Phase D: Automated DNS registration via MCNS
Add DNSRegistrar that creates/updates/deletes A records in MCNS during deploy and stop. When a service has routes, the agent ensures an A record exists in the configured zone pointing to the node's address. On stop, the record is removed. - Add MCNSConfig to agent config (server_url, ca_cert, token_path, zone, node_addr) with defaults and env overrides - Add DNSRegistrar (internal/agent/dns.go): REST client for MCNS record CRUD, nil-receiver safe - Wire into deploy flow (EnsureRecord after route registration) - Wire into stop flow (RemoveRecord before container stop) - 7 new tests, make all passes with 0 issues Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -34,6 +34,7 @@ type Agent struct {
|
||||
PortAlloc *PortAllocator
|
||||
Proxy *ProxyRouter
|
||||
Certs *CertProvisioner
|
||||
DNS *DNSRegistrar
|
||||
}
|
||||
|
||||
// Run starts the agent: opens the database, sets up the gRPC server with
|
||||
@@ -63,6 +64,11 @@ func Run(cfg *config.AgentConfig) error {
|
||||
return fmt.Errorf("create cert provisioner: %w", err)
|
||||
}
|
||||
|
||||
dns, err := NewDNSRegistrar(cfg.MCNS, logger)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create DNS registrar: %w", err)
|
||||
}
|
||||
|
||||
a := &Agent{
|
||||
Config: cfg,
|
||||
DB: db,
|
||||
@@ -72,6 +78,7 @@ func Run(cfg *config.AgentConfig) error {
|
||||
PortAlloc: NewPortAllocator(),
|
||||
Proxy: proxy,
|
||||
Certs: certs,
|
||||
DNS: dns,
|
||||
}
|
||||
|
||||
tlsCert, err := tls.LoadX509KeyPair(cfg.Server.TLSCert, cfg.Server.TLSKey)
|
||||
|
||||
@@ -164,6 +164,13 @@ func (a *Agent) deployComponent(ctx context.Context, serviceName string, cs *mcp
|
||||
}
|
||||
}
|
||||
|
||||
// Register DNS record for the service.
|
||||
if a.DNS != nil && len(regRoutes) > 0 {
|
||||
if err := a.DNS.EnsureRecord(ctx, serviceName); err != nil {
|
||||
a.Logger.Warn("failed to register DNS record", "service", serviceName, "err", err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := registry.UpdateComponentState(a.DB, serviceName, compName, "running", "running"); err != nil {
|
||||
a.Logger.Warn("failed to update component state", "service", serviceName, "component", compName, "err", err)
|
||||
}
|
||||
|
||||
260
internal/agent/dns.go
Normal file
260
internal/agent/dns.go
Normal file
@@ -0,0 +1,260 @@
|
||||
package agent
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"git.wntrmute.dev/mc/mcp/internal/auth"
|
||||
"git.wntrmute.dev/mc/mcp/internal/config"
|
||||
)
|
||||
|
||||
// DNSRegistrar creates and removes A records in MCNS during deploy
|
||||
// and stop. It is nil-safe: all methods are no-ops when the receiver
|
||||
// is nil.
|
||||
type DNSRegistrar struct {
|
||||
serverURL string
|
||||
token string
|
||||
zone string
|
||||
nodeAddr string
|
||||
httpClient *http.Client
|
||||
logger *slog.Logger
|
||||
}
|
||||
|
||||
// dnsRecord is the JSON representation of an MCNS record.
|
||||
type dnsRecord struct {
|
||||
ID int `json:"id"`
|
||||
Name string `json:"name"`
|
||||
Type string `json:"type"`
|
||||
Value string `json:"value"`
|
||||
TTL int `json:"ttl"`
|
||||
}
|
||||
|
||||
// NewDNSRegistrar creates a DNSRegistrar. Returns (nil, nil) if
|
||||
// cfg.ServerURL is empty (DNS registration disabled).
