Two faults found while preparing the control-node's convergence, the last machine still
running the packet filter it had before the mesh.
140 — an endpoint's reach is declared nowhere. A module has ports, and separately it has
routes. Nothing binds a port to a name to a certificate, so the filter, the proxy's names and
the certificate authority each settle reach on their own: a per-node setting overrides a port's
source and is read by the filter alone, while the proxy composes both a public and an internal
name for every route it is given and obtains a certificate for each from a different authority.
Measured: an identity provider carries a 90-day public certificate and a 24-hour internal one,
neither asked for by any assignment. "This endpoint must not be public" cannot be written, so it
is enforced by nothing — and the open certificate questions (which authority, expiry, revocation)
cannot be answered until it can be.
141 — the forward chain follows constants, not the modules. It allows two ranges named in the
control plane's source plus a list a person types since ADR 0137. The machine measured hosts 21
container networks; six fall outside the constant and would have lost their guests on the flip.
Four of those six are networks the mesh's own modules declare and the host created; two are
predecessor leftovers. Any range wide enough to keep the four forwards the two as well. ADR 0137
rejected deriving this from what the machine reports, correctly — but deriving it from the declaration has neither objection it raised: the set is known before the network exists, and it
cannot widen itself.
Both end in open questions; neither proposes a fix. Diagnosis and graduation are separate steps.
Two faults found while preparing the control-node's convergence, the last machine still
running the packet filter it had before the mesh.
**140 — an endpoint's reach is declared nowhere.** A module has ports, and separately it has
routes. Nothing binds a port to a name to a certificate, so the filter, the proxy's names and
the certificate authority each settle reach on their own: a per-node setting overrides a port's
source and is read by the filter alone, while the proxy composes both a public and an internal
name for every route it is given and obtains a certificate for each from a different authority.
Measured: an identity provider carries a 90-day public certificate and a 24-hour internal one,
neither asked for by any assignment. "This endpoint must not be public" cannot be written, so it
is enforced by nothing — and the open certificate questions (which authority, expiry, revocation)
cannot be answered until it can be.
**141 — the forward chain follows constants, not the modules.** It allows two ranges named in the
control plane's source plus a list a person types since ADR 0137. The machine measured hosts 21
container networks; six fall outside the constant and would have lost their guests on the flip.
Four of those six are networks the mesh's own modules declare and the host created; two are
predecessor leftovers. Any range wide enough to keep the four forwards the two as well. ADR 0137
rejected deriving this from *what the machine reports*, correctly — but deriving it from the
*declaration* has neither objection it raised: the set is known before the network exists, and it
cannot widen itself.
Both end in open questions; neither proposes a fix. Diagnosis and graduation are separate steps.
Found preparing the control-node's convergence. Reach is settled independently by
the filter, the proxy's names and the certificate authority, so "this must not be
public" cannot be written and a public certificate is obtained regardless. And the
forward chain allows two hardcoded ranges plus a typed list, though the mesh
already knows which networks exist because its own modules declared them — a range
wide enough to keep four of them would have forwarded two predecessor leftovers too.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two faults found while preparing the control-node's convergence, the last machine still
running the packet filter it had before the mesh.
140 — an endpoint's reach is declared nowhere. A module has ports, and separately it has
routes. Nothing binds a port to a name to a certificate, so the filter, the proxy's names and
the certificate authority each settle reach on their own: a per-node setting overrides a port's
source and is read by the filter alone, while the proxy composes both a public and an internal
name for every route it is given and obtains a certificate for each from a different authority.
Measured: an identity provider carries a 90-day public certificate and a 24-hour internal one,
neither asked for by any assignment. "This endpoint must not be public" cannot be written, so it
is enforced by nothing — and the open certificate questions (which authority, expiry, revocation)
cannot be answered until it can be.
141 — the forward chain follows constants, not the modules. It allows two ranges named in the
control plane's source plus a list a person types since ADR 0137. The machine measured hosts 21
container networks; six fall outside the constant and would have lost their guests on the flip.
Four of those six are networks the mesh's own modules declare and the host created; two are
predecessor leftovers. Any range wide enough to keep the four forwards the two as well. ADR 0137
rejected deriving this from what the machine reports, correctly — but deriving it from the
declaration has neither objection it raised: the set is known before the network exists, and it
cannot widen itself.
Both end in open questions; neither proposes a fix. Diagnosis and graduation are separate steps.