ADR 0191: the mesh's names are known by where they were composed, not by their suffix
A progressive insight: the rule and its check were stated as a suffix test; the mesh composes both names of a route and publishes its internal one. The decision is unchanged.
This commit is contained in:
@@ -11,6 +11,15 @@ supersedes-in-part:
|
|||||||
|
|
||||||
# 191. The mesh's resolver holds only the mesh's own names; a public name resolves publicly
|
# 191. The mesh's resolver holds only the mesh's own names; a public name resolves publicly
|
||||||
|
|
||||||
|
> **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public
|
||||||
|
> ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision
|
||||||
|
> read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends
|
||||||
|
> in the mesh suffix"*. The mesh needs no such test: it composes both names of every route itself,
|
||||||
|
> `name` from the node's public domain and `internal-name` from its own domain under the serving node
|
||||||
|
> (ADR 0151), and publishes the second. Which names are its own is known from where each was
|
||||||
|
> composed. Both sentences now say that; what was decided — a public name is never given a private
|
||||||
|
> answer — is unchanged.
|
||||||
|
|
||||||
## Context
|
## Context
|
||||||
|
|
||||||
**[ADR 0066](0066-public-routing-is-name-agnostic.md) published every routed name into internal
|
**[ADR 0066](0066-public-routing-is-name-agnostic.md) published every routed name into internal
|
||||||
@@ -63,7 +72,8 @@ every public name the mesh serves, is forwarded and resolves publicly. Chosen.
|
|||||||
|
|
||||||
## Decision
|
## Decision
|
||||||
|
|
||||||
**The mesh publishes into internal resolution only names under its own suffix.** A machine's name,
|
**The mesh publishes into internal resolution only the names it composes for itself** — a
|
||||||
|
machine's name, and each route's `internal-name`, never a route's public `name`. A machine's name,
|
||||||
and through it every `<label>.<node>.internal`, resolve to that machine's private address. **A public
|
and through it every `<label>.<node>.internal`, resolve to that machine's private address. **A public
|
||||||
name is never given a private answer by the mesh**: it resolves through public DNS to the public
|
name is never given a private answer by the mesh**: it resolves through public DNS to the public
|
||||||
address, from members and non-members alike.
|
address, from members and non-members alike.
|
||||||
@@ -93,8 +103,8 @@ reachability — the lab — certifies its internal names and has no public name
|
|||||||
|
|
||||||
**How each is checked:**
|
**How each is checked:**
|
||||||
|
|
||||||
- **The roster:** the controller's catalogue tests assert that every name the roster carries ends in
|
- **The roster:** the controller's catalogue tests assert that the names served are routes'
|
||||||
the mesh suffix — a routed public name in it fails the build.
|
internal names and that no route's public name is among them — one published fails the build.
|
||||||
- **On a machine:** asking the machine's resolver for a public name the mesh serves returns the
|
- **On a machine:** asking the machine's resolver for a public name the mesh serves returns the
|
||||||
public address, and asking it for that route's internal name returns the private one. Asked from a
|
public address, and asking it for that route's internal name returns the private one. Asked from a
|
||||||
non-member on a LAN the resolver answers, the first must hold as well.
|
non-member on a LAN the resolver answers, the first must hold as well.
|
||||||
|
|||||||
@@ -425,15 +425,16 @@ the cost of not seeing it is inventing a mechanism that already exists.
|
|||||||
|
|
||||||
### The mesh resolves only its own names; a public name resolves publicly
|
### The mesh resolves only its own names; a public name resolves publicly
|
||||||
|
|
||||||
**The mesh's resolver holds names under the mesh suffix and nothing else** — every machine, and through
|
**The mesh's resolver holds the names the mesh composes for itself and nothing else** — every
|
||||||
it every route's internal name `<label>.<node>.internal`
|
machine's name, and every route's internal name `<label>.<node>.internal`
|
||||||
([ADR 0151](../../02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)).
|
([ADR 0151](../../02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)).
|
||||||
**A public name the mesh serves is never given a private answer**: it is forwarded and resolves to the
|
**A public name the mesh serves is never given a private answer**: it is forwarded and resolves to the
|
||||||
public address, from a member and from anything else the resolver answers — a resolver may serve a
|
public address, from a member and from anything else the resolver answers — a resolver may serve a
|
||||||
machine's LAN, and a phone on that LAN must get the address it can reach
|
machine's LAN, and a phone on that LAN must get the address it can reach
|
||||||
([ADR 0191](../../02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). Inside the
|
([ADR 0191](../../02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). Inside the
|
||||||
mesh, a routed service is reached, and certified by the internal authority, under its internal name.
|
mesh, a routed service is reached, and certified by the internal authority, under its internal name.
|
||||||
*Checked by the controller's catalogue tests — every name the roster carries ends in the mesh suffix —
|
*Checked by the controller's catalogue tests — the names served are routes' internal names, and no
|
||||||
|
route's public name is among them —
|
||||||
and on a machine by asking its resolver for a public name the mesh serves: the answer is the public
|
and on a machine by asking its resolver for a public name the mesh serves: the answer is the public
|
||||||
address.*
|
address.*
|
||||||
|
|
||||||
@@ -1009,9 +1010,6 @@ The list is worth having in one place, because it is most of the argument:
|
|||||||
operator's to move between meshes, but the manifest layer still stores it as a literal — so today
|
operator's to move between meshes, but the manifest layer still stores it as a literal — so today
|
||||||
the composition is a per-node override rather than the design. The interpolation that would let a
|
the composition is a per-node override rather than the design. The interpolation that would let a
|
||||||
module carry a label and a node carry the domain, and the mesh join them, does not yet exist.
|
module carry a label and a node carry the domain, and the mesh join them, does not yet exist.
|
||||||
- **Withdrawing public names from internal resolution.** The roster still publishes every routed
|
|
||||||
public name at its serving node's private address, which ADR 0191 forbids; until the controller
|
|
||||||
stops, a resolver that answers a LAN hands that LAN's non-members addresses they cannot reach.
|
|
||||||
|
|
||||||
## The hub adopts the predecessor's tunnel
|
## The hub adopts the predecessor's tunnel
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user