[management, client] Make the agent-network setup RPC provable at runtime

An Unimplemented answer to GetAgentNetworkSetup can only come from a
server binary compiled without the regenerated management proto — the
combined and management servers share the one registration path in
boot.go. Make that failure mode self-diagnosing:

- Log "ManagementService registered on gRPC server (agent-network
  setup RPC available)" at boot, so server logs prove which build is
  running.
- Have the CLI name the management URL it dialed in every error, and
  map Unimplemented to an actionable message including the binary
  check (grep -ac GetAgentNetworkSetup <server binary>).
- Pin the wire path with a round-trip test: a real gRPC server built
  from this tree routes the RPC through the NaCl envelope end to end.

Verified live: a combined server built from this branch answers an
unregistered probe with PermissionDenied "peer is not registered",
never Unimplemented.

Linear: NET-1399
This commit is contained in:
mlsmaycon
2026-08-04 02:06:48 +00:00
parent 74b2f5cf4f
commit 9169a36658
3 changed files with 100 additions and 3 deletions
+10 -3
View File
@@ -104,10 +104,17 @@ func fetchAgentNetworkSetup(ctx context.Context) (*mgmProto.AgentNetworkSetupRes
setup, err := mgmClient.GetAgentNetworkSetup(mgmCtx)
if err != nil {
if s, ok := status.FromError(err); ok && s.Code() == codes.PermissionDenied {
return nil, fmt.Errorf("this peer is not registered with the management service — run 'netbird up' first")
if s, ok := status.FromError(err); ok {
switch s.Code() {
case codes.PermissionDenied:
return nil, fmt.Errorf("this peer is not registered with the management service at %s — run 'netbird up' first", config.ManagementURL.String())
case codes.Unimplemented:
return nil, fmt.Errorf("the management server at %s does not implement the agent-network setup RPC — the process answering runs a build without it.\n"+
"Verify the running binary contains the RPC: grep -ac GetAgentNetworkSetup <path-to-server-binary> (0 = built without it),\n"+
"and that this URL actually reaches the server you rebuilt", config.ManagementURL.String())
}
}
return nil, fmt.Errorf("get agent network setup: %v", err)
return nil, fmt.Errorf("get agent network setup from %s: %v", config.ManagementURL.String(), err)
}
return setup, nil
}