diff --git a/main.go b/main.go index a18e02b..b319d4d 100644 --- a/main.go +++ b/main.go @@ -251,7 +251,7 @@ func tsproxy(ctx context.Context) error { // SingleHostReverseProxy for each upstream. rpx = make(map[string]http.Handler) - // targets returned by http_sd discovery endpoint. + // targets returned by the http_sd discovery endpoint. targets []string ) for _, u := range ups { diff --git a/tsproxy.go b/tsproxy.go index 6071e21..c858114 100644 --- a/tsproxy.go +++ b/tsproxy.go @@ -7,6 +7,7 @@ import ( "net/http" "net/http/httputil" "net/url" + "sort" "golang.org/x/exp/slog" "tailscale.com/client/tailscale/apitype" @@ -46,6 +47,7 @@ func tsSingleHostReverseProxy(logger *slog.Logger, lc tailscaleLocalClient, url } func tsReverseProxy(rpx map[string]http.Handler, metrics http.Handler, targets []string, self string) http.Handler { + sort.Strings(targets) return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { if r.TLS == nil { http.Error(w, http.StatusText(http.StatusInternalServerError), http.StatusInternalServerError) diff --git a/tsproxy_test.go b/tsproxy_test.go index 767b8df..7c9573d 100644 --- a/tsproxy_test.go +++ b/tsproxy_test.go @@ -145,9 +145,9 @@ func TestNewTSProxyHandler(t *testing.T) { }, { name: "self service discovery", - h: tsReverseProxy(nil, nil, []string{"localhost:8000"}, "example.com"), + h: tsReverseProxy(nil, nil, []string{"zzz:80", "localhost:8000"}, "example.com"), req: &http.Request{RequestURI: "/sd", TLS: &tls.ConnectionState{ServerName: "example.com"}}, - want: &http.Response{StatusCode: http.StatusOK, Header: http.Header{"Content-Type": []string{`application/json; charset=utf-8`}}, Body: io.NopCloser(bytes.NewReader([]byte(`[{"targets":["localhost:8000"]}]`)))}, + want: &http.Response{StatusCode: http.StatusOK, Header: http.Header{"Content-Type": []string{`application/json; charset=utf-8`}}, Body: io.NopCloser(bytes.NewReader([]byte(`[{"targets":["localhost:8000","zzz:80"]}]`)))}, }, } { tc := tc