Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
28d53dcc28 | ||
|
|
df667eb710 | ||
|
|
098a2ca485 | ||
|
|
a34cedeb5d | ||
|
|
db5ff5a5ee |
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
status: located
|
status: resolved
|
||||||
opened: 2026-10-01
|
opened: 2026-10-01
|
||||||
located-in: [mesh-controller examples/route-proxy/main.go (routesFrom requires a route's public `name` and treats `internal-name` only as an alias of it; the handler serves every routed name to any source), mesh-controller internal/broker/membership.go (a membership says nothing of what its module receives or who the mesh is)]
|
located-in: [mesh-controller examples/route-proxy/main.go (routesFrom requires a route's public `name` and treats `internal-name` only as an alias of it; the handler serves every routed name to any source), mesh-controller internal/broker/membership.go (a membership says nothing of what its module receives or who the mesh is)]
|
||||||
fixed-by:
|
fixed-by: mesh-controller PR 207 (the membership carries what a module receives and who the mesh is; the proxy follows it and serves internal names to the mesh only), mesh-catalog PR 211 (the proxy's bus account), mesh-controller PR 208 (the issue verb that delivers it), live 2026-10-02
|
||||||
amended-design: [03-DESIGN/01-to-be/08-connectivity.md, 03-DESIGN/01-to-be/25-the-bus-on-nats.md]
|
amended-design: [03-DESIGN/01-to-be/08-connectivity.md, 03-DESIGN/01-to-be/25-the-bus-on-nats.md]
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -59,3 +59,22 @@ It also publishes an administration interface to the internet to get a name on t
|
|||||||
only in its own log? The same silent skip covers a route with no usable port or an unknown scheme.
|
only in its own log? The same silent skip covers a route with no usable port or an unknown scheme.
|
||||||
- What checks that what the controller composes and what the proxy serves stay the same shape? ADR
|
- What checks that what the controller composes and what the proxy serves stay the same shape? ADR
|
||||||
0138 changed one side and nothing failed on the other.
|
0138 changed one side and nothing failed on the other.
|
||||||
|
|
||||||
|
## Resolved (2026-10-02)
|
||||||
|
|
||||||
|
Built as [ADR 0167](../../02-DECISIONS/0167-a-membership-carries-what-its-module-receives-and-who-the-mesh-is.md)
|
||||||
|
decided, and live on both machines that run the proxy. Each logs that its routes now come from its
|
||||||
|
membership, and serves internal names to the four machines the mesh names. Checked by hand:
|
||||||
|
|
||||||
|
- the internal-only route answers through the proxy from the serving machine and from two other
|
||||||
|
machines of the mesh, over a certificate from the mesh's own authority that each verifies;
|
||||||
|
- the same name asked from an address outside the mesh is answered as a name never routed, over plain
|
||||||
|
HTTP, and refused in the TLS handshake; the list of served names it is shown leaves out every internal
|
||||||
|
name.
|
||||||
|
|
||||||
|
Two things the rollout found are their own records: the proxy's bus account could be issued only from
|
||||||
|
the controller's command line, until mesh-controller PR 208 added the `issue` verb, and the status line
|
||||||
|
counting every module as a bus user without a credential is
|
||||||
|
[issue 195](../195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md).
|
||||||
|
The serving machine also lacked the certificate-trust module, so it could not verify the mesh's own
|
||||||
|
certificates until it was assigned there.
|
||||||
|
|||||||
+62
@@ -0,0 +1,62 @@
|
|||||||
|
---
|
||||||
|
status: open
|
||||||
|
opened: 2026-10-02
|
||||||
|
located-in: []
|
||||||
|
fixed-by:
|
||||||
|
amended-design:
|
||||||
|
---
|
||||||
|
|
||||||
|
# 195 — Every assigned module is counted as a bus user without a credential, and the real gaps are lost in the count
|
||||||
|
|
||||||
|
## What was observed
|
||||||
|
|
||||||
|
`status`, and `plan` for any machine, open with one line before anything else:
|
||||||
|
|
||||||
|
```
|
||||||
|
the bus's user list leaves out 49 user(s) the mesh has minted no credential for: <node>.<module>, …
|
||||||
|
Each is a user that cannot connect until one is issued
|
||||||
|
```
|
||||||
|
|
||||||
|
The 49 are spread over four machines and name 26 distinct modules. Checked against the catalogue on
|
||||||
|
2026-10-02:
|
||||||
|
|
||||||
|
| what the module's definition says | modules |
|
||||||
|
|---|---|
|
||||||
|
| declares an own secret named `broker` | 1 — the route proxy, which needed a bus account for issue 191 |
|
||||||
|
| declares no `broker` secret, and emits, consumes and serves nothing on the bus | 17 — the packet filter, the intrusion filter, the ssh daemon, the resolver configuration, the certificate authority, the broker itself and others |
|
||||||
|
| declares no `broker` secret, and **emits events** | 1 |
|
||||||
|
| not in this catalogue, so not checked | 7 |
|
||||||
|
|
||||||
|
So the line counts every module assigned anywhere as a bus user. For almost all of them that is not a
|
||||||
|
missing credential. A module with no `broker` secret has nowhere to receive one, and the mesh already
|
||||||
|
says an account nothing reads is an orphan ([issue 078](../078-a-delivered-secret-is-accepted-under-any-name/00-report.md)).
|
||||||
|
|
||||||
|
Two real gaps sit inside the count and cannot be told from the noise:
|
||||||
|
|
||||||
|
- **A declared `broker` secret was filled with a value that is not an account.** Before its account was
|
||||||
|
issued, the route proxy's plan on both machines already carried a sealed `broker` file, while the same
|
||||||
|
status line said no credential had been minted for it. A push had made the declared secret the way it
|
||||||
|
makes any own secret. The module would have started with a credential the bus does not know, and
|
||||||
|
nothing would have said why. It was found only because the account was being issued by hand.
|
||||||
|
- **A module that emits events declares no way to reach the bus.** Its events can go nowhere, and no
|
||||||
|
check refuses that.
|
||||||
|
|
||||||
|
## Why it matters
|
||||||
|
|
||||||
|
**A warning that is always on is read as never on.** The line names 49 users on every `status` and every
|
||||||
|
`plan`. An operator, or an agent, learns to scroll past it. The one entry that was a real fault looked
|
||||||
|
exactly like the 48 that were not.
|
||||||
|
|
||||||
|
**The fault that was real is the silent kind.** A module whose broker credential is a generated value
|
||||||
|
starts, fails to authenticate, and reports that three layers away from the cause. That is the failure
|
||||||
|
the composition already refuses for a secret that was never made at all ("declared and not made"). Here
|
||||||
|
a value was made, so the refusal never fired.
|
||||||
|
|
||||||
|
## Open questions
|
||||||
|
|
||||||
|
- Should a bus user be composed for a module that declares no `broker` secret at all? If not, the line
|
||||||
|
shrinks to the modules that can actually use an account.
|
||||||
|
- Is a `broker` secret ever correctly made by the generic generator? If not, should composition refuse
|
||||||
|
a declared `broker` until it is issued, or should the mesh issue it as part of placing the module?
|
||||||
|
- Should a module that emits, consumes or serves on the bus be refused when it declares no `broker`
|
||||||
|
secret?
|
||||||
Reference in New Issue
Block a user