Issue 122: a module cannot ask for its own public name #121

Merged
jschoubben merged 1 commits from issue/122-a-module-cannot-ask-for-its-own-public-name into main 2026-09-26 12:58:42 +00:00
Owner

Found while reviewing the four open module PRs. Three of them independently write one mesh's names into the catalogue, each for different software and each as the only expressible option:

  • the identity provider gains a literal KC_HOSTNAME, because it generates absolute URLs and cannot derive them behind a proxy (mesh-catalog #55);
  • the object store gains a literal browser-redirect URL, for the same reason (mesh-catalog #58);
  • the file-sync module's bucket is renamed to one carrying this mesh's name, to match a bucket that already exists here (mesh-catalog #59).

The mechanism that would honour ADR 0112 does not exist: a manifest can interpolate ${secret:}, ${seat:}, ${bound:}, ${port:} and ${machine:at|name|address} — the last being the machine's private identity. The mesh does compose <label>.<public-domain> for a route contribution, but that happens as the declaration is built and reaches the proxy, never the module that asked for the route. A module that must tell its own software what it will be reached at cannot read what the mesh already computed.

Filed rather than used to block those three, since the instances are live needs and the fix is a mechanism. The cost is stated plainly: a second mesh installing the identity provider from this catalogue gets the first mesh's hostname and a login flow that fails like a proxy fault, and nothing distinguishes a literal domain from a version number.

located-in: names the controller's declaration builder and the three modules. Checks: cycle 286 documents, the chain holds; records 104, all passed; index current.

Found while reviewing the four open module PRs. Three of them independently write one mesh's names into the catalogue, each for different software and each as the only expressible option: - the identity provider gains a literal `KC_HOSTNAME`, because it generates absolute URLs and cannot derive them behind a proxy (mesh-catalog #55); - the object store gains a literal browser-redirect URL, for the same reason (mesh-catalog #58); - the file-sync module's bucket is renamed to one carrying this mesh's name, to match a bucket that already exists here (mesh-catalog #59). The mechanism that would honour ADR 0112 does not exist: a manifest can interpolate `${secret:}`, `${seat:}`, `${bound:}`, `${port:}` and `${machine:at|name|address}` — the last being the machine's **private** identity. The mesh does compose `<label>.<public-domain>` for a route contribution, but that happens as the declaration is built and reaches the proxy, never the module that asked for the route. A module that must tell its own software what it will be reached at cannot read what the mesh already computed. Filed rather than used to block those three, since the instances are live needs and the fix is a mechanism. The cost is stated plainly: a second mesh installing the identity provider from this catalogue gets the first mesh's hostname and a login flow that fails like a proxy fault, and nothing distinguishes a literal domain from a version number. `located-in:` names the controller's declaration builder and the three modules. Checks: cycle 286 documents, the chain holds; records 104, all passed; index current.
jschoubben added 1 commit 2026-09-26 12:58:32 +00:00
Three open module changes independently wrote one mesh's names into the catalogue — two literal
public URLs, because the software generates absolute URLs behind a proxy, and one bucket renamed to
match what exists here. None was careless: the mesh composes <label>.<public-domain> for the proxy
and never hands it back to the module that asked for the route, and no interpolation yields a public
name, so writing the answer down is the only expressible option.

Files it rather than blocking the three, because the fix is a mechanism and the instances are live
needs. The cost is stated: a second mesh installing the identity provider gets the first mesh's
hostname, and nothing distinguishes a literal domain from a version number.
jschoubben merged commit bfcb660a8e into main 2026-09-26 12:58:42 +00:00
jschoubben deleted branch issue/122-a-module-cannot-ask-for-its-own-public-name 2026-09-26 12:58:43 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#121