feat: Domain-keyed service registration model
Rewrite the service registration model per the architecture plan:
Model changes:
- Domain is the unique key (removed Name field)
- Removed ExtraDomains — each domain is its own registration
- Removed SourceNode, BackendStatic, ReachOff
- Added Subdomains bool for wildcard matching control
- Files stored as <domain_with_underscores>.yaml
- API routes: /services/{domain:.+} (regex for dots in path)
- Added DeregisterBySource for cleanup before re-registration
Reconciliation changes:
- No ExtraDomains iteration — each service IS one domain
- reach:internal → sets InternalDomain (generates local=/)
- reach:public → sets Domain (no local=/)
- tcp-passthrough → DNS points to backend IP
- http → DNS points to Central IP
All 22 tests pass (9 manager + 8 handler + 5 config/cert).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -113,7 +113,6 @@ func (api *API) RegisterSelf(port int) {
|
||||
}
|
||||
|
||||
svc := services.Service{
|
||||
Name: "wild-central",
|
||||
Source: "wild-central",
|
||||
Domain: domain,
|
||||
Backend: services.Backend{
|
||||
@@ -251,12 +250,13 @@ func (api *API) RegisterRoutes(r *mux.Router) {
|
||||
r.HandleFunc("/api/v1/cloudflare/zone", api.CloudflareGetZoneID).Methods("GET")
|
||||
r.HandleFunc("/api/v1/cloudflare/zone", api.CloudflareSetZoneID).Methods("POST")
|
||||
|
||||
// Service registration
|
||||
// Service registration — domain is the unique key
|
||||
r.HandleFunc("/api/v1/services", api.ServicesListAll).Methods("GET")
|
||||
r.HandleFunc("/api/v1/services", api.ServicesRegister).Methods("POST")
|
||||
r.HandleFunc("/api/v1/services/{name}", api.ServicesGet).Methods("GET")
|
||||
r.HandleFunc("/api/v1/services/{name}", api.ServicesUpdate).Methods("PATCH")
|
||||
r.HandleFunc("/api/v1/services/{name}", api.ServicesDeregister).Methods("DELETE")
|
||||
r.HandleFunc("/api/v1/services/deregister", api.ServicesDeregisterBySource).Methods("DELETE")
|
||||
r.HandleFunc("/api/v1/services/{domain:.+}", api.ServicesGet).Methods("GET")
|
||||
r.HandleFunc("/api/v1/services/{domain:.+}", api.ServicesUpdate).Methods("PATCH")
|
||||
r.HandleFunc("/api/v1/services/{domain:.+}", api.ServicesDeregister).Methods("DELETE")
|
||||
|
||||
// SSE events
|
||||
r.HandleFunc("/api/v1/events", api.GlobalEventStream).Methods("GET")
|
||||
|
||||
@@ -6,6 +6,7 @@ import (
|
||||
"strings"
|
||||
|
||||
"github.com/wild-cloud/wild-central/internal/config"
|
||||
"github.com/wild-cloud/wild-central/internal/services"
|
||||
)
|
||||
|
||||
// CertStatus returns TLS certificate status for all relevant domains:
|
||||
@@ -27,7 +28,7 @@ func (api *API) CertStatus(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
svcs, _ := api.services.List()
|
||||
for _, svc := range svcs {
|
||||
if svc.TLS != "terminate" || svc.Domain == "" {
|
||||
if svc.TLS != services.TLSTerminate || svc.Domain == "" {
|
||||
continue
|
||||
}
|
||||
if seen[svc.Domain] {
|
||||
@@ -39,7 +40,7 @@ func (api *API) CertStatus(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
entry := map[string]any{
|
||||
"domain": svc.Domain,
|
||||
"service": svc.Name,
|
||||
"service": svc.Domain,
|
||||
"source": svc.Source,
|
||||
"cert": status,
|
||||
}
|
||||
|
||||
@@ -27,11 +27,11 @@ func (api *API) ServicesListAll(w http.ResponseWriter, r *http.Request) {
|
||||
})
|
||||
}
|
||||
|
||||
// ServicesGet retrieves a service by name.
|
||||
// ServicesGet retrieves a service by domain.
