Add central ASN address-group expander
Expand asn address groups to concrete prefixes centrally (one iplocate key, consistent fleet-wide) and refresh them on a per-group TTL (default 24h). A background Refresher scans for due groups, unions each group's ASNs to a deduped prefix set, and writes them to a new resolved/resolved_at column (migration 0002). Fail-safe: a lookup error or empty expansion keeps the last-good set, never emptying it. The compiler folds resolved prefixes into the rendered set members; membership churn bumps the generation but never rewrites rules. The iplocate client is endpoint-configurable and response-tolerant, documented as needing endpoint/key confirmation. Unit tests cover TTL parsing, due-checks, and union/dedup/error propagation with a fake expander.
This commit is contained in:
@@ -243,7 +243,8 @@ func renderSet(g model.AddressGroup) RenderedSet {
|
||||
case model.GroupDNS:
|
||||
rs.FQDNs = g.Members
|
||||
case model.GroupASN:
|
||||
rs.ASNs = g.Members // expanded prefixes are attached out-of-band by the ASN expander
|
||||
rs.ASNs = g.Members // source ASNs
|
||||
rs.Members = g.Resolved // concrete prefixes from the central expander (may be empty until first expansion)
|
||||
}
|
||||
return rs
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user