Repository navigation
Conversation
…0) only dusk-1 (operator desktop, WSL) serves an OpenAI-compatible API while the Sparks are sold. It is an untagged member device, so no tag grant reached it and srv2 (tag:ci + tag:dashboard) timed out. The grant admits the dashboard plane to tcp:8080 on its tailnet address only; tag:ci stays quarantined. The security spine now requires exactly that one grant to reach dusk-1, and the witness carries a red control (a tag:ci wildcard grant to dusk-1 refuses). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9532f164b5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| fn grant_reaches_dusk_serving(g: TailscaleGrant) -> Bool { | ||
| selector_list_contains(items: g.dst, needle: sel_ipv4(address: dusk_serving_ip)) | ||
| } |
There was a problem hiding this comment.
Include wildcard destinations in the dusk reachability check
grant_reaches_dusk_serving recognizes only a literal 100.127.39.77 destination, but the existing member_baseline_grant uses dst: [sel_wildcard()] and ip: [sel_wildcard()]. Tailscale defines a destination wildcard as matching all tailnet IP addresses and an ip wildcard as matching every protocol and port (Tailscale selector reference), so the emitted policy lets every member reach dusk-1 on all ports while this new security-spine predicate reports that only tag:dashboard can reach TCP 8080. Account for wildcard destinations (and any modeled ranges containing this address) in this reachability check and its negative witness.
Useful? React with 👍 / 👎.
|
Folded into #13641 (merge second parent = this head). |
Models the grant the operator is adding in the admin console, so the repo's policy (
extdeps.tailscale.acloperator_tailscale_acl_policy) matches live.tag_dashboard_to_dusk_serving_api_grant: srctag:dashboard→ dst100.127.39.77(dusk-1) →tcp:8080.operator_acl_security_spine_holdsnow also requiresdusk_serving_reached_by_dashboard_api_only: exactly one grant reaches dusk-1, fromtag:dashboardonly, port 8080 only.tag:cistays quarantined.witness_dusk_serving_api_onlyadds a red control: atag:ciwildcard grant to dusk-1 refuses. Reference fixture updated.Evidence:
claim_batch --entry dag/test/claim/tailscale_acl_witness_test.dag --functions tailscale_acl_witnesses→ PASS.Not covered: there is still no apply route (
tailscale_acl_upsert_wetis a declared scaffold with no definition), so live is edited in the console and this PR only records it. dusk-1 is addressed by IP because it is an untagged member device; tagging it would replace the IP.🤖 Generated with Claude Code