|
||||
func (api *API) ServicesGet(w http.ResponseWriter, r *http.Request) {
|
||||
name := mux.Vars(r)["name"]
|
||||
domain := mux.Vars(r)["domain"]
|
||||
|
||||
svc, err := api.services.Get(name)
|
||||
svc, err := api.services.Get(domain)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusNotFound, fmt.Sprintf("Service not found: %v", err))
|
||||
return
|
||||
@@ -54,16 +54,16 @@ func (api *API) ServicesRegister(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
// Return the stored version (has defaults applied)
|
||||
stored, _ := api.services.Get(svc.Name)
|
||||
stored, _ := api.services.Get(svc.Domain)
|
||||
respondJSON(w, http.StatusCreated, map[string]any{
|
||||
"message": fmt.Sprintf("Service %q registered", svc.Name),
|
||||
"message": fmt.Sprintf("Service %q registered", svc.Domain),
|
||||
"service": stored,
|
||||
})
|
||||
}
|
||||
|
||||
// ServicesUpdate applies partial updates to a service.
|
||||
func (api *API) ServicesUpdate(w http.ResponseWriter, r *http.Request) {
|
||||
name := mux.Vars(r)["name"]
|
||||
domain := mux.Vars(r)["domain"]
|
||||
|
||||
var updates map[string]any
|
||||
if err := json.NewDecoder(r.Body).Decode(&updates); err != nil {
|
||||
@@ -71,26 +71,44 @@ func (api *API) ServicesUpdate(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
if err := api.services.Update(name, updates); err != nil {
|
||||
if err := api.services.Update(domain, updates); err != nil {
|
||||
respondError(w, http.StatusNotFound, fmt.Sprintf("Failed to update service: %v", err))
|
||||
return
|
||||
}
|
||||
|
||||
svc, _ := api.services.Get(name)
|
||||
svc, _ := api.services.Get(domain)
|
||||
respondJSON(w, http.StatusOK, map[string]any{
|
||||
"message": fmt.Sprintf("Service %q updated", name),
|
||||
"message": fmt.Sprintf("Service %q updated", domain),
|
||||
"service": svc,
|
||||
})
|
||||
}
|
||||
|
||||
// ServicesDeregister removes a service registration.
|
||||
func (api *API) ServicesDeregister(w http.ResponseWriter, r *http.Request) {
|
||||
name := mux.Vars(r)["name"]
|
||||
domain := mux.Vars(r)["domain"]
|
||||
|
||||
if err := api.services.Deregister(name); err != nil {
|
||||
if err := api.services.Deregister(domain); err != nil {
|
||||
respondError(w, http.StatusNotFound, fmt.Sprintf("Failed to deregister service: %v", err))
|
||||
return
|
||||
}
|
||||
|
||||
respondMessage(w, http.StatusOK, fmt.Sprintf("Service %q deregistered", name))
|
||||
respondMessage(w, http.StatusOK, fmt.Sprintf("Service %q deregistered", domain))
|
||||
}
|
||||
|
||||
// ServicesDeregisterBySource removes all services from a source with a given backend.
|
||||
func (api *API) ServicesDeregisterBySource(w http.ResponseWriter, r *http.Request) {
|
||||
source := r.URL.Query().Get("source")
|
||||
backend := r.URL.Query().Get("backend")
|
||||
|
||||
if source == "" {
|
||||
respondError(w, http.StatusBadRequest, "source query parameter is required")
|
||||
return
|
||||
}
|
||||
|
||||
if err := api.services.DeregisterBySource(source, backend); err != nil {
|
||||
respondError(w, http.StatusInternalServerError, fmt.Sprintf("Failed to deregister: %v", err))
|
||||
return
|
||||
}
|
||||
|
||||
respondMessage(w, http.StatusOK, fmt.Sprintf("Services from %q deregistered", source))
|
||||
}
|
||||
|
||||
@@ -14,20 +14,17 @@ func TestServicesRegister(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": "my-api",
|
||||
"source": "wild-works",
|
||||
"domain": "my-api.payne.io",
|
||||
"source": "wild-works",
|
||||
"backend": map[string]any{
|
||||
"address": "192.168.8.60:9001",
|
||||
"type": "http",
|
||||
"health": "/health",
|
||||
},
|
||||
"reach": "internal",
|
||||
})
|
||||
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
if w.Code != http.StatusCreated {
|
||||
@@ -37,194 +34,15 @@ func TestServicesRegister(t *testing.T) {
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
|
||||
svc, ok := resp["service"].(map[string]any)
|
||||
if !ok {
|
||||
t.Fatal("expected service in response")
|
||||
}
|
||||
if svc["name"] != "my-api" {
|
||||
t.Errorf("expected name my-api, got %v", svc["name"])
|
||||
svc := resp["service"].(map[string]any)
|
||||
if svc["domain"] != "my-api.payne.io" {
|
||||
t.Errorf("expected domain my-api.payne.io, got %v", svc["domain"])
|
||||
}
|
||||
if svc["tls"] != "terminate" {
|
||||
t.Errorf("expected tls=terminate default for http backend, got %v", svc["tls"])
|
