, "nat": true,
|
||||
}
|
||||
|
||||
// parseRoutes extracts destination prefixes from `ip route show` output.
|
||||
// defaultPrefix is substituted for a "default" route (family-specific).
|
||||
func parseRoutes(output, defaultPrefix string) []string {
|
||||
var out []string
|
||||
for _, line := range strings.Split(output, "\n") {
|
||||
fields := strings.Fields(line)
|
||||
if len(fields) == 0 {
|
||||
continue
|
||||
}
|
||||
dst := fields[0]
|
||||
// ECMP routes emit continuation "nexthop ..." lines with no destination.
|
||||
if dst == "nexthop" {
|
||||
continue
|
||||
}
|
||||
if routeTypeKeywords[dst] {
|
||||
if len(fields) < 2 {
|
||||
continue
|
||||
}
|
||||
dst = fields[1]
|
||||
}
|
||||
if dst == "default" {
|
||||
out = append(out, defaultPrefix)
|
||||
continue
|
||||
}
|
||||
out = append(out, normalizePrefix(dst))
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// normalizePrefix turns a bare host address into a host prefix (/32 or /128).
|
||||
func normalizePrefix(dst string) string {
|
||||
if strings.Contains(dst, "/") {
|
||||
return dst
|
||||
}
|
||||
if strings.Contains(dst, ":") {
|
||||
return dst + "/128"
|
||||
}
|
||||
return dst + "/32"
|
||||
}
|
||||
@@ -0,0 +1,55 @@
|
||||
package agent
|
||||
|
||||
import (
|
||||
"reflect"
|
||||
"sort"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestParseRoutesV4(t *testing.T) {
|
||||
// Representative `ip route show` output, including a default route, an ECMP
|
||||
// route with nexthop continuation lines, a connected route, and a host route.
|
||||
out := `default via 10.0.0.1 dev eth0 proto dhcp
|
||||
10.1.0.0/24 dev eth1 proto kernel scope link src 10.1.0.5
|
||||
10.4.0.0/24 proto bgp metric 20
|
||||
nexthop via 10.0.0.2 dev eth0 weight 1
|
||||
nexthop via 10.0.0.3 dev eth0 weight 1
|
||||
192.0.2.7 dev eth2 scope link
|
||||
blackhole 172.16.0.0/12
|
||||
`
|
||||
got := parseRoutes(out, "0.0.0.0/0")
|
||||
sort.Strings(got)
|
||||
want := []string{"0.0.0.0/0", "10.1.0.0/24", "10.4.0.0/24", "172.16.0.0/12", "192.0.2.7/32"}
|
||||
sort.Strings(want)
|
||||
if !reflect.DeepEqual(got, want) {
|
||||
t.Errorf("parseRoutes v4 = %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseRoutesV6(t *testing.T) {
|
||||
out := `default via fe80::1 dev eth0 metric 1024
|
||||
2001:db8:1::/64 dev eth1 proto kernel metric 256
|
||||
2001:db8:4::5 dev eth2
|
||||
`
|
||||
got := parseRoutes(out, "::/0")
|
||||
sort.Strings(got)
|
||||
want := []string{"2001:db8:1::/64", "2001:db8:4::5/128", "::/0"}
|
||||
sort.Strings(want)
|
||||
if !reflect.DeepEqual(got, want) {
|
||||
t.Errorf("parseRoutes v6 = %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestNormalizePrefix(t *testing.T) {
|
||||
cases := map[string]string{
|
||||
"10.1.0.0/24": "10.1.0.0/24",
|
||||
"10.1.0.5": "10.1.0.5/32",
|
||||
"2001:db8::1": "2001:db8::1/128",
|
||||
"2001:db8::/32": "2001:db8::/32",
|
||||
}
|
||||
for in, want := range cases {
|
||||
if got := normalizePrefix(in); got != want {
|
||||
t.Errorf("normalizePrefix(%q) = %q, want %q", in, got, want)
|
||||
}
|
||||
}
|
||||
}
|
||||
+260
-10
@@ -8,16 +8,266 @@ package agent
|
||||
// GET /api/v1/devices/{name}/config. It mirrors the control plane's compiler
|
||||
// output: interface-agnostic, address-matched rules plus named sets.