|
||||
func NewDNSRegistrar(cfg config.MCNSConfig, logger *slog.Logger) (*DNSRegistrar, error) {
|
||||
if cfg.ServerURL == "" {
|
||||
logger.Info("mcns not configured, DNS registration disabled")
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
token, err := auth.LoadToken(cfg.TokenPath)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("load mcns token: %w", err)
|
||||
}
|
||||
|
||||
httpClient, err := newTLSClient(cfg.CACert)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("create mcns HTTP client: %w", err)
|
||||
}
|
||||
|
||||
logger.Info("mcns DNS registrar enabled", "server", cfg.ServerURL, "zone", cfg.Zone, "node_addr", cfg.NodeAddr)
|
||||
return &DNSRegistrar{
|
||||
serverURL: strings.TrimRight(cfg.ServerURL, "/"),
|
||||
token: token,
|
||||
zone: cfg.Zone,
|
||||
nodeAddr: cfg.NodeAddr,
|
||||
httpClient: httpClient,
|
||||
logger: logger,
|
||||
}, nil
|
||||
}
|
||||
|
||||
// EnsureRecord ensures an A record exists for the service in the
|
||||
// configured zone, pointing to the node's address.
|
||||
func (d *DNSRegistrar) EnsureRecord(ctx context.Context, serviceName string) error {
|
||||
if d == nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
existing, err := d.listRecords(ctx, serviceName)
|
||||
if err != nil {
|
||||
return fmt.Errorf("list DNS records: %w", err)
|
||||
}
|
||||
|
||||
if len(existing) > 0 {
|
||||
r := existing[0]
|
||||
if r.Value == d.nodeAddr {
|
||||
d.logger.Debug("DNS record exists, skipping",
|
||||
"service", serviceName,
|
||||
"record", r.Name+"."+d.zone,
|
||||
"value", r.Value,
|
||||
)
|
||||
return nil
|
||||
}
|
||||
// Wrong value — update it.
|
||||
d.logger.Info("updating DNS record",
|
||||
"service", serviceName,
|
||||
"old_value", r.Value,
|
||||
"new_value", d.nodeAddr,
|
||||
)
|
||||
return d.updateRecord(ctx, r.ID, serviceName)
|
||||
}
|
||||
|
||||
// No existing record — create one.
|
||||
d.logger.Info("creating DNS record",
|
||||
"service", serviceName,
|
||||
"record", serviceName+"."+d.zone,
|
||||
"value", d.nodeAddr,
|
||||
)
|
||||
return d.createRecord(ctx, serviceName)
|
||||
}
|
||||
|
||||
// RemoveRecord removes A records for the service from the configured zone.
|
||||
func (d *DNSRegistrar) RemoveRecord(ctx context.Context, serviceName string) error {
|
||||
if d == nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
existing, err := d.listRecords(ctx, serviceName)
|
||||
if err != nil {
|
||||
return fmt.Errorf("list DNS records: %w", err)
|
||||
}
|
||||
|
||||
if len(existing) == 0 {
|
||||
d.logger.Debug("no DNS record to remove", "service", serviceName)
|
||||
return nil
|
||||
}
|
||||
|
||||
for _, r := range existing {
|
||||
d.logger.Info("removing DNS record",
|
||||
"service", serviceName,
|
||||
"record", r.Name+"."+d.zone,
|
||||
"id", r.ID,
|
||||
)
|
||||
if err := d.deleteRecord(ctx, r.ID); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// listRecords returns A records matching the service name in the zone.
