feat: Domain-keyed service registration model
Rewrite the service registration model per the architecture plan:
Model changes:
- Domain is the unique key (removed Name field)
- Removed ExtraDomains — each domain is its own registration
- Removed SourceNode, BackendStatic, ReachOff
- Added Subdomains bool for wildcard matching control
- Files stored as <domain_with_underscores>.yaml
- API routes: /services/{domain:.+} (regex for dots in path)
- Added DeregisterBySource for cleanup before re-registration
Reconciliation changes:
- No ExtraDomains iteration — each service IS one domain
- reach:internal → sets InternalDomain (generates local=/)
- reach:public → sets Domain (no local=/)
- tcp-passthrough → DNS points to backend IP
- http → DNS points to Central IP
All 22 tests pass (9 manager + 8 handler + 5 config/cert).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,9 +1,9 @@
|
||||
// Package services manages service registrations from Wild Cloud, Wild Works,
|
||||
// and manual entries. Services register with Central to get DNS, gateway
|
||||
// routing, TLS certificates, and optional public exposure (tunnels or direct).
|
||||
// routing, TLS certificates, and optional public exposure via DDNS.
|
||||
//
|
||||
// Registrations are stored as YAML files on disk and will later be backed by
|
||||
// NATS JetStream KV for real-time coordination.
|
||||
// Each registration is keyed by its domain — one registration per domain.
|
||||
// Central's own services (its UI, VPN, firewall) come from config, not here.
|
||||
package services
|
||||
|
||||
import (
|
||||
@@ -11,6 +11,7 @@ import (
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
"gopkg.in/yaml.v3"
|
||||
@@ -20,9 +21,8 @@ import (
|
||||
type Reach string
|
||||
|
||||
const (
|
||||
ReachOff Reach = "off" // localhost only — no DNS, no proxy
|
||||
ReachInternal Reach = "internal" // LAN-visible — DNS + proxy + TLS
|
||||
ReachPublic Reach = "public" // internet-visible — + tunnel or direct exposure
|
||||
ReachPublic Reach = "public" // internet-visible — + DDNS + external HAProxy
|
||||
)
|
||||
|
||||
// BackendType describes how the gateway handles traffic for this service.
|
||||
@@ -31,41 +31,38 @@ type BackendType string
|
||||
const (
|
||||
BackendTCPPassthrough BackendType = "tcp-passthrough" // L4 SNI passthrough (k8s)
|
||||
BackendHTTP BackendType = "http" // L7 HTTP reverse proxy
|
||||
BackendStatic BackendType = "static" // L7 static file serving
|
||||
)
|
||||
|
||||
// TLSMode describes how TLS is handled for the service.
|
||||
type TLSMode string
|
||||
|
||||
const (
|
||||
TLSTerminate TLSMode = "terminate" // Central terminates TLS (wildcard cert)
|
||||
TLSTerminate TLSMode = "terminate" // Central terminates TLS
|
||||
TLSPassthrough TLSMode = "passthrough" // Backend handles TLS (k8s traefik)
|
||||
)
|
||||
|
||||
// Backend describes the target for a service.
|
||||
type Backend struct {
|
||||
Address string `yaml:"address" json:"address"` // host:port (e.g., "192.168.8.60:9001")
|
||||
Type BackendType `yaml:"type" json:"type"` // how to route
|
||||
Health string `yaml:"health,omitempty" json:"health,omitempty"` // health check path (e.g., "/health")
|
||||
Address string `yaml:"address" json:"address"` // host:port
|
||||
Type BackendType `yaml:"type" json:"type"` // tcp-passthrough or http
|
||||
Health string `yaml:"health,omitempty" json:"health,omitempty"`
|
||||
}
|
||||
|
||||
// Service represents a registered service.
|
||||
// Service represents a registered service. The Domain is the unique key.
|
||||
type Service struct {
|
||||
Name string `yaml:"name" json:"name"`
|
||||
Source string `yaml:"source" json:"source"` // "wild-cloud", "wild-works", "manual"
|
||||
SourceNode string `yaml:"sourceNode,omitempty" json:"sourceNode,omitempty"` // IP of the node running this service
|
||||
Domain string `yaml:"domain" json:"domain"` // FQDN (e.g., "my-api.payne.io")
|
||||
ExtraDomains []string `yaml:"extraDomains,omitempty" json:"extraDomains,omitempty"` // additional domains
|
||||
Backend Backend `yaml:"backend" json:"backend"`
|
||||
Reach Reach `yaml:"reach" json:"reach"`
|
||||
TLS TLSMode `yaml:"tls,omitempty" json:"tls,omitempty"`
|
||||
Domain string `yaml:"domain" json:"domain"` // FQDN — unique key
|
||||
Source string `yaml:"source,omitempty" json:"source,omitempty"` // who registered: wild-cloud, wild-works, manual
|
||||
Backend Backend `yaml:"backend" json:"backend"` // where to route
|
||||
Subdomains bool `yaml:"subdomains,omitempty" json:"subdomains,omitempty"` // also match *.domain
|
||||
Reach Reach `yaml:"reach" json:"reach"` // internal or public
|
||||
TLS TLSMode `yaml:"tls,omitempty" json:"tls,omitempty"` // passthrough or terminate
|
||||
}
|
||||
|
||||
// Manager handles service registration CRUD and triggers networking reconciliation.
