igneum/infra/cloud-devnet/net/setup.sh
igneum-labs 723b1b8c05 Cloud devnet: private-network mode (4 zone networks, 4 gateways), 12 nodes up, first latency measurement
A new Hetzner account is capped at 10 primary IPs (IPv4 and IPv6 both count), 20 shared vCPUs, 8 dedicated
vCPUs and no Arm, and a network cannot span zones. So: one private network per zone (10.20.<zone>.0/24),
the lowest-index node of each zone keeps a public IPv4 and is its gateway (NAT, MSS clamp, one DNAT port
27000+index per private node, persisted as igneum-nat.service), every other node has no public address.
nodes.tsv gains access, pub and port columns; lib resolves same-zone vs cross-zone dial addresses and jumps
ssh through the gateway for private nodes. All nodes.tsv loops read on fd 3 (a backgrounded ssh drained the
file). TYPE_BY_INDEX puts nodes 8 to 11 on ccx13; node 12 is the last shared one the account allows.
create.sh prints the plan's cost from the live API. provision.sh install takes node names and skips binaries
whose sha256 matches. Binaries copied from the seed's staged v4 build (same sources), no vCPU for a builder.

Results 2026-10-04: RTT matrix (hel1-fsn1 35 ms, ash-sin 289 ms) and a 10-minute propagation window of 644
blocks: p50 343 ms, p90 497 ms, p99 666 ms across 12 nodes in 5 locations.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:41:23 +00:00

36 lines
2.4 KiB
Bash
Executable file

#!/usr/bin/env bash
# Wire the private-network mode after the servers exist (create.sh calls this; it can be re-run at any time):
# ./net/setup.sh every zone: the 0.0.0.0/0 route to the gateway, the gateway's NAT and port forwards,
# every private node's uplink check
# ./net/setup.sh gateways gateways only ./net/setup.sh nodes private nodes only
# Needs nodes.tsv (7 columns). Hetzner only; NET_MODE=public has nothing to do here.
. "$(dirname "$0")/../lib/common.sh"
require_nodes
what="${1:-all}"
[ "$NET_MODE" = private ] || { log "NET_MODE=$NET_MODE: nothing to set up"; exit 0; }
need hcloud "brew install hcloud"
if [ "$what" = all ] || [ "$what" = gateways ]; then
for z in $(cut -f3 "$NODES_FILE" | while read -r r; do zone_of_region "$r"; done | sort -u); do
gw=$(gateway_of_zone "$z"); [ -n "$gw" ] || die "zone $z has no public node in $NODES_FILE"
gwip=$(node_ip "$gw"); gwpub=$(node_pub "$gw"); net=$(network_name "$z")
if ! hcloud network describe "$net" -o json | python3 -c 'import json,sys; r=json.load(sys.stdin)["routes"]; sys.exit(0 if any(x["destination"]=="0.0.0.0/0" for x in r) else 1)'; then
hcloud network add-route "$net" --destination 0.0.0.0/0 --gateway "$gwip" >/dev/null && log "$net: route 0.0.0.0/0 via $gwip ($gw)"
fi
fwd=$(awk -F'\t' -v z="$z" -v gw="$gw" '$5 == "private" { print $7 ":" $4 "\t" $3 }' "$NODES_FILE" | while IFS=$'\t' read -r pair r; do if [ "$(zone_of_region "$r")" = "$z" ]; then printf '%s ' "$pair"; fi; done; true)
nscp "$HERE/net/gateway.sh" "$SSH_USER@$gwip:/root/gateway.sh"
# shellcheck disable=SC2086
nssh "$gwip" "P2P_PORT=$P2P_PORT bash /root/gateway.sh '$NET_PREFIX.0.0/16' '$(zone_hetzner_gw "$z")' '$gwpub' $fwd" </dev/null 2>&1 | sed "s/^/[$gw] /"
done
fi
if [ "$what" = all ] || [ "$what" = nodes ]; then
bad=0
while IFS=$'\t' read -r -u 3 name idx reg ip access pub port; do
[ "$access" = private ] || continue
router=$(zone_hetzner_gw "$(zone_of_region "$reg")")
( nscp "$HERE/net/private-node.sh" "$SSH_USER@$ip:/root/private-node.sh" </dev/null && nssh "$ip" "bash /root/private-node.sh '$router'" 2>&1 </dev/null | sed "s/^/[$name] /" ) || { log "$name: uplink setup failed"; bad=$((bad + 1)); }
done 3< "$NODES_FILE"
[ "$bad" = 0 ] || die "$bad private node(s) without a working uplink"
fi
log "network setup done"