Correct the record: a limitation that no longer exists, and one that was never written
The connectivity design still said a hub cannot be filtered — a gap recorded in the morning and closed in the afternoon, left standing as though it were current. Worse than a stale date: it would send somebody away from something that works. `restart-on` was described nowhere, including the part added today that lets a service reflect a file another module put on the machine. A rule the host enforces and no document mentions is a rule nobody can rely on. And nine of fifteen design documents claimed an `updated:` older than their last change, some by a week. That field is what cross-cutting views are generated from, so it is not decoration.
This commit is contained in:
@@ -420,17 +420,28 @@ tmpfiles — is shaped that way. Until there is one, a module ships a unit that
|
||||
the better shape: how a machine enforces rules is a fact about the machine, and the mesh has no
|
||||
business depending on what a distribution happens to package.
|
||||
|
||||
**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is
|
||||
stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound
|
||||
connections from every node at other sites; a node that is not a hub dials out and needs nothing
|
||||
open, because a reply to a flow it started is already accepted. So the two want different rules on
|
||||
an identical module — and `listens` is a static field on a manifest, while the overlay module's
|
||||
resources are computed per node.
|
||||
**One rule is derived from the overlay's shape rather than from what is assigned: a hub's own
|
||||
listening port.** A hub accepts inbound connections from every node at other sites; a machine that
|
||||
is not a hub dials out and needs nothing open, because a reply to a flow it started is already
|
||||
accepted. The two want different rules on an *identical module*, so `listens` — a static field —
|
||||
cannot say it. The machine a static answer gets wrong is the one facing the public internet, which
|
||||
is the machine that most needs filtering.
|
||||
|
||||
A machine that is not a hub is therefore correct today, and **a hub would have its own port closed
|
||||
by a rule set derived this way.** The fix is that a computed module contributes listens the way it
|
||||
contributes resources; until it exists, the firewall belongs on machines that are not hubs, and
|
||||
this paragraph is the reason rather than an oversight to find later.
|
||||
*Recorded as a gap on 2026-08-31 and closed the same day.* **A computed module now contributes
|
||||
listens the way it contributes resources.** The port comes from the endpoint, which is where the
|
||||
interface takes its `ListenPort` from — one source, so a rule set cannot open a port the interface
|
||||
is not on. It is open to *everywhere* deliberately: a node at another site is not on the private
|
||||
network until this port lets it on, so restricting it to the mesh would be a rule that can never
|
||||
be satisfied by the thing it exists for.
|
||||
|
||||
**A generator that cannot say what a machine opens is refused, not read as silence.** Closing a
|
||||
port on the evidence of a failure to look is how a machine is severed by a fault somewhere else —
|
||||
and the machine it would sever is the hub, whose only route to being repaired is the network it
|
||||
just closed.
|
||||
|
||||
*Checked by filtering the hub and then requiring the mesh to keep working: a declaration still
|
||||
reaches the other machine, and the other machine still reaches the hub. A rule file that looks
|
||||
right and a mesh that has stopped are exactly what that guards against.*
|
||||
|
||||
**And it is enforced, which is what separates this from `scope:`.** Checked on two real machines:
|
||||
two ports opened, one declared, and from the other machine the declared one answers and the
|
||||
|
||||
Reference in New Issue
Block a user