Skip to content

daemon: report the real endpoint on a private network and keep -advertise-endpoint across re-registration - #491

Merged
TeoSlayer merged 5 commits into
mainfrom
fix/loopback-endpoint
Oct 1, 2026
Merged

TeoSlayer merged 5 commits into
mainfrom
fix/loopback-endpoint

Conversation

@TeoSlayer

Copy link
Copy Markdown
Collaborator

Pull Request

Summary

Two endpoint fixes found while running nodes in containers.

Changes

  • -advertise-endpoint survives a re-registration. reRegister (registry reconnect, transport watchdog recovery) sent the tunnel socket's local address instead of the advertised endpoint, so the registry replaced the operator's address with <observed-ip>:<local port>. The override is now applied on re-registration as it is at start. This is the case the flag exists for (pods behind a CNI).
  • On a private network the daemon reports the endpoint peers actually use, not loopback. With a wildcard listen address the daemon registers [::1]:port; the registry rewrites a loopback or private host to the source IP it observed, so peers resolve the right address — but the daemon only adopted that observed address when it was public, and kept showing loopback in pilotctl info, the "daemon registered" log line and registration events. It now adopts the observed private host with its own tunnel port when its local address is loopback. Display only: nothing different is sent.

Not changed, deliberately: registering the STUN-reported address. -listen defaults to :0, so the temporary STUN socket and the tunnel socket have different ports; the STUN address would advertise a dead port.

Test Plan

  • go build ./..., go vet ./..., unit suite and full go test -parallel 4 -count=1 ./tests/ with GOWORK=off
  • TestPrivateNetworkEndpointReported (fails on main: daemon reports [::1]:port while peers resolve the LAN address)
  • Unit test for the advertised endpoint on re-registration

Checklist

  • New code includes the SPDX license header
  • go.mod / go.sum unchanged
  • CHANGELOG updated

🤖 Generated with Claude Code

Teo Calin and others added 5 commits October 1, 2026 17:39
…back

On a private network (container bridge, lab LAN) STUN reflects a private
address, which is discarded, and the daemon registers the loopback form of
its wildcard tunnel socket. The registry replaces that host with the one it
observed, so peers resolve <private-ip>:<tunnel port>, but the daemon only
adopted a registry-observed address when it was public and so kept logging
and reporting [::1]:<port>. Adopt the observed private host when our own
address is loopback. Display only: nothing sent to the registry changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
reRegister rebuilt the registration address from -endpoint or the tunnel
socket only, so after a registry reconnect or a watchdog soft recovery the
registry held <observed-ip>:<local port> instead of the advertised endpoint.
Apply the same override Start applies.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@TeoSlayer
TeoSlayer merged commit 4e5b1fe into main Oct 1, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant