Documentation
¶
Overview ¶
Package clusternetwork tells cloud how this cluster can be reached, over the negotiated uplink session.
The facts are measured on the box (advertised addresses, the CA the API presents, netcheck's verdict, whether the server runs in a container) and describe the link rather than any stored entity, which is why they ride a purpose-built capability instead of entity sync. They are the same facts the legacy status poll carries; when cloud selects this capability the poll has nothing left to say about the network.
Index ¶
Constants ¶
const ( Version1 uint = 1 TypeReport = "cluster.network.report" )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Link ¶
type Link interface {
OfferCapability(uplink.CapabilityOffer)
OnSession(func(context.Context, uplink.Session))
SendMessageBlocking(context.Context, string, any) error
}
Link is the slice of the uplink client the reporter uses.
type Report ¶
type Report struct {
// APIAddresses are the "host:port" endpoints advertised for the API,
// already pruned to what netcheck confirmed (see ComputeAdvertise).
APIAddresses []string `json:"api_addresses,omitempty"`
// CACertFingerprint is the hex SHA-1 of the DER CA certificate the API
// presents, which the CLI pins when it connects directly.
CACertFingerprint string `json:"ca_cert_fingerprint,omitempty"`
// Reachability is netcheck's verdict, nil when it produced no usable
// public source address; cloud then keeps whatever it last stored.
Reachability *cloudauth.ReachabilityVerdict `json:"reachability,omitempty"`
// Containerized is sent unconditionally so an explicit false lands.
Containerized bool `json:"containerized"`
}
Report is what this cluster says about how it can be reached. It is the network-shaped half of the legacy status report, field for field, so cloud treats the two sources identically while both are live.
There is no cluster field: cloud takes identity from the authenticated socket, never from the payload.