|
||||
type Manager struct {
|
||||
dataDir string
|
||||
mu sync.RWMutex
|
||||
reconcileFn func() // called after service changes to update DNS/proxy/TLS
|
||||
reconcileFn func()
|
||||
}
|
||||
|
||||
// NewManager creates a new service registration manager.
|
||||
@@ -86,8 +83,13 @@ func (m *Manager) servicesDir() string {
|
||||
return filepath.Join(m.dataDir, "services")
|
||||
}
|
||||
|
||||
func (m *Manager) servicePath(name string) string {
|
||||
return filepath.Join(m.servicesDir(), name+".yaml")
|
||||
// domainToFilename converts a domain to a filesystem-safe filename.
|
||||
func domainToFilename(domain string) string {
|
||||
return strings.ReplaceAll(domain, ".", "_") + ".yaml"
|
||||
}
|
||||
|
||||
func (m *Manager) servicePath(domain string) string {
|
||||
return filepath.Join(m.servicesDir(), domainToFilename(domain))
|
||||
}
|
||||
|
||||
// Register creates or updates a service registration.
|
||||
@@ -95,24 +97,19 @@ func (m *Manager) Register(svc Service) error {
|
||||
m.mu.Lock()
|
||||
defer m.mu.Unlock()
|
||||
|
||||
if svc.Name == "" {
|
||||
return fmt.Errorf("service name is required")
|
||||
}
|
||||
if svc.Domain == "" {
|
||||
return fmt.Errorf("service domain is required")
|
||||
return fmt.Errorf("domain is required")
|
||||
}
|
||||
if svc.Backend.Address == "" {
|
||||
return fmt.Errorf("backend address is required")
|
||||
}
|
||||
|
||||
// Default reach to internal
|
||||
if svc.Reach == "" {
|
||||
svc.Reach = ReachInternal
|
||||
}
|
||||
// Default backend type to http
|
||||
if svc.Backend.Type == "" {
|
||||
svc.Backend.Type = BackendHTTP
|
||||
return fmt.Errorf("backend type is required")
|
||||
}
|
||||
if svc.Reach == "" {
|
||||
return fmt.Errorf("reach is required")
|
||||
}
|
||||
|
||||
// Default TLS mode based on backend type
|
||||
if svc.TLS == "" {
|
||||
if svc.Backend.Type == BackendTCPPassthrough {
|
||||
@@ -122,16 +119,21 @@ func (m *Manager) Register(svc Service) error {
|
||||
}
|
||||
}
|
||||
|
||||
// Default source
|
||||
if svc.Source == "" {
|
||||
svc.Source = "manual"
|
||||
}
|
||||
|
||||
data, err := yaml.Marshal(svc)
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshaling service: %w", err)
|
||||
}
|
||||
|
||||
if err := os.WriteFile(m.servicePath(svc.Name), data, 0644); err != nil {
|
||||
if err := os.WriteFile(m.servicePath(svc.Domain), data, 0644); err != nil {
|
||||
return fmt.Errorf("writing service file: %w", err)
|
||||
}
|
||||
|
||||
slog.Info("service registered", "name", svc.Name, "domain", svc.Domain, "reach", svc.Reach, "source", svc.Source)
|
||||
slog.Info("service registered", "domain", svc.Domain, "reach", svc.Reach, "source", svc.Source, "subdomains", svc.Subdomains)
|
||||
|
||||
if m.reconcileFn != nil {
|
||||
go m.reconcileFn()
|
||||
@@ -140,21 +142,21 @@ func (m *Manager) Register(svc Service) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Deregister removes a service registration.
|
||||
func (m *Manager) Deregister(name string) error {
|
||||
// Deregister removes a service registration by domain.