|
||||
func (d *DNSRegistrar) listRecords(ctx context.Context, serviceName string) ([]dnsRecord, error) {
|
||||
url := fmt.Sprintf("%s/v1/zones/%s/records?name=%s&type=A", d.serverURL, d.zone, serviceName)
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, nil)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("create list request: %w", err)
|
||||
}
|
||||
req.Header.Set("Authorization", "Bearer "+d.token)
|
||||
|
||||
resp, err := d.httpClient.Do(req)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("list records: %w", err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("read list response: %w", err)
|
||||
}
|
||||
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
return nil, fmt.Errorf("list records: mcns returned %d: %s", resp.StatusCode, string(body))
|
||||
}
|
||||
|
||||
var records []dnsRecord
|
||||
if err := json.Unmarshal(body, &records); err != nil {
|
||||
return nil, fmt.Errorf("parse list response: %w", err)
|
||||
}
|
||||
return records, nil
|
||||
}
|
||||
|
||||
// createRecord creates an A record in the zone.
|
||||
func (d *DNSRegistrar) createRecord(ctx context.Context, serviceName string) error {
|
||||
reqBody := map[string]interface{}{
|
||||
"name": serviceName,
|
||||
"type": "A",
|
||||
"value": d.nodeAddr,
|
||||
"ttl": 300,
|
||||
}
|
||||
|
||||
body, err := json.Marshal(reqBody)
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshal create request: %w", err)
|
||||
}
|
||||
|
||||
url := fmt.Sprintf("%s/v1/zones/%s/records", d.serverURL, d.zone)
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, bytes.NewReader(body))
|
||||
if err != nil {
|
||||
return fmt.Errorf("create record request: %w", err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("Authorization", "Bearer "+d.token)
|
||||
|
||||
resp, err := d.httpClient.Do(req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create record: %w", err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
if resp.StatusCode != http.StatusCreated && resp.StatusCode != http.StatusOK {
|
||||
respBody, _ := io.ReadAll(resp.Body)
|
||||
return fmt.Errorf("create record: mcns returned %d: %s", resp.StatusCode, string(respBody))
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// updateRecord updates an existing record's value.
|
||||
func (d *DNSRegistrar) updateRecord(ctx context.Context, recordID int, serviceName string) error {
|
||||
reqBody := map[string]interface{}{
|
||||
"name": serviceName,
|
||||
"type": "A",
|
||||
"value": d.nodeAddr,
|
||||
"ttl": 300,
|
||||
}
|
||||
|
||||
body, err := json.Marshal(reqBody)
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshal update request: %w", err)
|
||||
}
|
||||
|
||||
url := fmt.Sprintf("%s/v1/zones/%s/records/%d", d.serverURL, d.zone, recordID)
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodPut, url, bytes.NewReader(body))
|
||||
if err != nil {
|
||||
return fmt.Errorf("create update request: %w", err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
req.Header.Set("Authorization", "Bearer "+d.token)
|
||||
|
||||
resp, err := d.httpClient.Do(req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("update record: %w", err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
respBody, _ := io.ReadAll(resp.Body)
|
||||
return fmt.Errorf("update record: mcns returned %d: %s", resp.StatusCode, string(respBody))
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// deleteRecord deletes a record by ID.
|
||||
func (d *DNSRegistrar) deleteRecord(ctx context.Context, recordID int) error {
|
||||
url := fmt.Sprintf("%s/v1/zones/%s/records/%d", d.serverURL, d.zone, recordID)
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodDelete, url, nil)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create delete request: %w", err)
|
||||
}
|
||||
req.Header.Set("Authorization", "Bearer "+d.token)
|
||||
|
||||
resp, err := d.httpClient.Do(req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("delete record: %w", err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
if resp.StatusCode != http.StatusNoContent && resp.StatusCode != http.StatusOK {
|
||||
respBody, _ := io.ReadAll(resp.Body)
|
||||
return fmt.Errorf("delete record: mcns returned %d: %s", resp.StatusCode, string(respBody))
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
214
internal/agent/dns_test.go
Normal file
214
internal/agent/dns_test.go
Normal file
@@ -0,0 +1,214 @@
|
||||
package agent
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
|
||||
"git.wntrmute.dev/mc/mcp/internal/config"
|
||||
)
|
||||
|
||||
func TestNilDNSRegistrarIsNoop(t *testing.T) {
|
||||
var d *DNSRegistrar
|
||||
if err := d.EnsureRecord(context.Background(), "svc"); err != nil {
|
||||
t.Fatalf("EnsureRecord on nil: %v", err)
|
||||
}
|
||||
if err := d.RemoveRecord(context.Background(), "svc"); err != nil {
|
||||
t.Fatalf("RemoveRecord on nil: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestNewDNSRegistrarDisabledWhenUnconfigured(t *testing.T) {
|
||||
d, err := NewDNSRegistrar(config.MCNSConfig{}, slog.Default())
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if d != nil {
|
||||
t.Fatal("expected nil registrar for empty config")
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureRecordCreatesWhenMissing(t *testing.T) {
|
||||
var gotMethod, gotPath, gotAuth string
|
||||
var gotBody map[string]interface{}
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method == http.MethodGet {
|
||||
// List returns empty — no existing records.
