-
Notifications
You must be signed in to change notification settings - Fork 10
Validation
Validation lives in the topology layer, not the compiler. A redirector with no upstream teamserver, a segment with unintended egress, a host with no reachable management path: these light up live in the canvas, and the compiler refuses to run on an invalid topology.
Every finding carries a machine-readable code and prose written for a person. The code lets tooling react; the prose says what to do.
The current codes, by family. The full text for each lives in docs/validation.md.
-
RDR001(error): a redirector has no domain, or its domain is still a placeholder. A domain has to be registered and pointed at the box by hand. Supply one you control. -
RDR002(warning): a cover knob is set that needs an asset pack but none was supplied. The page falls back and is fine; the flag stops a knob that looks applied from being a silent no-op.
Findings that keep every managed host reachable. MGT001, for example, catches a host
with no management path: nothing manages its segment or network, and it is not directly
reachable.
Exposure is a ceiling. EXP001 through EXP005 catch a host asking to be more exposed
than its segment allows. EXP005 is a host asking for a public address in a segment that
permits none, which would read as exposed and deploy as unreachable.
-
BOOT001(warning): a jumpbox on a WireGuard transport needs a two-stage play order, because Ansible cannot configure WireGuard over WireGuard. -
ORD001(error): a cycle in the play order derived from the edges. It means the topology is wrong, not the ordering logic.
Shipped examples that carry a redirector arrive one field short on purpose (see
RDR001). Pass a domain you control:
redstackpro compile <template> --hostname your-domain.example -o export