|
||||
type RenderedConfig struct {
|
||||
Generation int64 `yaml:"generation" json:"generation"`
|
||||
Device string `yaml:"device" json:"device"`
|
||||
Class string `yaml:"class" json:"class"`
|
||||
Enforcing bool `yaml:"enforcing" json:"enforcing"`
|
||||
Settings RenderedSettings `yaml:"settings" json:"settings"`
|
||||
Resolver []string `yaml:"resolver,omitempty" json:"resolver,omitempty"`
|
||||
Bindings map[string][]string `yaml:"bindings,omitempty" json:"bindings,omitempty"` // zone -> interfaces
|
||||
Sets []RenderedSet `yaml:"sets,omitempty" json:"sets,omitempty"`
|
||||
Rules []RenderedRule `yaml:"rules,omitempty" json:"rules,omitempty"`
|
||||
Policies []RenderedPolicy `yaml:"policies,omitempty" json:"policies,omitempty"`
|
||||
Generation int64 `yaml:"generation" json:"generation"`
|
||||
Device string `yaml:"device" json:"device"`
|
||||
Class string `yaml:"class" json:"class"`
|
||||
Enforcing bool `yaml:"enforcing" json:"enforcing"`
|
||||
Settings RenderedSettings `yaml:"settings" json:"settings"`
|
||||
Resolver []string `yaml:"resolver,omitempty" json:"resolver,omitempty"`
|
||||
Bindings map[string][]string `yaml:"bindings,omitempty" json:"bindings,omitempty"` // zone -> interfaces
|
||||
Sets []RenderedSet `yaml:"sets,omitempty" json:"sets,omitempty"`
|
||||
Rules []RenderedRule `yaml:"rules,omitempty" json:"rules,omitempty"`
|
||||
Policies []RenderedPolicy `yaml:"policies,omitempty" json:"policies,omitempty"`
|
||||
SNAT []RenderedSNAT `yaml:"snat,omitempty" json:"snat,omitempty"`
|
||||
Netmap []RenderedNetmap `yaml:"netmap,omitempty" json:"netmap,omitempty"`
|
||||
NAT []RenderedNAT `yaml:"nat,omitempty" json:"nat,omitempty"`
|
||||
Hosts []RenderedHost `yaml:"hosts,omitempty" json:"hosts,omitempty"`
|
||||
Providers []RenderedProvider `yaml:"providers,omitempty" json:"providers,omitempty"`
|
||||
Routes []RenderedRoute `yaml:"routes,omitempty" json:"routes,omitempty"`
|
||||
RoutingRules []RenderedRoutingRule `yaml:"routing_rules,omitempty" json:"routing_rules,omitempty"`
|
||||
Tunnels []RenderedTunnel `yaml:"tunnels,omitempty" json:"tunnels,omitempty"`
|
||||
StoppedRules []RenderedStoppedRule `yaml:"stopped_rules,omitempty" json:"stopped_rules,omitempty"`
|
||||
ProxyARP []RenderedProxy `yaml:"proxy_arp,omitempty" json:"proxy_arp,omitempty"`
|
||||
ProxyNDP []RenderedProxy `yaml:"proxy_ndp,omitempty" json:"proxy_ndp,omitempty"`
|
||||
ArpRules []RenderedArpRule `yaml:"arp_rules,omitempty" json:"arp_rules,omitempty"`
|
||||
Maclist []RenderedMaclist `yaml:"maclist,omitempty" json:"maclist,omitempty"`
|
||||
Mangle []RenderedMangle `yaml:"mangle,omitempty" json:"mangle,omitempty"`
|
||||
Accounting []RenderedAccounting `yaml:"accounting,omitempty" json:"accounting,omitempty"`
|
||||
TCDevices []RenderedTCDevice `yaml:"tc_devices,omitempty" json:"tc_devices,omitempty"`
|
||||
TCClasses []RenderedTCClass `yaml:"tc_classes,omitempty" json:"tc_classes,omitempty"`
|
||||
TCFilters []RenderedTCFilter `yaml:"tc_filters,omitempty" json:"tc_filters,omitempty"`
|
||||
TCInterfaces []RenderedTCInterface `yaml:"tc_interfaces,omitempty" json:"tc_interfaces,omitempty"`
|
||||
TCPriorities []RenderedTCPriority `yaml:"tc_priorities,omitempty" json:"tc_priorities,omitempty"`
|
||||
Blrules []RenderedBlrule `yaml:"blrules,omitempty" json:"blrules,omitempty"`
|
||||
Conntrack []RenderedConntrack `yaml:"conntrack,omitempty" json:"conntrack,omitempty"`
|
||||
Secmarks []RenderedSecmark `yaml:"secmarks,omitempty" json:"secmarks,omitempty"`
|
||||
Vars map[string]string `yaml:"vars,omitempty" json:"vars,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedBlrule struct {
|
||||
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Log string `yaml:"log,omitempty" json:"log,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedConntrack struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
|
||||
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
|
||||
User string `yaml:"user,omitempty" json:"user,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedSecmark struct {
|
||||
Secmark string `yaml:"secmark" json:"secmark"`
|
||||
Chain string `yaml:"chain" json:"chain"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedMangle struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
|
||||
MarkValue string `yaml:"mark_value,omitempty" json:"mark_value,omitempty"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
User string `yaml:"user,omitempty" json:"user,omitempty"`
|
||||
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
|
||||
Length string `yaml:"length,omitempty" json:"length,omitempty"`
|
||||
TOS string `yaml:"tos,omitempty" json:"tos,omitempty"`
|
||||
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
|
||||
Probability *float64 `yaml:"probability,omitempty" json:"probability,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedAccounting struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Section string `yaml:"section,omitempty" json:"section,omitempty"`