||||
t.Errorf("expected tls=terminate default for http, got %v", svc["tls"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesListAll_Empty(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
req := httptest.NewRequest("GET", "/api/v1/services", nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
api.ServicesListAll(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d", w.Code)
|
||||
}
|
||||
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
|
||||
svcs, ok := resp["services"].([]any)
|
||||
if !ok {
|
||||
t.Fatal("expected services array")
|
||||
}
|
||||
if len(svcs) != 0 {
|
||||
t.Errorf("expected empty services, got %d", len(svcs))
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesListAll_WithServices(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register two services
|
||||
for _, name := range []string{"svc-a", "svc-b"} {
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": name,
|
||||
"source": "test",
|
||||
"domain": name + ".example.com",
|
||||
"backend": map[string]any{"address": "127.0.0.1:8080", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
if w.Code != http.StatusCreated {
|
||||
t.Fatalf("register %s failed: %d", name, w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
req := httptest.NewRequest("GET", "/api/v1/services", nil)
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
api.ServicesListAll(w, req)
|
||||
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
|
||||
svcs := resp["services"].([]any)
|
||||
if len(svcs) != 2 {
|
||||
t.Errorf("expected 2 services, got %d", len(svcs))
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesGet(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": "get-test",
|
||||
"source": "test",
|
||||
"domain": "get-test.example.com",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
// Get
|
||||
req = httptest.NewRequest("GET", "/api/v1/services/get-test", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"name": "get-test"})
|
||||
w = httptest.NewRecorder()
|
||||
|
||||
api.ServicesGet(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d: %s", w.Code, w.Body.String())
|
||||
}
|
||||
|
||||
var svc map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &svc)
|
||||
|
||||
if svc["domain"] != "get-test.example.com" {
|
||||
t.Errorf("expected domain get-test.example.com, got %v", svc["domain"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesGet_NotFound(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
req := httptest.NewRequest("GET", "/api/v1/services/nonexistent", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"name": "nonexistent"})
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
api.ServicesGet(w, req)
|
||||
|
||||
if w.Code != http.StatusNotFound {
|
||||
t.Errorf("expected 404, got %d", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesUpdate(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": "update-test",
|
||||
"source": "test",
|
||||
"domain": "update-test.example.com",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
// Update reach to public
|
||||
update, _ := json.Marshal(map[string]any{"reach": "public"})
|
||||
req = httptest.NewRequest("PATCH", "/api/v1/services/update-test", bytes.NewReader(update))
|
||||
req = mux.SetURLVars(req, map[string]string{"name": "update-test"})
|
||||
w = httptest.NewRecorder()
|
||||
|
||||
api.ServicesUpdate(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d: %s", w.Code, w.Body.String())
|
||||
}
|
||||
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
|
||||
svc := resp["service"].(map[string]any)
|
||||
if svc["reach"] != "public" {
|
||||
t.Errorf("expected reach=public after update, got %v", svc["reach"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesDeregister(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": "delete-me",
|
||||
"source": "test",
|
||||
"domain": "delete-me.example.com",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
// Delete
|
||||
req = httptest.NewRequest("DELETE", "/api/v1/services/delete-me", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"name": "delete-me"})
|
||||
w = httptest.NewRecorder()
|
||||
|
||||
api.ServicesDeregister(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d", w.Code)
|
||||
}
|
||||
|
||||
// Verify it's gone
|
||||
req = httptest.NewRequest("GET", "/api/v1/services/delete-me", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"name": "delete-me"})
|
