Skip to content

v0.2.2

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 03 Sep 11:30
9cec717

The release where the command line became usable and the page became something to
look at. Nothing about the data plane changed; everything about reaching it did.

Still pre-alpha. Every packet goes through a relay — there are no direct
peer-to-peer paths yet, so throughput and latency are worse than any mature mesh
and a self-hoster pays for that bandwidth. There are no mobile clients. Access
policy is enforced on Linux only.

The command line does things now

v0.2.1 shipped seven commands, all of them about the machine they ran on, and a
help text advertising ten nouns and thirty-seven verbs that did not exist. That
help now lists only what works, and what works is five nouns:

  • meshp device — list, revoke, forget. Names as well as ids, because an id
    is a UUID nobody has memorised.
  • meshp network — list, show, use, create. use remembers which network
    commands act on, so --network is optional after the first time.
  • meshp acl — show, edit, test, apply, versions. The policy is edited as a
    document, parsed before it is sent, and shown as a diff against what is live.
  • meshp dns — list, add, remove.
  • meshp token — list, create, revoke, for the API tokens meshp login mints.

Every one is a client of a route that already existed. None of them added an
endpoint, which is the point: the API is the contract three clients share
(ADR-0009), and a verb that needed an endpoint shaped for it would be a verb
defining the API.

See what a policy does before publishing it

POST /networks/{id}/acl/test compiles a document for one named device and
returns the packet filter it would actually enforce, without storing anything.
Selectors become the prefixes allocated to real devices, and each device is shown
its own side of a rule.

Reachable as meshp acl test <device> [--file p.json] and from the page. It is
compiled the way the session builder compiles it, so the answer is what the device
would be sent rather than a second implementation's opinion of it.

The page

A diagram of the network, which is a hub rather than a mesh because that is
what the network is — drawing a line between two devices would show a path that
does not exist. Devices carrying a prefix or reporting a fault are drawn and
named; past a couple of dozen the rest are counted rather than crowded.

An access policy editor: the document as text, diffed against what is live,
with the dry-run above as its last step. Refusing to publish a policy identical to
the one in force, because a version history where half the entries changed nothing
cannot be read backwards.

And a layout — the verdict, then the devices, then the things that change a
network. It was eight identical cards in the order they were written.

Devices can be erased, not only revoked

Since v0.2.1: DELETE /organizations/{id}/devices/{id} removes a device, its
memberships and its keys from every network at once, leaving the audit trail
behind. Revoking cuts a device out and leaves it visible; this leaves nothing.

Upgrading from v0.2.1

Nothing invalidates an existing deployment and no migration is needed — the schema
is unchanged at 17. meshp --help will list fewer commands than it used to, which
is the correction rather than a regression: the ones it stops advertising never
worked.

What's Changed

  • docs: ADR-0032, the UI and the CLI are clients of the API by @aswinsam in #220
  • refactor(web): move the reconciler into its own module by @aswinsam in #221
  • test(web): the reconciler is checked by a machine by @aswinsam in #222
  • fix(cli): the help offers only what the binary does by @aswinsam in #224
  • test(web): the page's own controls are checked by a machine by @aswinsam in #225
  • feat(cli): meshp device, the first noun by @aswinsam in #226
  • feat(cli): meshp network, and a choice that sticks by @aswinsam in #227
  • feat(cli): meshp acl, a policy edited as a document by @aswinsam in #228
  • feat(acl): see what a device would enforce before publishing by @aswinsam in #229
  • feat(web): the policy is edited on the page, as a document by @aswinsam in #230
  • fix(web): lay the page out around what somebody came for by @aswinsam in #231
  • feat(web): the network, as a picture by @aswinsam in #232
  • fix(web): sign in down a column, not across a screen by @aswinsam in #233
  • feat(cli): meshp dns and meshp token by @aswinsam in #234

Full Changelog: v0.2.1...v0.2.2