oxidecomputer / oxidecomputer/omicron
wicket: preflight could check NTP connectivity from all (or several?) IPs in the service pool
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 572
- Forks
- 97
- Avg merge
- 2d 12h
- Merged PRs (30d)
- 96
Description
If firewall rules are opened up only for the service pool IP that attempted to make an NTP query during preflight, it's very likely that the boundary NTP zones will come up with different IPs and fail to make connectivity. Preflight could check that several or all of the IPs in the service pool have the ability to reach NTP servers.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing wicket's preflight flow and the existing service-pool NTP connectivity check. Determine how preflight selects pool IPs and whether the intended check covers several or all of them. Done means preflight verifies NTP reachability across the selected pool IPs so later boundary zones do not fail because a different IP is used.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- backend, networking
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100