feat: enrol nodes with a one-time setup token - #166
Merged
Merged
Conversation
e226li
marked this pull request as ready for review
September 30, 2026 20:11
Owner
|
I think it's a bit of a slippery slope for nylon to auto configure the ip, and graph... Since the join is authenticated with the token, maybe on the client side, we can pass some options like what node name, prefixes, and address we want for this new node. (this could be both via cli, or interactive) As for the graph, I think we might want to default to a fully connected graph (maybe add support for wildcards), for ease of use, I think it should be more of an advanced feature anyways.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Previously joining a node to the cluster involved a lot of friction: the user had to manually fetch the central config, then generate the keys on the joiner, then amend the central config and redistribute it to every node. This PR provides a 1 to 2 step process to reduce this friction.
How
nylon init --serveloads or createsnode.yaml/central.yaml, prints a single use setup token, and waits on node port for one join--address/--prefix. The server adds it as a router with those and no graph edges, then returnscentral.yamlwhich is given to the user on the client node--idUsage
New
nylon initoptions:--serve--connect--connect <host[:port]>--serve(port defaults to57175)--token <token>--serve(required with--connect)-c, --config <path>--serveand--connect(default./central.yaml)--address <ip>--prefix <cidr>--id <name>--force--connect, overwrite existing configs; with--serve, discard an undistributed joinTesting
This was tested in a KVM setup with 4 separate Nylon nodes. The tool was successfully used to add a new node.