diff --git a/stream/experiment/infra/main.tf b/stream/experiment/infra/main.tf index 4a9c35b..6ce0bb4 100644 --- a/stream/experiment/infra/main.tf +++ b/stream/experiment/infra/main.tf @@ -19,7 +19,7 @@ resource "hcloud_firewall" "workload" { direction = "in" protocol = "tcp" port = "22" - source_ips = [var.operator_cidr] + source_ips = split(",", var.operator_cidr) } rule { @@ -45,7 +45,7 @@ resource "hcloud_firewall" "watchdog" { direction = "in" protocol = "tcp" port = "22" - source_ips = [var.operator_cidr] + source_ips = split(",", var.operator_cidr) } } @@ -57,7 +57,7 @@ resource "hcloud_firewall" "observer" { direction = "in" protocol = "tcp" port = "22" - source_ips = [var.operator_cidr] + source_ips = split(",", var.operator_cidr) } } diff --git a/stream/experiment/infra/variables.tf b/stream/experiment/infra/variables.tf index e969a7e..3044927 100644 --- a/stream/experiment/infra/variables.tf +++ b/stream/experiment/infra/variables.tf @@ -11,7 +11,7 @@ variable "ssh_key_name" { } variable "operator_cidr" { - description = "Narrow IPv4 CIDR allowed to reach SSH" + description = "Comma-separated narrow IPv4 CIDRs allowed to reach SSH. A list because a home connection can flap between addresses mid-run, and a single value locks the operator out of a machine they are paying for." type = string } diff --git a/stream/experiment/provision.sh b/stream/experiment/provision.sh index 77a1419..8ded114 100755 --- a/stream/experiment/provision.sh +++ b/stream/experiment/provision.sh @@ -19,7 +19,14 @@ if [ "${STREAM_OPERATOR_CIDR_SKIP_CHECK:-0}" != "1" ]; then echo "re-run with STREAM_OPERATOR_CIDR_SKIP_CHECK=1 to proceed anyway." >&2 exit 1 fi - if [ "$STREAM_OPERATOR_CIDR" != "$detected/32" ]; then + # STREAM_OPERATOR_CIDR may list several CIDRs: a home address can flap + # between two ISP addresses, and pinning one locks the operator out mid-run. + # The check passes if any listed entry is the address we actually egress from. + cidr_match=0 + for entry in ${STREAM_OPERATOR_CIDR//,/ }; do + [ "$entry" = "$detected/32" ] && cidr_match=1 + done + if [ "$cidr_match" != "1" ]; then echo "STREAM_OPERATOR_CIDR is $STREAM_OPERATOR_CIDR but this host egresses from $detected/32." >&2 echo "that firewall would lock you out. export STREAM_OPERATOR_CIDR=$detected/32" >&2 echo "or re-run with STREAM_OPERATOR_CIDR_SKIP_CHECK=1 if the mismatch is deliberate." >&2