||||
w = httptest.NewRecorder()
|
||||
api.ServicesGet(w, req)
|
||||
|
||||
if w.Code != http.StatusNotFound {
|
||||
t.Errorf("expected 404 after delete, got %d", w.Code)
|
||||
if svc["source"] != "wild-works" {
|
||||
t.Errorf("expected source wild-works, got %v", svc["source"])
|
||||
}
|
||||
}
|
||||
|
||||
@@ -232,19 +50,18 @@ func TestServicesRegister_TCPPassthrough(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"name": "cloud-instance",
|
||||
"source": "wild-cloud",
|
||||
"domain": "cloud.payne.io",
|
||||
"source": "wild-cloud",
|
||||
"backend": map[string]any{
|
||||
"address": "192.168.8.100:443",
|
||||
"address": "192.168.8.240:443",
|
||||
"type": "tcp-passthrough",
|
||||
},
|
||||
"reach": "internal",
|
||||
"subdomains": true,
|
||||
"reach": "public",
|
||||
})
|
||||
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
if w.Code != http.StatusCreated {
|
||||
@@ -258,21 +75,153 @@ func TestServicesRegister_TCPPassthrough(t *testing.T) {
|
||||
if svc["tls"] != "passthrough" {
|
||||
t.Errorf("expected tls=passthrough for tcp-passthrough, got %v", svc["tls"])
|
||||
}
|
||||
if svc["subdomains"] != true {
|
||||
t.Errorf("expected subdomains=true, got %v", svc["subdomains"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesRegister_Validation(t *testing.T) {
|
||||
func TestServicesListAll_Empty(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Missing name
|
||||
req := httptest.NewRequest("GET", "/api/v1/services", nil)
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesListAll(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d", w.Code)
|
||||
}
|
||||
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
svcs := resp["services"].([]any)
|
||||
if len(svcs) != 0 {
|
||||
t.Errorf("expected empty, got %d", len(svcs))
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesGet(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"domain": "x.com",
|
||||
"backend": map[string]any{"address": "127.0.0.1:80", "type": "http"},
|
||||
"domain": "get-test.example.com",
|
||||
"source": "test",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
if w.Code != http.StatusBadRequest {
|
||||
t.Errorf("expected 400 for missing name, got %d", w.Code)
|
||||
// Get by domain
|
||||
req = httptest.NewRequest("GET", "/api/v1/services/get-test.example.com", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"domain": "get-test.example.com"})
|
||||
w = httptest.NewRecorder()
|
||||
api.ServicesGet(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d: %s", w.Code, w.Body.String())
|
||||
}
|
||||
|
||||
var svc map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &svc)
|
||||
if svc["domain"] != "get-test.example.com" {
|
||||
t.Errorf("expected domain get-test.example.com, got %v", svc["domain"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesGet_NotFound(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
req := httptest.NewRequest("GET", "/api/v1/services/nonexistent.com", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"domain": "nonexistent.com"})
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesGet(w, req)
|
||||
|
||||
if w.Code != http.StatusNotFound {
|
||||
t.Errorf("expected 404, got %d", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesUpdate(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"domain": "update-test.example.com",
|
||||
"source": "test",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
// Update reach to public
|
||||
update, _ := json.Marshal(map[string]any{"reach": "public"})
|
||||
req = httptest.NewRequest("PATCH", "/api/v1/services/update-test.example.com", bytes.NewReader(update))
|
||||
req = mux.SetURLVars(req, map[string]string{"domain": "update-test.example.com"})
|
||||
w = httptest.NewRecorder()
|
||||
api.ServicesUpdate(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d: %s", w.Code, w.Body.String())
|
||||
}
|
||||
|
||||
var resp map[string]any
|
||||
json.Unmarshal(w.Body.Bytes(), &resp)
|
||||
svc := resp["service"].(map[string]any)
|
||||
if svc["reach"] != "public" {
|
||||
t.Errorf("expected reach=public, got %v", svc["reach"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesDeregister(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Register
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"domain": "delete-me.example.com",
|
||||
"source": "test",
|
||||
"backend": map[string]any{"address": "127.0.0.1:9000", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