|
||||
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTCDevice struct {
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
InBandwidth string `yaml:"in_bandwidth,omitempty" json:"in_bandwidth,omitempty"`
|
||||
OutBandwidth string `yaml:"out_bandwidth,omitempty" json:"out_bandwidth,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTCClass struct {
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
Mark int `yaml:"mark,omitempty" json:"mark,omitempty"`
|
||||
Rate string `yaml:"rate,omitempty" json:"rate,omitempty"`
|
||||
Ceil string `yaml:"ceil,omitempty" json:"ceil,omitempty"`
|
||||
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTCFilter struct {
|
||||
Class string `yaml:"class" json:"class"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
TOS string `yaml:"tos,omitempty" json:"tos,omitempty"`
|
||||
Length int `yaml:"length,omitempty" json:"length,omitempty"`
|
||||
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTCInterface struct {
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
Type string `yaml:"type,omitempty" json:"type,omitempty"`
|
||||
InBandwidth string `yaml:"in_bandwidth,omitempty" json:"in_bandwidth,omitempty"`
|
||||
OutBandwidth string `yaml:"out_bandwidth,omitempty" json:"out_bandwidth,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTCPriority struct {
|
||||
Band int `yaml:"band" json:"band"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Address string `yaml:"address,omitempty" json:"address,omitempty"`
|
||||
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
|
||||
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedTunnel struct {
|
||||
Type string `yaml:"type" json:"type"`
|
||||
Zone string `yaml:"zone" json:"zone"`
|
||||
Gateways []string `yaml:"gateways,omitempty" json:"gateways,omitempty"`
|
||||
GatewayZones []string `yaml:"gateway_zones,omitempty" json:"gateway_zones,omitempty"`
|
||||
Port int `yaml:"port,omitempty" json:"port,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedStoppedRule struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
|
||||
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
|
||||
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedProxy struct {
|
||||
Address string `yaml:"address" json:"address"`
|
||||
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
|
||||
External string `yaml:"external" json:"external"`
|
||||
HaveRoute bool `yaml:"haveroute,omitempty" json:"haveroute,omitempty"`
|
||||
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedArpRule struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
ActionAddress string `yaml:"action_address,omitempty" json:"action_address,omitempty"`
|
||||
ActionMAC string `yaml:"action_mac,omitempty" json:"action_mac,omitempty"`
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Opcode int `yaml:"opcode,omitempty" json:"opcode,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedMaclist struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
MAC string `yaml:"mac,omitempty" json:"mac,omitempty"`
|
||||
Addresses []string `yaml:"addresses,omitempty" json:"addresses,omitempty"`
|
||||
Log string `yaml:"log,omitempty" json:"log,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedHost struct {
|
||||
Zone string `yaml:"zone" json:"zone"`
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
Addresses []string `yaml:"addresses,omitempty" json:"addresses,omitempty"`
|
||||
Exclusions []string `yaml:"exclusions,omitempty" json:"exclusions,omitempty"`
|
||||
Dynamic bool `yaml:"dynamic,omitempty" json:"dynamic,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedProvider struct {
|
||||
Name string `yaml:"name" json:"name"`
|
||||
Number int `yaml:"number" json:"number"`
|
||||
Mark int `yaml:"mark,omitempty" json:"mark,omitempty"`
|
||||
Duplicate string `yaml:"duplicate,omitempty" json:"duplicate,omitempty"`
|
||||
Interface string `yaml:"interface" json:"interface"`
|
||||
Gateway string `yaml:"gateway,omitempty" json:"gateway,omitempty"`
|
||||
Copy []string `yaml:"copy,omitempty" json:"copy,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedRoute struct {
|
||||
Provider string `yaml:"provider,omitempty" json:"provider,omitempty"`
|
||||
Dest string `yaml:"dest" json:"dest"`
|
||||
Gateway string `yaml:"gateway,omitempty" json:"gateway,omitempty"`
|
||||
Oif string `yaml:"oif,omitempty" json:"oif,omitempty"`
|
||||
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedRoutingRule struct {
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
|
||||
Provider string `yaml:"provider" json:"provider"`
|
||||
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
|
||||
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
|
||||
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
// RenderedSNAT is a resolved SNAT/masquerade rule (egress carries interface names).
