ADR 0138: reach asks for names on a routed endpoint #178

Merged
mesh-admin merged 1 commits from decision/0138-insight-reach-and-the-proxy into main 2026-09-29 00:50:29 +00:00
Contributor
No description provided.
mesh-admin added 1 commit 2026-09-29 00:50:27 +00:00
The record says internal and public each mean something to the filter. For an
endpoint the proxy serves, the second half is wrong, and ADR 0045 said so first:
a public service is exposed through the proxy, listening from the mesh, not by
opening its own port.

Found by trying to express one real module, not by review — routed name public
because browsers post to it, machine port private because it serves a dashboard in
cleartext. Under one value for both, saying public would have reopened a port an
operator had just closed. Measured the same evening: the routed name answered from
the internet over TLS while the port was refused from the same place.

Corrects a fact. One statement per endpoint with three things derived from it
stands; the filter column applies to an unrouted endpoint.
mesh-admin merged commit 5ac77e3cef into main 2026-09-29 00:50:29 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#178