policy/v2: add advertised routes to compat test topologies

Add routable_ips and approved_routes fields to the node topology
definitions in all golden test files. These represent the subnet
routes actually advertised by nodes on the Tailscale SaaS network
during data capture:

  Routes topology (92 files, 6 router nodes):
    big-router:     10.0.0.0/8
    subnet-router:  10.33.0.0/16
    ha-router1:     192.168.1.0/24
    ha-router2:     192.168.1.0/24
    multi-router:   172.16.0.0/24
    exit-node:      0.0.0.0/0, ::/0

  ACL topology (199 files, 1 router node):
    subnet-router:  10.33.0.0/16

  Grants topology (203 files, 1 router node):
    subnet-router:  10.33.0.0/16

The route assignments were deduced from the golden data by analyzing
which router nodes receive FilterRules for which destination CIDRs
across all test files, and cross-referenced with the MTS setup
script (setup_grant_nodes.sh).

Updates #2180
This commit is contained in:
Kristoffer Dalby 2026-03-18 13:40:19 +00:00
parent 927ce418d2
commit 995ed0187c
494 changed files with 76022 additions and 15770 deletions

View file

@ -41,7 +41,13 @@
]
},
"grants_section": [
{ "src": ["autogroup:member", "tag:prod"], "dst": ["tag:server"], "app": { "example.com/cap/test": [{}] } }
{
"src": ["autogroup:member", "tag:prod"],
"dst": ["tag:server"],
"app": {
"example.com/cap/test": [{}]
}
}
],
"api_endpoint": "https://api.tailscale.com/api/v2/tailnet/kratail2tid%40passkey/acl",
"api_method": "POST",
@ -65,7 +71,9 @@
"user_id": 7489538288452506,
"tags": ["tag:router"],
"ipv4": "100.92.142.61",
"ipv6": "fd7a:115c:a1e0::3e37:8e3d"
"ipv6": "fd7a:115c:a1e0::3e37:8e3d",
"routable_ips": ["10.33.0.0/16"],
"approved_routes": ["10.33.0.0/16"]
},
"tagged-client": {
"mts_name": "tagged-client",
@ -307,8 +315,14 @@
"OS": "linux",
"Hostname": "tagged-server",
"Services": [
{ "Proto": "peerapi4", "Port": 46499 },
{ "Proto": "peerapi6", "Port": 46499 }
{
"Proto": "peerapi4",
"Port": 46499
},
{
"Proto": "peerapi6",
"Port": 46499
}
]
},
"Created": "2026-01-23T10:10:26.365653609Z",
@ -318,7 +332,11 @@
"ComputedName": "tagged-server",
"ComputedNameWithHost": "tagged-server"
},
"UserProfile": { "ID": 1260082990019555, "LoginName": "tagged-devices", "DisplayName": "Tagged Devices" },
"UserProfile": {
"ID": 1260082990019555,
"LoginName": "tagged-devices",
"DisplayName": "Tagged Devices"
},
"CapMap": null
}
},
@ -359,7 +377,9 @@
"CapGrant": [
{
"Dsts": ["100.108.74.26/32", "fd7a:115c:a1e0::b901:4a87/128"],
"CapMap": { "example.com/cap/test": [{}] }
"CapMap": {
"example.com/cap/test": [{}]
}
}
]
}
@ -380,8 +400,16 @@
"SrcCaps": null,
"Dsts": [],
"Caps": [
{ "Dst": "100.108.74.26/32", "Cap": "example.com/cap/test", "Values": [{}] },
{ "Dst": "fd7a:115c:a1e0::b901:4a87/128", "Cap": "example.com/cap/test", "Values": [{}] }
{
"Dst": "100.108.74.26/32",
"Cap": "example.com/cap/test",
"Values": [{}]
},
{
"Dst": "fd7a:115c:a1e0::b901:4a87/128",
"Cap": "example.com/cap/test",
"Values": [{}]
}
]
}
],
@ -426,8 +454,14 @@
"OS": "linux",
"Hostname": "tagged-prod",
"Services": [
{ "Proto": "peerapi4", "Port": 37678 },
{ "Proto": "peerapi6", "Port": 37678 }
{
"Proto": "peerapi4",
"Port": 37678
},
{
"Proto": "peerapi6",
"Port": 37678
}
]
},
"Created": "2026-02-20T14:03:12.89283153Z",
@ -437,8 +471,14 @@
"ComputedName": "tagged-prod",
"ComputedNameWithHost": "tagged-prod"
},
"UserProfile": { "ID": 1260082990019555, "LoginName": "tagged-devices", "DisplayName": "Tagged Devices" },
"CapMap": { "example.com/cap/test": [{}] }
"UserProfile": {
"ID": 1260082990019555,
"LoginName": "tagged-devices",
"DisplayName": "Tagged Devices"
},
"CapMap": {
"example.com/cap/test": [{}]
}
}
},
"100.110.121.96": {
@ -467,8 +507,14 @@
