oxidecomputer / oxidecomputer/omicron

wicket: preflight could check NTP connectivity from all (or several?) IPs in the service pool

Open
#6,622 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
572
Forks
97
Avg merge
2d 12h
Merged PRs (30d)
96

Description

If firewall rules are opened up only for the service pool IP that attempted to make an NTP query during preflight, it's very likely that the boundary NTP zones will come up with different IPs and fail to make connectivity. Preflight could check that several or all of the IPs in the service pool have the ability to reach NTP servers.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing wicket's preflight flow and the existing service-pool NTP connectivity check. Determine how preflight selects pool IPs and whether the intended check covers several or all of them. Done means preflight verifies NTP reachability across the selected pool IPs so later boundary zones do not fail because a different IP is used.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
backend, networking
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.