|
||||
func (m *Manager) Deregister(domain string) error {
|
||||
m.mu.Lock()
|
||||
defer m.mu.Unlock()
|
||||
|
||||
path := m.servicePath(name)
|
||||
path := m.servicePath(domain)
|
||||
if _, err := os.Stat(path); os.IsNotExist(err) {
|
||||
return fmt.Errorf("service %q not found", name)
|
||||
return fmt.Errorf("service %q not found", domain)
|
||||
}
|
||||
|
||||
if err := os.Remove(path); err != nil {
|
||||
return fmt.Errorf("removing service file: %w", err)
|
||||
}
|
||||
|
||||
slog.Info("service deregistered", "name", name)
|
||||
slog.Info("service deregistered", "domain", domain)
|
||||
|
||||
if m.reconcileFn != nil {
|
||||
go m.reconcileFn()
|
||||
@@ -163,15 +165,15 @@ func (m *Manager) Deregister(name string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Get retrieves a service registration by name.
|
||||
func (m *Manager) Get(name string) (*Service, error) {
|
||||
// Get retrieves a service registration by domain.
|
||||
func (m *Manager) Get(domain string) (*Service, error) {
|
||||
m.mu.RLock()
|
||||
defer m.mu.RUnlock()
|
||||
|
||||
data, err := os.ReadFile(m.servicePath(name))
|
||||
data, err := os.ReadFile(m.servicePath(domain))
|
||||
if err != nil {
|
||||
if os.IsNotExist(err) {
|
||||
return nil, fmt.Errorf("service %q not found", name)
|
||||
return nil, fmt.Errorf("service %q not found", domain)
|
||||
}
|
||||
return nil, fmt.Errorf("reading service file: %w", err)
|
||||
}
|
||||
@@ -221,19 +223,37 @@ func (m *Manager) List() ([]Service, error) {
|
||||
return services, nil
|
||||
}
|
||||
|
||||
// Update applies partial updates to a service registration.
|
||||
func (m *Manager) Update(name string, updates map[string]any) error {
|
||||
svc, err := m.Get(name)
|
||||
// DeregisterBySource removes all registrations from a given source that match
|
||||
// a backend address. Used by consumers to clean up before re-registering.
|
||||
func (m *Manager) DeregisterBySource(source, backendAddress string) error {
|
||||
svcs, err := m.List()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
for _, svc := range svcs {
|
||||
if svc.Source == source && svc.Backend.Address == backendAddress {
|
||||
if err := m.Deregister(svc.Domain); err != nil {
|
||||
slog.Warn("failed to deregister service during cleanup", "domain", svc.Domain, "error", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// Update applies partial updates to a service registration.
|
||||
func (m *Manager) Update(domain string, updates map[string]any) error {
|
||||
svc, err := m.Get(domain)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Apply known fields
|
||||
if reach, ok := updates["reach"].(string); ok {
|
||||
svc.Reach = Reach(reach)
|
||||
}
|
||||
if domain, ok := updates["domain"].(string); ok {
|
||||
svc.Domain = domain
|
||||
if sub, ok := updates["subdomains"].(bool); ok {
|
||||
svc.Subdomains = sub
|
||||
}
|
||||
if backend, ok := updates["backend"].(map[string]any); ok {
|
||||
if addr, ok := backend["address"].(string); ok {
|
||||
|
||||
@@ -8,13 +8,11 @@ func TestRegisterAndGet(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
svc := Service{
|
||||
Name: "my-api",
|
||||
Source: "wild-works",
|
||||
Domain: "my-api.payne.io",
|
||||
Source: "wild-works",
|
||||
Backend: Backend{
|
||||
Address: "192.168.8.60:9001",
|
||||
Type: BackendHTTP,
|
||||
Health: "/health",
|
||||
},
|
||||
Reach: ReachInternal,
|
||||
}
|
||||
@@ -23,7 +21,7 @@ func TestRegisterAndGet(t *testing.T) {
|
||||
t.Fatalf("Register failed: %v", err)
|
||||
}
|
||||
|
||||
got, err := mgr.Get("my-api")
|
||||
got, err := mgr.Get("my-api.payne.io")
|
||||
if err != nil {
|
||||
t.Fatalf("Get failed: %v", err)
|
||||
}
|
||||
@@ -34,54 +32,59 @@ func TestRegisterAndGet(t *testing.T) {
|
||||
if got.Backend.Address != "192.168.8.60:9001" {
|
||||
t.Errorf("expected backend 192.168.8.60:9001, got %s", got.Backend.Address)
|
||||
}
|