|
||||
type RenderedSNAT struct {
|
||||
Action string `yaml:"action" json:"action"`
|
||||
Source []string `yaml:"source,omitempty" json:"source,omitempty"`
|
||||
Egress []string `yaml:"egress" json:"egress"`
|
||||
Address string `yaml:"address,omitempty" json:"address,omitempty"`
|
||||
Probability *float64 `yaml:"probability,omitempty" json:"probability,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
// RenderedNetmap is a resolved network-to-network mapping on one interface.
|
||||
type RenderedNetmap struct {
|
||||
Type string `yaml:"type" json:"type"`
|
||||
FromNet string `yaml:"from_net" json:"from_net"`
|
||||
ToNet string `yaml:"to_net" json:"to_net"`
|
||||
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
// RenderedNAT is a resolved one-to-one static NAT on one interface.
|
||||
type RenderedNAT struct {
|
||||
External string `yaml:"external" json:"external"`
|
||||
Internal string `yaml:"internal" json:"internal"`
|
||||
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
|
||||
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
|
||||
}
|
||||
|
||||
type RenderedSettings struct {
|
||||
|
||||
@@ -60,9 +60,192 @@ func Translate(rc *RenderedConfig) (*config.Config, error) {
|
||||
})
|
||||
}
|
||||
|
||||
for _, s := range rc.SNAT {
|
||||
cfg.SNAT = append(cfg.SNAT, translateSNAT(s)...)
|
||||
}
|
||||
for _, n := range rc.Netmap {
|
||||
cfg.Netmap = append(cfg.Netmap, config.Netmap{
|
||||
Type: config.NetmapType(n.Type),
|
||||
Net1: n.FromNet,
|
||||
Net2: n.ToNet,
|
||||
Interface: n.Interface,
|
||||
Comment: n.Comment,
|
||||
})
|
||||
}
|
||||
for _, n := range rc.NAT {
|
||||
cfg.StaticNAT = append(cfg.StaticNAT, config.StaticNAT{
|
||||
External: n.External,
|
||||
Internal: n.Internal,
|
||||
Interface: n.Interface,
|
||||
Comment: n.Comment,
|
||||
})
|
||||
}
|
||||
|
||||
for _, h := range rc.Hosts {
|
||||
cfg.Hosts = append(cfg.Hosts, config.Host{
|
||||
Zone: h.Zone, Interface: h.Interface, Addresses: h.Addresses,
|
||||
Exclusions: h.Exclusions, Dynamic: h.Dynamic,
|
||||
})
|
||||
}
|
||||
for _, p := range rc.Providers {
|
||||
cfg.Providers = append(cfg.Providers, config.Provider{
|
||||
Name: p.Name, Number: p.Number, Mark: p.Mark, Duplicate: p.Duplicate,
|
||||
Interface: p.Interface, Gateway: p.Gateway, Copy: p.Copy,
|
||||
})
|
||||
}
|
||||
for _, r := range rc.Routes {
|
||||
cfg.Routes = append(cfg.Routes, config.StaticRoute{
|
||||
Provider: r.Provider, Dest: r.Dest, Gateway: r.Gateway,
|
||||
Device: r.Oif, Persistent: r.Persistent, Comment: r.Comment,
|
||||
})
|
||||
}
|
||||
for _, r := range rc.RoutingRules {
|
||||
cfg.RoutingRules = append(cfg.RoutingRules, config.RoutingRule{
|
||||
Source: r.Source, Dest: r.Dest, Provider: r.Provider, Priority: r.Priority,
|
||||
Persistent: r.Persistent, Mark: r.Mark, Comment: r.Comment,
|
||||
})
|
||||
}
|
||||
|
||||
for _, t := range rc.Tunnels {
|
||||
cfg.Tunnels = append(cfg.Tunnels, config.Tunnel{
|
||||
Type: t.Type, Zone: t.Zone, Gateways: t.Gateways,
|
||||
