feat(P7): doctor ingress + docs + integration tests (REQ-177,178,179)
New 'orca doctor ingress' command: verifies podman orca-traefik
container running, nft DNAT+SNAT, /etc/traefik/dynamic exists,
step-ca root CA present.
UAT signoff script: replaced assertion 36 (systemd → podman
container), added assertions 40-46 (nft table, DNAT, SNAT, dynamic
dir, step-ca CA, traefik.yml, doctor ingress pass).
docs/ingress.md: R-024 podman traefik section — three topologies,
container config, nft ruleset, doctor ingress, Dockerfile.traefik.
TLS model updated (drop certResolver, tls:{} for v0.14, mTLS v0.15).
ARCHITECTURE.md: v0.14 deltas section — R-024, three topologies,
nft emitter changes, TLS model, migration 0009, new CLI.
Integration tests (tests/ingress_bootstrap_test.go): nft postrouting
+ DNATTarget, priority -10, traefik TLS model (tls:{} no
certResolver), image ref resolution, floating-IP LXC provisioning
commands (pct create with hwaddr/ip/gw/features), MAC generation.
---ci---
project: orca
phase: 7
milestone: v0.14
status: execute
---/ci---
This commit is contained in:
+71
-7
@@ -138,13 +138,77 @@ restore traffic).
|
||||
|
||||
## TLS
|
||||
|
||||
- **certResolver**: `orca` (references the Traefik ACME/step-ca
|
||||
certificate resolver configured in Traefik's static config).
|
||||
- **Trust domain**: `cluster.orca.local` (placeholder in v0.9; step-ca
|
||||
provisioner in v0.11 overrides with the real cluster trust domain).
|
||||
- **SPIFFE SVIDs**: workload identity via SPIFFE SVIDs minted at submit
|
||||
time via step-ca (v0.11-P01.5, gate C-08). The SVID is a URI SAN in
|
||||
the workload's X.509 cert.
|
||||
- **v0.14 model**: `tls: {}` in dynamic config (no certResolver).
|
||||
Traefik v3.3 `certificatesResolvers` only supports `acme` and
|
||||
`tailscale` — not CA-file-based. The `certResolver: orca` reference
|
||||
from v0.11 was broken (research finding). v0.14 emits `tls: {}`
|
||||
(traefik uses its default self-signed cert). Real mTLS via dynamic
|
||||
`tls.certificates` + `tls.options.default.clientAuth.caFiles` is
|
||||
deferred to v0.15.
|
||||
- **Step-ca root CA**: mounted at `/etc/orca/step-ca-root.crt` in the
|
||||
traefik container. v0.14 does not use it for TLS termination (it's
|
||||
a placeholder for v0.15 mTLS).
|
||||
|
||||
## R-024: Podman Traefik Container (v0.14)
|
||||
|
||||
As of v0.14, Traefik runs as a **podman container** from the custom
|
||||
`orca-traefik` image (published per release). The v0.13 binary+systemd
|
||||
install is replaced.
|
||||
|
||||
### Three topologies
|
||||
|
||||
1. **Linux**: host → nft DNAT → `podman run orca-traefik` (`--network host`)
|
||||
2. **Proxmox Native** (`--ingress-mode native`, default): PVE host →
|
||||
nft DNAT → LXC (nesting=1,keyctl=1,fuse=1) → `podman run orca-traefik`
|
||||
3. **Proxmox Floating-IP** (`--ingress-mode floating-ip`): LXC owns
|
||||
the floating IP → nft inside LXC → `podman run orca-traefik`
|
||||
|
||||
### Container configuration
|
||||
|
||||
```bash
|
||||
podman run -d --name orca-traefik --restart=unless-stopped \
|
||||
--network host \
|
||||
-v /etc/traefik/traefik.yml:/etc/traefik/traefik.yml:ro \
|
||||
-v /etc/traefik/dynamic:/etc/traefik/dynamic:ro \
|
||||
-v /etc/orca/step-ca-root.crt:/etc/orca/step-ca-root.crt:ro \
|
||||
git.cloudinit.dev/coreci/orca-traefik:<version>
|
||||
```
|
||||
|
||||
- `--network host`: traefik binds 127.0.0.1:8080/8443 on host/LXC loopback
|
||||
- `--restart=unless-stopped`: survives reboot via `podman-restart.service`
|
||||
- No `:Z` SELinux flag (research Topic 7)
|
||||
- Static config mounted `:ro` (overrides baked image default, preserves
|
||||
`traefik-on-public-ip` opt-out, REQ-100)
|
||||
|
||||
### nft ruleset
|
||||
|
||||
The nft emitter (`internal/emitter/nft.go`) renders `/etc/nftables.d/orca.nft`:
|
||||
|
||||
- DNAT `:443` → `<DNATTarget>:8443` (default 127.0.0.1; LXC IP for native)
|
||||
- DNAT `:80` → `<DNATTarget>:8080`
|
||||
- SNAT/MASQUERADE: `ip saddr 127.0.0.0/8 oifname != "lo" masquerade`
|
||||
- Input/forward chains at priority -10 (pve-firewall coexistence)
|
||||
|
||||
### `orca doctor ingress`
|
||||
|
||||
```bash
|
||||
orca doctor ingress # check localhost
|
||||
orca doctor ingress --peer <name> # check remote peer
|
||||
```
|
||||
|
||||
Verifies: podman container running, nft DNAT+SNAT, dynamic dir exists,
|
||||
step-ca root CA present.
|
||||
|
||||
### Dockerfile.traefik
|
||||
|
||||
```dockerfile
|
||||
FROM traefik:v3.3.0
|
||||
COPY docker/orca-traefik/traefik.yml /etc/traefik/traefik.yml
|
||||
CMD ["--configFile=/etc/traefik/traefik.yml"]
|
||||
```
|
||||
|
||||
Built + published per release alongside the orca image
|
||||
(`scripts/release.sh` + `.coreci.yml container-publish-traefik`).
|
||||
|
||||
## Health checks
|
||||
|
||||
|
||||
Reference in New Issue
Block a user