||||
if got.Reach != ReachInternal {
|
||||
t.Errorf("expected reach internal, got %s", got.Reach)
|
||||
}
|
||||
if got.TLS != TLSTerminate {
|
||||
t.Errorf("expected TLS terminate (default for http), got %s", got.TLS)
|
||||
}
|
||||
if got.Source != "wild-works" {
|
||||
t.Errorf("expected source wild-works, got %s", got.Source)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRegisterTCPPassthrough(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
svc := Service{
|
||||
Name: "payne-cloud",
|
||||
Source: "wild-cloud",
|
||||
Domain: "cloud.payne.io",
|
||||
Source: "wild-cloud",
|
||||
Backend: Backend{
|
||||
Address: "192.168.8.100:443",
|
||||
Address: "192.168.8.240:443",
|
||||
Type: BackendTCPPassthrough,
|
||||
},
|
||||
Reach: ReachInternal,
|
||||
Subdomains: true,
|
||||
Reach: ReachPublic,
|
||||
}
|
||||
|
||||
if err := mgr.Register(svc); err != nil {
|
||||
t.Fatalf("Register failed: %v", err)
|
||||
}
|
||||
|
||||
got, err := mgr.Get("payne-cloud")
|
||||
got, err := mgr.Get("cloud.payne.io")
|
||||
if err != nil {
|
||||
t.Fatalf("Get failed: %v", err)
|
||||
}
|
||||
|
||||
if got.TLS != TLSPassthrough {
|
||||
t.Errorf("expected TLS passthrough (default for tcp-passthrough), got %s", got.TLS)
|
||||
t.Errorf("expected TLS passthrough for tcp-passthrough, got %s", got.TLS)
|
||||
}
|
||||
if !got.Subdomains {
|
||||
t.Error("expected subdomains=true")
|
||||
}
|
||||
if got.Reach != ReachPublic {
|
||||
t.Errorf("expected reach public, got %s", got.Reach)
|
||||
}
|
||||
}
|
||||
|
||||
func TestListServices(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
for _, name := range []string{"svc-a", "svc-b", "svc-c"} {
|
||||
for _, domain := range []string{"a.example.com", "b.example.com", "c.example.com"} {
|
||||
if err := mgr.Register(Service{
|
||||
Name: name,
|
||||
Domain: domain,
|
||||
Source: "test",
|
||||
Domain: name + ".example.com",
|
||||
Backend: Backend{Address: "127.0.0.1:8080", Type: BackendHTTP},
|
||||
Reach: ReachInternal,
|
||||
}); err != nil {
|
||||
t.Fatalf("Register %s failed: %v", name, err)
|
||||
t.Fatalf("Register %s failed: %v", domain, err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -98,64 +101,136 @@ func TestDeregister(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
if err := mgr.Register(Service{
|
||||
Name: "temp",
|
||||
Source: "test",
|
||||
Domain: "temp.example.com",
|
||||
Source: "test",
|
||||
Backend: Backend{Address: "127.0.0.1:8080", Type: BackendHTTP},
|
||||
Reach: ReachInternal,
|
||||
}); err != nil {
|
||||
t.Fatalf("Register failed: %v", err)
|
||||
}
|
||||
|
||||
if err := mgr.Deregister("temp"); err != nil {
|
||||
if err := mgr.Deregister("temp.example.com"); err != nil {
|
||||
t.Fatalf("Deregister failed: %v", err)
|
||||
}
|
||||
|
||||
if _, err := mgr.Get("temp"); err == nil {
|
||||
if _, err := mgr.Get("temp.example.com"); err == nil {
|
||||
t.Error("expected error after deregister, got nil")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDeregisterBySource(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
// Register 3 services from wild-cloud with same backend
|
||||
for _, domain := range []string{"cloud.payne.io", "internal.cloud.payne.io", "payne.io"} {
|
||||
mgr.Register(Service{
|
||||
Domain: domain,
|
||||
Source: "wild-cloud",
|
||||
Backend: Backend{Address: "192.168.8.240:443", Type: BackendTCPPassthrough},
|
||||
Reach: ReachPublic,
|
||||
})
|
||||
}
|
||||
// Register 1 service from wild-works (different source)
|
||||
mgr.Register(Service{
|
||||
Domain: "my-api.payne.io",
|
||||
Source: "wild-works",
|
||||
Backend: Backend{Address: "127.0.0.1:9001", Type: BackendHTTP},
|
||||
Reach: ReachInternal,
|
||||
})
|
||||
|
||||
// Deregister all wild-cloud services with backend 192.168.8.240:443
|
||||
if err := mgr.DeregisterBySource("wild-cloud", "192.168.8.240:443"); err != nil {
|
||||
