Repository navigation
exporter: add a global TCP port range - #1978
Arthur031221 wants to merge 1 commit into
Conversation
Use a shared start/end range for automatic TCP port allocation, as requested for networks with restricted inbound ports. Try candidates in random order and report exhaustion instead of returning port zero. Signed-off-by: Arthur031221 <levi74108520963@gmail.com> Co-authored-by: Benjamin B. Frost <5191751+benjamin1313@users.noreply.github.com>
ozan956
left a comment
There was a problem hiding this comment.
Hey @Arthur031221,
thanks for the PR.
Have you seen #1832? That issue describes essentially the same topology. The client is outside a firewall, the coordinator/exporter is behind it, and ser2net binds arbitrary ports.
Does the later guidance in #1832 supersede the earlier direction in #1743?
Could you clarify and document the concrete use case where the existing SSH proxy mechanism is insufficient? For example, is a direct client-to-exporter connection explicitly required?
Without such a distinction, this appears to introduce an alternative solution for a problem already covered by the supported proxy mechanism. Perhaps documenting --proxy / LG_PROXY would be sufficient instead.
|
I should have followed the later SSH proxy guidance in #1832. On this PR's head, a local raw |
|
Thanks for verifying this. In that case, please feel free to close this PR. Since #1743 appears to target the same use case, we can reference this conclusion there as well and wait for the original author to confirm whether they have a distinct case where the SSH proxy is insufficient. If not, #1743 can probably be closed too. |
Description
Picks up #1743 by @benjamin1313.
Exporters behind restrictive firewalls cannot limit their automatically allocated TCP ports. Add
--port-range=START-ENDwith randomized allocation and an error when the range is exhausted.Addresses @jluebbe's global range of at least 1000 ports, @Bastian-Krause's CLI option, and @Emantor's start/end format.
Added allocation and CLI regression tests. Tested with
python -m pytest -q tests/test_port_range.py.Checklist
@benjamin1313, I'm glad to close this if you'd rather finish yours.
Co-authored-by: Benjamin B. Frost 5191751+benjamin1313@users.noreply.github.com