"OS": "linux",
"Hostname": "user-kris",
"Services": [
{ "Proto": "peerapi4", "Port": 40159 },
{ "Proto": "peerapi6", "Port": 40159 }
{
"Proto": "peerapi4",
"Port": 40159
},
{
"Proto": "peerapi6",
"Port": 40159
}
]
},
"Created": "2026-02-20T14:09:34.803901523Z",
@ -477,8 +523,14 @@
"ComputedName": "user-kris",
"ComputedNameWithHost": "user-kris"
},
"UserProfile": { "ID": 4538565228176803, "LoginName": "kristoffer@dalby.cc", "DisplayName": "kristoffer" },
"CapMap": { "example.com/cap/test": [{}] }
"UserProfile": {
"ID": 4538565228176803,
"LoginName": "kristoffer@dalby.cc",
"DisplayName": "kristoffer"
},
"CapMap": {
"example.com/cap/test": [{}]
}
}
},
"100.103.90.82": {
@ -507,8 +559,14 @@
"OS": "linux",
"Hostname": "user-mon",
"Services": [
{ "Proto": "peerapi4", "Port": 33201 },
{ "Proto": "peerapi6", "Port": 33201 }
{
"Proto": "peerapi4",
"Port": 33201
},
{
"Proto": "peerapi6",
"Port": 33201
}
]
},
"Created": "2026-02-20T14:09:00.203639664Z",
@ -522,7 +580,9 @@
"LoginName": "monitorpasskeykradalby@passkey",
"DisplayName": "monitorpasskeykradalby"
},
"CapMap": { "example.com/cap/test": [{}] }
"CapMap": {
"example.com/cap/test": [{}]
}
}
},
"100.90.199.68": {
@ -551,8 +611,14 @@
"OS": "linux",
"Hostname": "user1",
"Services": [
{ "Proto": "peerapi4", "Port": 46708 },
{ "Proto": "peerapi6", "Port": 46708 }
{
"Proto": "peerapi4",
"Port": 46708
},
{
"Proto": "peerapi6",
"Port": 46708
}
]
},
"Created": "2026-01-23T10:04:13.531671894Z",
@ -561,8 +627,14 @@
"ComputedName": "user1",
"ComputedNameWithHost": "user1"
},
"UserProfile": { "ID": 4156223528223174, "LoginName": "kratail2tid@passkey", "DisplayName": "kratail2tid" },
"CapMap": { "example.com/cap/test": [{}] }
"UserProfile": {
"ID": 4156223528223174,
"LoginName": "kratail2tid@passkey",
"DisplayName": "kratail2tid"
},
"CapMap": {
"example.com/cap/test": [{}]
}
}
}
}
@ -620,8 +692,14 @@
"OS": "linux",
"Hostname": "tagged-server",
"Services": [
{ "Proto": "peerapi4", "Port": 46499 },
{ "Proto": "peerapi6", "Port": 46499 }
{
"Proto": "peerapi4",
"Port": 46499
},
{
"Proto": "peerapi6",
"Port": 46499
}
]
},
"Created": "2026-01-23T10:10:26.365653609Z",
@ -631,7 +709,11 @@
"ComputedName": "tagged-server",
"ComputedNameWithHost": "tagged-server"
},
"UserProfile": { "ID": 1260082990019555, "LoginName": "tagged-devices", "DisplayName": "Tagged Devices" },
"UserProfile": {
"ID": 1260082990019555,
"LoginName": "tagged-devices",
"DisplayName": "Tagged Devices"
},
"CapMap": null
}
},
@ -700,8 +782,14 @@
"OS": "linux",
"Hostname": "tagged-server",
"Services": [
{ "Proto": "peerapi4", "Port": 46499 },
{ "Proto": "peerapi6", "Port": 46499 }
{
"Proto": "peerapi4",
"Port": 46499
},
{
"Proto": "peerapi6",
"Port": 46499
}
]
},
"Created": "2026-01-23T10:10:26.365653609Z",
@ -711,7 +799,11 @@
"ComputedName": "tagged-server",
"ComputedNameWithHost": "tagged-server"
},
"UserProfile": { "ID": 1260082990019555, "LoginName": "tagged-devices", "DisplayName": "Tagged Devices" },
"UserProfile": {
"ID": 1260082990019555,
"LoginName": "tagged-devices",
"DisplayName": "Tagged Devices"
},
"CapMap": null
}
},
@ -780,8 +872,14 @@
"OS": "linux",
"Hostname": "tagged-server",
"Services": [
{ "Proto": "peerapi4", "Port": 46499 },
{ "Proto": "peerapi6", "Port": 46499 }
{
"Proto": "peerapi4",
"Port": 46499
},
{
"Proto": "peerapi6",
"Port": 46499
}
]
},
"Created": "2026-01-23T10:10:26.365653609Z",
@ -791,7 +889,11 @@
"ComputedName": "tagged-server",
"ComputedNameWithHost": "tagged-server"
},
"UserProfile": { "ID": 1260082990019555, "LoginName": "tagged-devices", "DisplayName": "Tagged Devices" },
"UserProfile": {
"ID": 1260082990019555,
"LoginName": "tagged-devices",
"DisplayName": "Tagged Devices"
},
"CapMap": null
}
},