Issue 021: narrow to mesh-assigned ports (bare decl binds loopback, explicit host mapping binds 0.0.0.0)

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-09 22:35:06 +02:00
parent 315bd7118a
commit d16b5294f6
@@ -49,6 +49,16 @@ consumers (the ordinary small-mesh case) is exactly where it bites.
It also blocks anything that must *reach* a routed/served name from inside the mesh, not just
application traffic — see the internal-CA validation dependency noted in the connectivity design.
## Narrowing
The loopback bind appears tied to **mesh-assigned** host ports, not to publishing as such. A
container that declares a bare port (`"5432"`) — which the mesh assigns a host port for — is bound
to `127.0.0.1:<assigned>`. A container that declares an explicit host mapping (`"17672:15672"`) is
bound to `0.0.0.0:17672` and is reachable at the node's private-network address. So the defect is
in the path that assigns and binds a host port for a bare declaration, not in the general publish
step — which is also why a route to an explicitly-mapped port works while a database on an assigned
port does not.
## Open questions
- Should a `from: mesh` provision publish on the node's private-network address specifically, on