mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Move examples/docker-network/ to testing/static/ and add testing/chaos/ as a new stochastic simulation harness. testing/static/ — Static 5-node test harness: - Fixed mesh, chain, and mesh-public topologies with docker compose - Manual test scripts (ping, iperf, netem) - Build script, config generation, key derivation testing/chaos/ — Stochastic network simulation: - Python orchestrator generating N-node FIPS meshes with dynamic network conditions, driven by reproducible YAML scenarios - Topology generation: random geometric, Erdos-Renyi, or chain graphs with BFS connectivity guarantee - Per-link netem: HTB classful qdiscs with u32 filters for per-peer impairment (delay, loss, jitter), stochastic mutation across configurable policy profiles - Per-link bandwidth pacing: HTB rate limiting with configurable tiers (1/10/100/1000 mbps) randomly assigned per edge - Link flaps: tc netem 100% loss with graph connectivity protection - Node churn: docker stop/start with netem re-application on restart, shared down_nodes tracking across all managers - Traffic generation: random iperf3 sessions between node pairs - Down-node guards: all docker exec callers check container liveness, auto-detect crashed containers via is_container_running() safety net - Log collection and post-run analysis (panics, errors, sessions, MMP metrics, tree reconvergence) - chaos.sh wrapper with --seed, --duration, --verbose, --list options - Four scenarios: smoke-10, chaos-10, churn-10, churn-20
30 lines
628 B
YAML
30 lines
628 B
YAML
# FIPS Node {{NODE_NAME}} configuration ({{TOPOLOGY}} topology)
|
|
#
|
|
# Identity: {{NPUB}}
|
|
|
|
node:
|
|
identity:
|
|
nsec: "{{NSEC}}"
|
|
|
|
tun:
|
|
enabled: true
|
|
name: fips0
|
|
mtu: 1280
|
|
|
|
dns:
|
|
enabled: true
|
|
bind_addr: "127.0.0.1"
|
|
|
|
transports:
|
|
udp:
|
|
bind_addr: "0.0.0.0:4000"
|
|
mtu: 1472
|
|
# recv_buf_size: 2097152 # 2 MB (default)
|
|
# send_buf_size: 2097152 # 2 MB (default)
|
|
# Note: The kernel clamps socket buffers to net.core.rmem_max / wmem_max.
|
|
# Ensure these sysctls are >= the configured buffer sizes:
|
|
# sysctl -w net.core.rmem_max=2097152
|
|
# sysctl -w net.core.wmem_max=2097152
|
|
|
|
peers:
|
|
{{PEERS}} |