fix(topology): allow allowed-location-ips to contain node IPs #404
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Allow
allowed-location-ipsCIDRs to fully contain node internal IPs without being rejected.Problem
Previously, if an
allowed-location-ipsCIDR contained a node's internal IP or allowed IP, it was rejected with a warning:For example, setting
allowed-location-ips=192.168.100.0/24on a node with internal IP192.168.100.11would fail.Solution
This was overly restrictive since WireGuard uses longest prefix match for routing. Now, if an
allowed-location-ipfully contains a node's IP (e.g.,192.168.100.0/24contains192.168.100.11/32), theallowed-location-ipis accepted.The more specific route to the node's IP will still work correctly due to longest prefix match.
Test plan
allowed-location-ipscontaining node IP