Correct the record: a limitation that no longer exists, and one that was never written

The connectivity design still said a hub cannot be filtered — a gap recorded in
the morning and closed in the afternoon, left standing as though it were
current. Worse than a stale date: it would send somebody away from something
that works.

`restart-on` was described nowhere, including the part added today that lets a
service reflect a file another module put on the machine. A rule the host
enforces and no document mentions is a rule nobody can rely on.

And nine of fifteen design documents claimed an `updated:` older than their last
change, some by a week. That field is what cross-cutting views are generated
from, so it is not decoration.
This commit is contained in:
2026-08-31 12:33:35 +02:00
parent f4e81074d3
commit 573a94e102
10 changed files with 43 additions and 19 deletions
+21 -10
View File
@@ -420,17 +420,28 @@ tmpfiles — is shaped that way. Until there is one, a module ships a unit that
the better shape: how a machine enforces rules is a fact about the machine, and the mesh has no
business depending on what a distribution happens to package.
**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is
stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound
connections from every node at other sites; a node that is not a hub dials out and needs nothing
open, because a reply to a flow it started is already accepted. So the two want different rules on
an identical module — and `listens` is a static field on a manifest, while the overlay module's
resources are computed per node.
**One rule is derived from the overlay's shape rather than from what is assigned: a hub's own
listening port.** A hub accepts inbound connections from every node at other sites; a machine that
is not a hub dials out and needs nothing open, because a reply to a flow it started is already
accepted. The two want different rules on an *identical module*, so `listens` — a static field —
cannot say it. The machine a static answer gets wrong is the one facing the public internet, which
is the machine that most needs filtering.
A machine that is not a hub is therefore correct today, and **a hub would have its own port closed
by a rule set derived this way.** The fix is that a computed module contributes listens the way it
contributes resources; until it exists, the firewall belongs on machines that are not hubs, and
this paragraph is the reason rather than an oversight to find later.
*Recorded as a gap on 2026-08-31 and closed the same day.* **A computed module now contributes
listens the way it contributes resources.** The port comes from the endpoint, which is where the
interface takes its `ListenPort` from — one source, so a rule set cannot open a port the interface
is not on. It is open to *everywhere* deliberately: a node at another site is not on the private
network until this port lets it on, so restricting it to the mesh would be a rule that can never
be satisfied by the thing it exists for.
**A generator that cannot say what a machine opens is refused, not read as silence.** Closing a
port on the evidence of a failure to look is how a machine is severed by a fault somewhere else —
and the machine it would sever is the hub, whose only route to being repaired is the network it
just closed.
*Checked by filtering the hub and then requiring the mesh to keep working: a declaration still
reaches the other machine, and the other machine still reaches the hub. A rule file that looks
right and a mesh that has stopped are exactly what that guards against.*
**And it is enforced, which is what separates this from `scope:`.** Checked on two real machines:
two ports opened, one declared, and from the other machine the declared one answers and the