Skip to content

DR sets (Slice A, PR2): collapse into one logical topology node - #20

Merged
Krishcalin merged 1 commit into
dr-setsfrom
dr-sets-topology
Oct 2, 2026
Merged

Krishcalin merged 1 commit into
dr-setsfrom
dr-sets-topology

Conversation

@Krishcalin

Copy link
Copy Markdown
Owner

Slice A, PR2 — Collapse a DR set into one logical node

Second of two PRs for DR sets. This is the topology change that reads what PR1 (#19) records. Stacked on dr-sets — merge #19 first, then this retargets to main.

What it does

Each DR set's standbys are folded into the primary's graph node and dropped as separate nodes, so a path through the pair is one hop and the standby is not counted as a second firewall in the estate.

The correctness-critical bit

The primary's routes and rulebase are the logical device (the standby is passive), so those are untouched. What is merged is the standby's interface addresses — the graph's join key (graph.add maps each address → its owner). Without that, a next hop pointing at the standby's address, or a VIP the pair floats, would resolve to no node and the path would read as a false unreachable at the very device the collapse removed. Networks and zones come with the addresses (so an ingress landing on the standby still finds its zone), and the standby is pruned from the metadata/site maps too — the graph, the map and the counts all agree the set is one device.

Cache

A DR set changes the graph without touching a device or snapshot row, so the graph fingerprint gains a DR member count + timestamp. Declaring or removing a set now invalidates the cached graph instead of serving its pre-collapse shape.

Read-only guarantee

No device is written; the collapse is pure in-memory graph assembly from stored config. SRS §8 holds.

Tests

Collapse removes the standby; a next hop at the standby resolves to the primary; the fingerprint changes on declaration; the cache is not served stale; a missing primary leaves standbys alone; the address/zone union (incl. VIP) is unit-tested. Map, segmentation and topology-cache suites stay green (35 + 69 passed across the touched areas).

🤖 Generated with Claude Code

The topology change that reads the DR sets PR1 records. Each set's standbys are
folded into the primary's node and dropped as separate nodes, so a path through the
pair is one hop and the standby is not a second firewall in the estate.

The primary's routes and rulebase are the logical device (the standby is passive), so
those are left untouched. What is merged is the standby's INTERFACE ADDRESSES — the
graph's join key (graph.add maps each address to its owner). Without that, a next hop
pointing at the standby's address, or at a VIP the pair floats, would resolve to no
node and the path would read as a false `unreachable` at the very device the collapse
removed. The standby's networks and zones come with the addresses so an ingress landing
on it still finds its zone, and it is pruned from the metadata and site maps too, so the
graph, the map and the counts all agree the set is one device.

A DR set changes the graph without touching a device or snapshot row, so the graph
fingerprint gains a DR member count and timestamp; declaring or removing a set now
invalidates the cached graph instead of serving its pre-collapse shape.

Tests: collapse removes the standby, a next hop at the standby resolves to the primary,
the fingerprint changes on declaration, the cache is not served stale, a missing primary
leaves standbys alone, and the address/zone union with VIP is unit-tested. Map,
segmentation and topology-cache suites stay green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@Krishcalin
Krishcalin merged commit a2052fa into dr-sets Oct 2, 2026
2 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant