Skip to main content

Module config_check

Module config_check 

Source
Expand description

Cross-chunk, cross-format checks for a project (Phase 29, “the config compiler”; ADR-0137).

Phase 18’s validation matrix runs each generated file past its own tool (nginx -t, wg-quick strip), which can only ever see one format. The mistakes that bite sit between chunks: a proxy_pass naming a service the project does not define, two WireGuard peers claiming one address.

Eight rule ids over the six designed checks, hand-written, and no rule language (WireGuard and Kubernetes each split into an error case and a softer one). A false positive costs far more than a missing check: a validator that cries wolf gets switched off and then protects nothing. So every rule fires only on positive evidence that the project means to define the thing (a rule about Docker services stays silent in a project with no docker_service chunk), and anything that could be resolved somewhere this function cannot see — a name@provider Traefik reference, a ${bundle:…} reference, a hostname with a dot — is skipped, not guessed at.

The functions are pure over the project JSON, so the CLI (unv check) and the desktop app (over IPC) cannot disagree about what a project means. Messages carry names and never values: a finding must be safe to print, and a hostname or chunk name is not a secret where a field value might be.

Structs§

Finding
One finding. severity is "error" (the generated config is wrong) or "warning" (probably wrong; could be satisfied somewhere this cannot see).

Constants§

RULES
The rule ids, in the order they run — unv describe and the panel list them.

Functions§

check_project
Run every rule over one project. vault_names are the vault’s entry names (provider, and provider_keyid) so a ${…} reference to a real entry is not reported; pass an empty slice to skip nothing and report every non-env_file ref.
check_project_scoped
As check_project, with elsewhere (see services_of) widening what an nginx proxy_pass host may resolve to. Off by default because it widens the evidence a rule may use: a name another project defines is not wired to this one.
gate
The push gate: the error-severity findings that must stop a node from writing this project’s config to a live host. Empty means go. A warning never gates.
services_of
Every Compose service name (and container_name) any of projects defines, lowercased. Passed to check_project_scoped as elsewhere so a proxy_pass is resolved against the whole stack, which is how people split one.