Issue 191: an internal name is served to the private network only

The first fix served the dropped route to anyone who sent its name. Record
why in the issue, as a progressive insight on ADR 0138, and in the to-be
connectivity design.
This commit is contained in:
2026-10-02 01:10:13 +02:00
parent 496d136d72
commit 68650cda5f
4 changed files with 71 additions and 4 deletions
@@ -124,6 +124,30 @@ This corrects a fact, not the decision: one statement per endpoint, three things
none of them deciding on its own, all stand. The table in the decision should be read with the filter
column applying to an unrouted endpoint.
## Progressive insight — 2026-10-02, from issue 191
**For a routed endpoint, "the proxy serves the internal name" has to mean "serves it to the private
network", and only the proxy can make it mean that.** The decision says `internal` means the proxy
serves the internal name and not the public one. It does not say to whom, and the proxy answered
every name it routes to any request that carried it, on the same listeners as its public names. A
name being internal kept nobody out: a request from the internet only had to send it. While every
routed endpoint also had a public name, nothing showed it. Once an endpoint could be internal alone
([issue 191](../04-ISSUES/191-a-route-with-only-an-internal-name-is-dropped/00-report.md)), serving
its name to everyone would have published exactly what `internal` was chosen to keep private.
The earlier insight above says the port is not the path for a routed endpoint. This is its other
half: the proxy is the path, so the proxy is where `internal` is enforced. It serves an internal name
only to a request from the private network — the mesh's range, the machine itself, or one of its own
container networks ([ADR 0144](0144-anything-on-a-machine-may-call-anything-on-it.md)). To anyone else, the name is
answered as one never routed, in the handshake and in the request, and not listed among the names it
serves. This holds for the internal name of a `both` endpoint too, whose outsiders have its public
name.
The decision, the options and the consequences stand: one statement per endpoint, three things
derived from it. Checked in the proxy's own tests: an internal-only name is served to the mesh
range, to loopback and to a container bridge, and refused, unlisted and uncertified for a request
from outside; with no range given, it is served to the machine alone.
## Consequences
- **A manifest gains endpoint names, and a route contribution names an endpoint instead of a port.**