Issue 191 resolved: internal-only routes are served to the mesh, live on both proxies
This commit is contained in:
@@ -1,8 +1,8 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-10-01
|
||||
located-in: [mesh-controller examples/route-proxy/main.go (routesFrom requires a route's public `name` and treats `internal-name` only as an alias of it; the handler serves every routed name to any source), mesh-controller internal/broker/membership.go (a membership says nothing of what its module receives or who the mesh is)]
|
||||
fixed-by:
|
||||
fixed-by: mesh-controller PR 207 (the membership carries what a module receives and who the mesh is; the proxy follows it and serves internal names to the mesh only), mesh-catalog PR 211 (the proxy's bus account), mesh-controller PR 208 (the issue verb that delivers it), live 2026-10-02
|
||||
amended-design: [03-DESIGN/01-to-be/08-connectivity.md, 03-DESIGN/01-to-be/25-the-bus-on-nats.md]
|
||||
---
|
||||
|
||||
@@ -59,3 +59,22 @@ It also publishes an administration interface to the internet to get a name on t
|
||||
only in its own log? The same silent skip covers a route with no usable port or an unknown scheme.
|
||||
- What checks that what the controller composes and what the proxy serves stay the same shape? ADR
|
||||
0138 changed one side and nothing failed on the other.
|
||||
|
||||
## Resolved (2026-10-02)
|
||||
|
||||
Built as [ADR 0167](../../02-DECISIONS/0167-a-membership-carries-what-its-module-receives-and-who-the-mesh-is.md)
|
||||
decided, and live on both machines that run the proxy. Each logs that its routes now come from its
|
||||
membership, and serves internal names to the four machines the mesh names. Checked by hand:
|
||||
|
||||
- the internal-only route answers through the proxy from the serving machine and from two other
|
||||
machines of the mesh, over a certificate from the mesh's own authority that each verifies;
|
||||
- the same name asked from an address outside the mesh is answered as a name never routed, over plain
|
||||
HTTP, and refused in the TLS handshake; the list of served names it is shown leaves out every internal
|
||||
name.
|
||||
|
||||
Two things the rollout found are their own records: the proxy's bus account could be issued only from
|
||||
the controller's command line, until mesh-controller PR 208 added the `issue` verb, and the status line
|
||||
counting every module as a bus user without a credential is
|
||||
[issue 195](../195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md).
|
||||
The serving machine also lacked the certificate-trust module, so it could not verify the mesh's own
|
||||
certificates until it was assigned there.
|
||||
|
||||
Reference in New Issue
Block a user