GatewayZones: t.GatewayZones, Port: t.Port, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
for _, r := range rc.StoppedRules {
|
||||
cfg.StoppedRules = append(cfg.StoppedRules, config.StoppedRule{
|
||||
Action: config.StoppedAction(r.Action), Source: r.Source, Dest: r.Dest,
|
||||
Proto: r.Proto, DPort: config.PortSpec(r.DPort), SPort: config.PortSpec(r.SPort), Comment: r.Comment,
|
||||
})
|
||||
}
|
||||
for _, p := range rc.ProxyARP {
|
||||
cfg.ProxyARP = append(cfg.ProxyARP, config.ProxyARP{
|
||||
Address: p.Address, Interface: p.Interface, External: p.External,
|
||||
HaveRoute: p.HaveRoute, Persistent: p.Persistent, Comment: p.Comment,
|
||||
})
|
||||
}
|
||||
for _, p := range rc.ProxyNDP {
|
||||
cfg.ProxyNDP = append(cfg.ProxyNDP, config.ProxyNDP{
|
||||
Address: p.Address, Interface: p.Interface, External: p.External,
|
||||
HaveRoute: p.HaveRoute, Persistent: p.Persistent, Comment: p.Comment,
|
||||
})
|
||||
}
|
||||
for _, a := range rc.ArpRules {
|
||||
cfg.ArpRules = append(cfg.ArpRules, config.ArpRule{
|
||||
Action: config.ArpAction(a.Action), ActionAddress: a.ActionAddress, ActionMAC: a.ActionMAC,
|
||||
Source: a.Source, Dest: a.Dest, Opcode: a.Opcode, Comment: a.Comment,
|
||||
})
|
||||
}
|
||||
for _, m := range rc.Maclist {
|
||||
cfg.Maclist = append(cfg.Maclist, config.MaclistEntry{
|
||||
Action: config.MaclistAction(m.Action), Interface: m.Interface, MAC: m.MAC,
|
||||
Addresses: m.Addresses, Log: m.Log, Comment: m.Comment,
|
||||
})
|
||||
}
|
||||
|
||||
for _, m := range rc.Mangle {
|
||||
mr := config.MangleRule{
|
||||
Action: config.MangleAction(m.Action), Chain: config.MangleChain(m.Chain), MarkValue: m.MarkValue,
|
||||
Source: m.Source, Dest: m.Dest, Proto: m.Proto, DPort: config.PortSpec(m.DPort), SPort: config.PortSpec(m.SPort),
|
||||
User: m.User, Mark: m.Mark, Length: m.Length, TOS: m.TOS, Helper: m.Helper, Comment: m.Comment,
|
||||
}
|
||||
if m.Probability != nil {
|
||||
mr.Probability = *m.Probability
|
||||
}
|
||||
cfg.Mangle = append(cfg.Mangle, mr)
|
||||
}
|
||||
for _, a := range rc.Accounting {
|
||||
cfg.Accounting = append(cfg.Accounting, config.AccountingRule{
|
||||
Action: config.AccountingAction(a.Action), Section: config.AccountingSection(a.Section), Chain: a.Chain,
|
||||
Source: a.Source, Dest: a.Dest, Proto: a.Proto, DPort: config.PortSpec(a.DPort), SPort: config.PortSpec(a.SPort),
|
||||
Mark: a.Mark, Comment: a.Comment,
|
||||
})
|
||||
}
|
||||
for _, t := range rc.TCDevices {
|
||||
cfg.TCDevices = append(cfg.TCDevices, config.TCDevice{
|
||||
Interface: t.Interface, InBandwidth: t.InBandwidth, OutBandwidth: t.OutBandwidth, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
for _, t := range rc.TCClasses {
|
||||
cfg.TCClasses = append(cfg.TCClasses, config.TCClass{
|
||||
Interface: t.Interface, Mark: t.Mark, Rate: t.Rate, Ceil: t.Ceil, Priority: t.Priority, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
for _, t := range rc.TCFilters {
|
||||
cfg.TCFilters = append(cfg.TCFilters, config.TCFilter{
|
||||
Class: t.Class, Source: t.Source, Dest: t.Dest, Proto: t.Proto,
|
||||
