Wire wake and identity into crossbar; v2 smoke and README
Implemented-By: OpenCode session (model recorded in docs/implementer-log.md)
This commit is contained in:
@@ -59,6 +59,9 @@ hosts = ["beta", "alpha"]
|
||||
| `hosts.<name>.models` | The models this host serves, with per-model parallel tuning. |
|
||||
| `routes.<name>.hosts` | Candidate hosts, tried in order until one is healthy; a conversation leases one of them. |
|
||||
| `routes.<name>.default_model` | Model used when a request omits one; must be served by a host in the route. |
|
||||
| `identity` | `"off"` (default), `"tailscale"`, or `"header"`; see below. |
|
||||
| `hosts.<name>.wake` | A wake-on-LAN target (`mac`, `broadcast`, `wait`) so crossbar can rouse a sleeping host when nothing else can take a new lease. |
|
||||
| `routes.<name>.peers` | The tailnet nodes allowed to reach the route, with `identity = "tailscale"`; see below. |
|
||||
|
||||
## Run
|
||||
|
||||
@@ -159,7 +162,29 @@ crossbar_host_healthy{host="alpha"} 1
|
||||
crossbar_host_healthy{host="beta"} 1
|
||||
```
|
||||
|
||||
## What v1 does not do
|
||||
## Wake
|
||||
|
||||
The context-size guard, wake-on-LAN, Tailscale identity and `/slots` are out of scope for v1; see
|
||||
`PLAN.md` v2.
|
||||
When a route has no healthy host left and at least one candidate lists a `wake` target, crossbar
|
||||
sends that host a wake-on-LAN magic packet, in route order, and retries the lease once. A host that
|
||||
wakes up takes the conversation; if none wakes, the request gets `503 {"error":"no healthy host",
|
||||
"woke":["<hosts tried>"]}`. The context-size guard wakes a sleeping host the same way before it
|
||||
answers `400 prompt too large`, when no healthy host's per-slot context can fit the prompt.
|
||||
|
||||
## Identity
|
||||
|
||||
`identity` gates who may use a route. With the default `"off"` every request is admitted. With
|
||||
`"tailscale"`, a route that lists `peers` answers `403` to any caller whose tailnet address is not
|
||||
one of them (checked with `tailscale whois`):
|
||||
|
||||
```toml
|
||||
[routes.hermes-x]
|
||||
hosts = ["beta", "alpha"]
|
||||
peers = ["talos"]
|
||||
```
|
||||
|
||||
`"header"` trusts the `X-Crossbar-Peer` header instead and needs no tailnet; it is insecure and for
|
||||
tests only, so crossbar logs a warning when it starts in that mode.
|
||||
|
||||
## What v2 does not do
|
||||
|
||||
Request coalescing, `/slots` and TLS are out of scope for v2; see `PLAN.md`.
|
||||
|
||||
Reference in New Issue
Block a user