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write([]byte("[]"))
|
||||
return
|
||||
}
|
||||
gotMethod = r.Method
|
||||
gotPath = r.URL.Path
|
||||
gotAuth = r.Header.Get("Authorization")
|
||||
_ = json.NewDecoder(r.Body).Decode(&gotBody)
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
_, _ = w.Write([]byte(`{"id":1}`))
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
d := &DNSRegistrar{
|
||||
serverURL: srv.URL,
|
||||
token: "test-token",
|
||||
zone: "svc.mcp.metacircular.net",
|
||||
nodeAddr: "192.168.88.181",
|
||||
httpClient: srv.Client(),
|
||||
logger: slog.Default(),
|
||||
}
|
||||
|
||||
if err := d.EnsureRecord(context.Background(), "myservice"); err != nil {
|
||||
t.Fatalf("EnsureRecord: %v", err)
|
||||
}
|
||||
|
||||
if gotMethod != http.MethodPost {
|
||||
t.Fatalf("method: got %q, want POST", gotMethod)
|
||||
}
|
||||
if gotPath != "/v1/zones/svc.mcp.metacircular.net/records" {
|
||||
t.Fatalf("path: got %q", gotPath)
|
||||
}
|
||||
if gotAuth != "Bearer test-token" {
|
||||
t.Fatalf("auth: got %q", gotAuth)
|
||||
}
|
||||
if gotBody["name"] != "myservice" {
|
||||
t.Fatalf("name: got %v", gotBody["name"])
|
||||
}
|
||||
if gotBody["type"] != "A" {
|
||||
t.Fatalf("type: got %v", gotBody["type"])
|
||||
}
|
||||
if gotBody["value"] != "192.168.88.181" {
|
||||
t.Fatalf("value: got %v", gotBody["value"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureRecordSkipsWhenExists(t *testing.T) {
|
||||
createCalled := false
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method == http.MethodGet {
|
||||
// Return an existing record with the correct value.
|
||||
records := []dnsRecord{{ID: 1, Name: "myservice", Type: "A", Value: "192.168.88.181", TTL: 300}}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_ = json.NewEncoder(w).Encode(records)
|
||||
return
|
||||
}
|
||||
createCalled = true
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
d := &DNSRegistrar{
|
||||
serverURL: srv.URL,
|
||||
token: "test-token",
|
||||
zone: "svc.mcp.metacircular.net",
|
||||
nodeAddr: "192.168.88.181",
|
||||
httpClient: srv.Client(),
|
||||
logger: slog.Default(),
|
||||
}
|
||||
|
||||
if err := d.EnsureRecord(context.Background(), "myservice"); err != nil {
|
||||
t.Fatalf("EnsureRecord: %v", err)
|
||||
}
|
||||
if createCalled {
|
||||
t.Fatal("should not create when record already exists with correct value")
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureRecordUpdatesWrongValue(t *testing.T) {
|
||||
var gotMethod string
|
||||
var gotPath string
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method == http.MethodGet {
|
||||
// Return a record with a stale value.
