Repository navigation
daemon: report the real endpoint on a private network and keep -advertise-endpoint across re-registration - #491
Merged
Merged
Conversation
…back On a private network (container bridge, lab LAN) STUN reflects a private address, which is discarded, and the daemon registers the loopback form of its wildcard tunnel socket. The registry replaces that host with the one it observed, so peers resolve <private-ip>:<tunnel port>, but the daemon only adopted a registry-observed address when it was public and so kept logging and reporting [::1]:<port>. Adopt the observed private host when our own address is loopback. Display only: nothing sent to the registry changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
reRegister rebuilt the registration address from -endpoint or the tunnel socket only, so after a registry reconnect or a watchdog soft recovery the registry held <observed-ip>:<local port> instead of the advertised endpoint. Apply the same override Start applies. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # CHANGELOG.md
# Conflicts: # CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Summary
Two endpoint fixes found while running nodes in containers.
Changes
-advertise-endpointsurvives a re-registration.reRegister(registry reconnect, transport watchdog recovery) sent the tunnel socket's local address instead of the advertised endpoint, so the registry replaced the operator's address with<observed-ip>:<local port>. The override is now applied on re-registration as it is at start. This is the case the flag exists for (pods behind a CNI).[::1]:port; the registry rewrites a loopback or private host to the source IP it observed, so peers resolve the right address — but the daemon only adopted that observed address when it was public, and kept showing loopback inpilotctl info, the "daemon registered" log line and registration events. It now adopts the observed private host with its own tunnel port when its local address is loopback. Display only: nothing different is sent.Not changed, deliberately: registering the STUN-reported address.
-listendefaults to:0, so the temporary STUN socket and the tunnel socket have different ports; the STUN address would advertise a dead port.Test Plan
go build ./...,go vet ./..., unit suite and fullgo test -parallel 4 -count=1 ./tests/withGOWORK=offTestPrivateNetworkEndpointReported(fails on main: daemon reports[::1]:portwhile peers resolve the LAN address)Checklist
go.mod/go.sumunchanged🤖 Generated with Claude Code