Skip to content

Validation

BaddKharma edited this page Sep 28, 2026 · 6 revisions

Validation

Validation lives in the topology layer, not the compiler. A redirector with no upstream teamserver, a segment with unintended egress, a host with no reachable management path: these light up live in the canvas, and the compiler refuses to run on an invalid topology.

Every finding carries a machine-readable code and prose written for a person. The code lets tooling react; the prose says what to do.

Findings

The current codes, by family. The full text for each lives in docs/validation.md.

Redirectors (RDR)

  • RDR001 (error): a redirector has no domain, or its domain is still a placeholder. A domain has to be registered and pointed at the box by hand. Supply one you control.
  • RDR002 (warning): a cover knob is set that needs an asset pack but none was supplied. The page falls back and is fine; the flag stops a knob that looks applied from being a silent no-op.

Management path (MGT)

Findings that keep every managed host reachable. MGT001, for example, catches a host with no management path: nothing manages its segment or network, and it is not directly reachable.

Exposure (EXP)

Exposure is a ceiling. EXP001 through EXP003, plus EXP005, catch a host whose exposure does not match what its segment allows. EXP005 is a host asking for a public address in a segment that permits none, which would read as exposed and deploy as unreachable.

Boot and ordering

  • BOOT001 (warning): a jumpbox on a WireGuard transport needs a two-stage play order, because Ansible cannot configure WireGuard over WireGuard.
  • ORD001 (error): a cycle in the play order derived from the edges. It means the topology is wrong, not the ordering logic.

Compiling a shipped example

Shipped examples that carry a redirector arrive one field short on purpose (see RDR001). Pass a domain you control:

redstackpro compile <template> --hostname your-domain.example -o export

Clone this wiki locally