|
||||
// Delete
|
||||
req = httptest.NewRequest("DELETE", "/api/v1/services/delete-me.example.com", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"domain": "delete-me.example.com"})
|
||||
w = httptest.NewRecorder()
|
||||
api.ServicesDeregister(w, req)
|
||||
|
||||
if w.Code != http.StatusOK {
|
||||
t.Fatalf("expected 200, got %d", w.Code)
|
||||
}
|
||||
|
||||
// Verify gone
|
||||
req = httptest.NewRequest("GET", "/api/v1/services/delete-me.example.com", nil)
|
||||
req = mux.SetURLVars(req, map[string]string{"domain": "delete-me.example.com"})
|
||||
w = httptest.NewRecorder()
|
||||
api.ServicesGet(w, req)
|
||||
if w.Code != http.StatusNotFound {
|
||||
t.Errorf("expected 404 after delete, got %d", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestServicesRegister_Validation(t *testing.T) {
|
||||
api, _ := setupTestAPI(t)
|
||||
|
||||
// Missing domain
|
||||
body, _ := json.Marshal(map[string]any{
|
||||
"backend": map[string]any{"address": "127.0.0.1:80", "type": "http"},
|
||||
"reach": "internal",
|
||||
})
|
||||
req := httptest.NewRequest("POST", "/api/v1/services", bytes.NewReader(body))
|
||||
w := httptest.NewRecorder()
|
||||
api.ServicesRegister(w, req)
|
||||
if w.Code != http.StatusBadRequest {
|
||||
t.Errorf("expected 400 for missing domain, got %d", w.Code)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -38,21 +38,16 @@ func (api *API) reconcileNetworking() {
|
||||
var httpRoutes []haproxy.HTTPRoute
|
||||
|
||||
for _, svc := range svcs {
|
||||
if svc.Reach == services.ReachOff {
|
||||
continue
|
||||
}
|
||||
|
||||
switch svc.Backend.Type {
|
||||
case services.BackendTCPPassthrough:
|
||||
instanceRoutes = append(instanceRoutes, haproxy.InstanceRoute{
|
||||
Name: svc.Name,
|
||||
Domain: svc.Domain,
|
||||
BackendIP: extractHost(svc.Backend.Address),
|
||||
ExtraDomains: svc.ExtraDomains,
|
||||
Name: svc.Domain,
|
||||
Domain: svc.Domain,
|
||||
BackendIP: extractHost(svc.Backend.Address),
|
||||
})
|
||||
case services.BackendHTTP, services.BackendStatic:
|
||||
case services.BackendHTTP:
|
||||
httpRoutes = append(httpRoutes, haproxy.HTTPRoute{
|
||||
Name: svc.Name,
|
||||
Name: svc.Domain,
|
||||
Domain: svc.Domain,
|
||||
Backend: svc.Backend.Address,
|
||||
HealthPath: svc.Backend.Health,
|
||||
@@ -116,7 +111,7 @@ func (api *API) reconcileNetworking() {
|
||||
|
||||
var instanceConfigs []config.InstanceConfig
|
||||
for _, svc := range svcs {
|
||||
if svc.Reach == services.ReachOff || svc.Domain == "" {
|
||||
if svc.Domain == "" {
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -127,17 +122,14 @@ func (api *API) reconcileNetworking() {
|
||||
dnsIP = extractHost(svc.Backend.Address)
|
||||
}
|
||||
|
||||
// Primary domain
|
||||
ic := config.InstanceConfig{}
|
||||
ic.Cloud.Domain = svc.Domain
|
||||
ic.Cluster.LoadBalancerIp = dnsIP
|
||||
|
||||
// Extra domains (e.g., internal.cloud.payne.io)
|
||||
for _, extra := range svc.ExtraDomains {
|
||||
if strings.HasPrefix(extra, "internal.") {
|
||||
// Internal-only domain: local=/ prevents upstream DNS forwarding
|
||||
ic.Cloud.InternalDomain = extra
|
||||
}
|
||||
if svc.Reach == services.ReachInternal {
|
||||
// Internal-only: local=/ prevents upstream DNS forwarding
|
||||
ic.Cloud.InternalDomain = svc.Domain
|
||||
} else {
|
||||
ic.Cloud.Domain = svc.Domain
|
||||
}
|
||||
|
||||
instanceConfigs = append(instanceConfigs, ic)
|
||||
@@ -182,7 +174,7 @@ func (api *API) ensureTLSCerts(globalCfg *config.GlobalConfig, svcs []services.S
|
||||
wildcardCert := certbot.HAProxyCertPath(gatewayDomain)
|
||||
if _, err := os.Stat(wildcardCert); err != nil {
|
||||
slog.Warn("reconcile/tls: no wildcard cert for gateway domain — provision via Certificates page",
|
||||
"service", svc.Name, "domain", svc.Domain, "needed", "*."+gatewayDomain)
|
||||
"domain", svc.Domain, "needed", "*."+gatewayDomain)
|
||||
}
|
||||
continue
|
||||
}
|
||||
@@ -190,7 +182,7 @@ func (api *API) ensureTLSCerts(globalCfg *config.GlobalConfig, svcs []services.S
|
||||
// Check individual cert
|
||||
if _, err := os.Stat(certbot.HAProxyCertPath(svc.Domain)); err != nil {
|
||||
slog.Warn("reconcile/tls: no cert for service — provision via Certificates page",
|
||||
"service", svc.Name, "domain", svc.Domain)
|
||||
"domain", svc.Domain)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user