-
Notifications
You must be signed in to change notification settings - Fork 7
Validation
Validation lives in the topology layer, not the compiler. A redirector with no upstream teamserver, a segment with unintended egress, a host with no reachable management path: these light up live in the canvas, and the compiler refuses to run on an invalid topology.
Every finding carries a machine-readable code and prose written for a person. The code lets tooling react; the prose says what to do.
The families you meet most often are below. The full list, with the text for every code, is in docs/validation.md. The other families cover naming (NAM), networks and segments (NET), referential integrity (REF), cardinality (CAR), provider capability (CAP), the range model (RNG), VPN access (VPN), peering (PEER), endpoint kinds (END), collectors (LOG), and fronting (FRT).
-
RDR001(error): a redirector has no domain, or its domain is still a placeholder. A domain has to be registered and pointed at the box by hand. Supply one you control. -
RDR002(warning): a cover knob is set that needs an asset pack but none was supplied. The page falls back and is fine; the flag stops a knob that looks applied from being a silent no-op.
Keeps every managed host reachable.
-
MGT001(error): a host has no management path. Nothing manages its segment or network, and it is not directly reachable. The jumpbox, and any host that already holds a public address, are exempt.
Exposure is a ceiling: a host cannot be more reachable than its segment allows.
-
EXP001(error): a jumpbox or redirector with no public address, because its segment forbids one or its ownpublic_addressis false. -
EXP002(error): a teamserver, collector, or operator holding a public address. Public addresses belong only on redirectors and jumpboxes. -
EXP003(error): a host in a segment withegress: nonethat still needs a package installed. Nothing installs offline. -
EXP005(error): a host asking for a public address in a segment whose exposure permits none, which would read as exposed and deploy as unreachable.
-
ORD001(error): a cycle in the play order derived from the edges. It means the topology is wrong, not the ordering logic.
A jumpbox on a WireGuard transport gets a two-stage play order in the export, because Ansible cannot configure WireGuard over WireGuard. The compiler splits bootstrap from tunnel bring-up automatically, so it is not a validation finding.
Shipped examples that carry a redirector arrive one field short on purpose (see
RDR001). Pass a domain you control:
redstackpro compile <blueprint> --hostname your-domain.example -o export