chore: replace real IPs in docs and configs with placeholders

Operator-facing IPs in user-visible configs/docs (examples, tutorials,
packaging, sidecar templates) are now the resolvable hostnames of the
public test fleet (test-us01.fips.network, etc.) so they keep working
without baking specific addresses into examples.

Doc-comment and test fixtures in src/config/transport.rs use RFC 5737
TEST-NET-2 (198.51.100.1) so they cannot accidentally point at a real
host.

Also resyncs the openwrt-ipk fips.yaml with the common reference
(merge from master) and applies the same DNS-name swap there.
This commit is contained in:
Arjen
2026-05-11 18:43:06 +01:00
parent b6bd28f77c
commit 733ee512d3
14 changed files with 35 additions and 35 deletions
+1 -1
View File
@@ -8,6 +8,6 @@ FIPS_NSEC=e752b92aed3ac1595807f5d0eb5125589fbec0a2cfd3a2948d87ea076557deeb
# Peer configuration (leave empty for standalone operation)
FIPS_PEER_NPUB=npub1qmc3cvfz0yu2hx96nq3gp55zdan2qclealn7xshgr448d3nh6lks7zel98
FIPS_PEER_ADDR=217.77.8.91:2121
FIPS_PEER_ADDR=test-us01.fips.network:2121
FIPS_PEER_ALIAS=vps
FIPS_PEER_TRANSPORT=udp
@@ -38,7 +38,7 @@ nodes:
# External/public node (not a Docker container)
pub:
npub: "npub1qmc3cvfz0yu2hx96nq3gp55zdan2qclealn7xshgr448d3nh6lks7zel98"
external_ip: "217.77.8.91"
external_ip: "test-us01.fips.network"
peers: [a, b, c]
# Spanning Tree Structure (rooted at node A):
@@ -1,6 +1,6 @@
# FIPS Tor test node A — socks5-outbound
#
# Connects outbound to test-us01 (217.77.8.91:443) via Tor SOCKS5 proxy.
# Connects outbound to test-us01 (test-us01.fips.network:443) via Tor SOCKS5 proxy.
# Identity generated per-run to avoid mesh clashes with parallel tests.
node:
@@ -24,5 +24,5 @@ peers:
alias: "test-us01"
addresses:
- transport: tor
addr: "217.77.8.91:443"
addr: "test-us01.fips.network:443"
connect_policy: auto_connect
@@ -1,6 +1,6 @@
# FIPS Tor test node B — socks5-outbound
#
# Connects outbound to test-us01 (217.77.8.91:443) via Tor SOCKS5 proxy.
# Connects outbound to test-us01 (test-us01.fips.network:443) via Tor SOCKS5 proxy.
# Identity generated per-run to avoid mesh clashes with parallel tests.
node:
@@ -24,5 +24,5 @@ peers:
alias: "test-us01"
addresses:
- transport: tor
addr: "217.77.8.91:443"
addr: "test-us01.fips.network:443"
connect_policy: auto_connect
@@ -1,7 +1,7 @@
# Tor transport integration test — socks5-outbound
#
# Topology:
# [fips-a] --tor/socks5--> test-us01 (217.77.8.91:443) <--tor/socks5-- [fips-b]
# [fips-a] --tor/socks5--> test-us01 (test-us01.fips.network:443) <--tor/socks5-- [fips-b]
#
# Both FIPS nodes connect outbound through a local Tor daemon's SOCKS5
# proxy to test-us01's TCP listener. test-us01 routes between them.
@@ -5,7 +5,7 @@
# fips-a --tor/socks5--> test-us01 <--tor/socks5-- fips-b
#
# Both local FIPS nodes connect outbound through a local Tor daemon
# to test-us01's TCP listener (217.77.8.91:443). Once both are peered
# to test-us01's TCP listener (test-us01.fips.network:443). Once both are peered
# with test-us01, traffic between fips-a and fips-b is routed through it.
#
# Each run generates ephemeral identities to avoid mesh clashes when