|
||||
records := []dnsRecord{{ID: 42, Name: "myservice", Type: "A", Value: "10.0.0.1", TTL: 300}}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_ = json.NewEncoder(w).Encode(records)
|
||||
return
|
||||
}
|
||||
gotMethod = r.Method
|
||||
gotPath = r.URL.Path
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
d := &DNSRegistrar{
|
||||
serverURL: srv.URL,
|
||||
token: "test-token",
|
||||
zone: "svc.mcp.metacircular.net",
|
||||
nodeAddr: "192.168.88.181",
|
||||
httpClient: srv.Client(),
|
||||
logger: slog.Default(),
|
||||
}
|
||||
|
||||
if err := d.EnsureRecord(context.Background(), "myservice"); err != nil {
|
||||
t.Fatalf("EnsureRecord: %v", err)
|
||||
}
|
||||
if gotMethod != http.MethodPut {
|
||||
t.Fatalf("method: got %q, want PUT", gotMethod)
|
||||
}
|
||||
if gotPath != "/v1/zones/svc.mcp.metacircular.net/records/42" {
|
||||
t.Fatalf("path: got %q", gotPath)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRemoveRecordDeletes(t *testing.T) {
|
||||
var gotMethod, gotPath string
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method == http.MethodGet {
|
||||
records := []dnsRecord{{ID: 7, Name: "myservice", Type: "A", Value: "192.168.88.181", TTL: 300}}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_ = json.NewEncoder(w).Encode(records)
|
||||
return
|
||||
}
|
||||
gotMethod = r.Method
|
||||
gotPath = r.URL.Path
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
d := &DNSRegistrar{
|
||||
serverURL: srv.URL,
|
||||
token: "test-token",
|
||||
zone: "svc.mcp.metacircular.net",
|
||||
nodeAddr: "192.168.88.181",
|
||||
httpClient: srv.Client(),
|
||||
logger: slog.Default(),
|
||||
}
|
||||
|
||||
if err := d.RemoveRecord(context.Background(), "myservice"); err != nil {
|
||||
t.Fatalf("RemoveRecord: %v", err)
|
||||
}
|
||||
if gotMethod != http.MethodDelete {
|
||||
t.Fatalf("method: got %q, want DELETE", gotMethod)
|
||||
}
|
||||
if gotPath != "/v1/zones/svc.mcp.metacircular.net/records/7" {
|
||||
t.Fatalf("path: got %q", gotPath)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRemoveRecordNoopWhenMissing(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
// List returns empty.
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_, _ = w.Write([]byte("[]"))
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
d := &DNSRegistrar{
|
||||
serverURL: srv.URL,
|
||||
token: "test-token",
|
||||
zone: "svc.mcp.metacircular.net",
|
||||
nodeAddr: "192.168.88.181",
|
||||
httpClient: srv.Client(),
|
||||
logger: slog.Default(),
|
||||
}
|
||||
|
||||
if err := d.RemoveRecord(context.Background(), "myservice"); err != nil {
|
||||
t.Fatalf("RemoveRecord: %v", err)
|
||||
}
|
||||
}
|
||||
@@ -37,6 +37,13 @@ func (a *Agent) StopService(ctx context.Context, req *mcpv1.StopServiceRequest)
|
||||
}
|
||||
}
|
||||
|
||||
// Remove DNS record when stopping the service.
|
||||
if len(c.Routes) > 0 && a.DNS != nil {
|
||||
if err := a.DNS.RemoveRecord(ctx, req.GetName()); err != nil {
|
||||
a.Logger.Warn("failed to remove DNS record", "service", req.GetName(), "err", err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := a.Runtime.Stop(ctx, containerName); err != nil {
|
||||
a.Logger.Info("stop container (ignored)", "container", containerName, "error", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user