t.Fatalf("DeregisterBySource failed: %v", err)
|
||||
}
|
||||
|
||||
svcs, _ := mgr.List()
|
||||
if len(svcs) != 1 {
|
||||
t.Errorf("expected 1 remaining service, got %d", len(svcs))
|
||||
}
|
||||
if svcs[0].Domain != "my-api.payne.io" {
|
||||
t.Errorf("expected wild-works service to remain, got %s", svcs[0].Domain)
|
||||
}
|
||||
}
|
||||
|
||||
func TestUpdate(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
if err := mgr.Register(Service{
|
||||
Name: "updatable",
|
||||
Source: "test",
|
||||
mgr.Register(Service{
|
||||
Domain: "updatable.example.com",
|
||||
Source: "test",
|
||||
Backend: Backend{Address: "127.0.0.1:8080", Type: BackendHTTP},
|
||||
Reach: ReachInternal,
|
||||
}); err != nil {
|
||||
t.Fatalf("Register failed: %v", err)
|
||||
}
|
||||
})
|
||||
|
||||
if err := mgr.Update("updatable", map[string]any{
|
||||
"reach": "public",
|
||||
if err := mgr.Update("updatable.example.com", map[string]any{
|
||||
"reach": "public",
|
||||
"subdomains": true,
|
||||
}); err != nil {
|
||||
t.Fatalf("Update failed: %v", err)
|
||||
}
|
||||
|
||||
got, _ := mgr.Get("updatable")
|
||||
got, _ := mgr.Get("updatable.example.com")
|
||||
if got.Reach != ReachPublic {
|
||||
t.Errorf("expected reach public after update, got %s", got.Reach)
|
||||
}
|
||||
if !got.Subdomains {
|
||||
t.Error("expected subdomains=true after update")
|
||||
}
|
||||
}
|
||||
|
||||
func TestRegisterValidation(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
// Missing name
|
||||
if err := mgr.Register(Service{Domain: "x.com", Backend: Backend{Address: "127.0.0.1:80"}}); err == nil {
|
||||
t.Error("expected error for missing name")
|
||||
}
|
||||
|
||||
// Missing domain
|
||||
if err := mgr.Register(Service{Name: "x", Backend: Backend{Address: "127.0.0.1:80"}}); err == nil {
|
||||
if err := mgr.Register(Service{Backend: Backend{Address: "127.0.0.1:80", Type: BackendHTTP}, Reach: ReachInternal}); err == nil {
|
||||
t.Error("expected error for missing domain")
|
||||
}
|
||||
|
||||
// Missing backend
|
||||
if err := mgr.Register(Service{Name: "x", Domain: "x.com"}); err == nil {
|
||||
t.Error("expected error for missing backend")
|
||||
// Missing backend address
|
||||
if err := mgr.Register(Service{Domain: "x.com", Backend: Backend{Type: BackendHTTP}, Reach: ReachInternal}); err == nil {
|
||||
t.Error("expected error for missing backend address")
|
||||
}
|
||||
|
||||
// Missing backend type
|
||||
if err := mgr.Register(Service{Domain: "x.com", Backend: Backend{Address: "127.0.0.1:80"}, Reach: ReachInternal}); err == nil {
|
||||
t.Error("expected error for missing backend type")
|
||||
}
|
||||
|
||||
// Missing reach
|
||||
if err := mgr.Register(Service{Domain: "x.com", Backend: Backend{Address: "127.0.0.1:80", Type: BackendHTTP}}); err == nil {
|
||||
t.Error("expected error for missing reach")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDefaultSource(t *testing.T) {
|
||||
mgr := NewManager(t.TempDir())
|
||||
|
||||
mgr.Register(Service{
|
||||
Domain: "test.com",
|
||||
Backend: Backend{Address: "127.0.0.1:80", Type: BackendHTTP},
|
||||
Reach: ReachInternal,
|
||||
})
|
||||
|
||||
got, _ := mgr.Get("test.com")
|
||||
if got.Source != "manual" {
|
||||
t.Errorf("expected default source 'manual', got %s", got.Source)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDomainToFilename(t *testing.T) {
|
||||
tests := []struct {
|
||||
domain string
|
||||
expected string
|
||||
}{
|
||||
{"cloud.payne.io", "cloud_payne_io.yaml"},
|
||||
{"internal.cloud.payne.io", "internal_cloud_payne_io.yaml"},
|
||||
{"payne.io", "payne_io.yaml"},
|
||||
{"example.com", "example_com.yaml"},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
got := domainToFilename(tt.domain)
|
||||
if got != tt.expected {
|
||||
t.Errorf("domainToFilename(%q) = %q, want %q", tt.domain, got, tt.expected)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user