DPort: config.PortSpec(t.DPort), SPort: config.PortSpec(t.SPort),
|
||||
TOS: t.TOS, Length: t.Length, Priority: t.Priority, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
for _, t := range rc.TCInterfaces {
|
||||
cfg.TCInterfaces = append(cfg.TCInterfaces, config.TCInterface{
|
||||
Interface: t.Interface, Type: t.Type, InBandwidth: t.InBandwidth, OutBandwidth: t.OutBandwidth, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
for _, t := range rc.TCPriorities {
|
||||
cfg.TCPriorities = append(cfg.TCPriorities, config.TCPriority{
|
||||
Band: t.Band, Proto: t.Proto, DPort: config.PortSpec(t.DPort), SPort: config.PortSpec(t.SPort),
|
||||
Address: t.Address, Interface: t.Interface, Helper: t.Helper, Comment: t.Comment,
|
||||
})
|
||||
}
|
||||
|
||||
for _, b := range rc.Blrules {
|
||||
cfg.Blrules = append(cfg.Blrules, config.BlruleRule{
|
||||
Action: config.BlruleAction(b.Action), Source: b.Source, Dest: b.Dest, Proto: b.Proto,
|
||||
DPort: config.PortSpec(b.DPort), SPort: config.PortSpec(b.SPort), Log: b.Log, Comment: b.Comment,
|
||||
})
|
||||
}
|
||||
for _, c := range rc.Conntrack {
|
||||
cfg.Conntrack = append(cfg.Conntrack, config.ConntrackRule{
|
||||
Action: config.ConntrackAction(c.Action), Source: c.Source, Dest: c.Dest, Proto: c.Proto,
|
||||
DPort: config.PortSpec(c.DPort), SPort: config.PortSpec(c.SPort),
|
||||
Chain: config.ConntrackChain(c.Chain), Helper: c.Helper, User: c.User, Comment: c.Comment,
|
||||
})
|
||||
}
|
||||
for _, sm := range rc.Secmarks {
|
||||
cfg.Secmarks = append(cfg.Secmarks, config.SecmarkRule{
|
||||
Secmark: sm.Secmark, Chain: sm.Chain, Source: sm.Source, Dest: sm.Dest, Proto: sm.Proto,
|
||||
DPort: config.PortSpec(sm.DPort), SPort: config.PortSpec(sm.SPort), Comment: sm.Comment,
|
||||
})
|
||||
}
|
||||
if len(rc.Vars) > 0 {
|
||||
cfg.Vars = make(map[string]string, len(rc.Vars))
|
||||
for k, v := range rc.Vars {
|
||||
cfg.Vars[k] = v
|
||||
}
|
||||
}
|
||||
|
||||
return cfg, nil
|
||||
}
|
||||
|
||||
// translateSNAT expands a rendered SNAT (which carries a list of egress
|
||||
// interfaces and source CIDRs) into native tomswall SNAT rules — one per
|
||||
// (egress interface, source) pair, since a native rule takes a single Dest.
|
||||
func translateSNAT(s RenderedSNAT) []config.SNATRule {
|
||||
sources := s.Source
|
||||
if len(sources) == 0 {
|
||||
sources = []string{""}
|
||||
}
|
||||
var out []config.SNATRule
|
||||
for _, egress := range s.Egress {
|
||||
for _, src := range sources {
|
||||
r := config.SNATRule{
|
||||
Action: config.SNATAction(s.Action),
|
||||
Source: src,
|
||||
Dest: egress,
|
||||
Address: s.Address,
|
||||
Comment: s.Comment,
|
||||
}
|
||||
if s.Probability != nil {
|
||||
r.Probability = *s.Probability
|
||||
}
|
||||
out = append(out, r)
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// indexSets maps set name -> concrete member CIDRs (invalid members skipped).
|
||||
func indexSets(sets []RenderedSet) map[string][]string {
|
||||
m := make(map[string][]string, len(sets))
|
||||
|
||||
Reference in New Issue
Block a user