--- status: open opened: 2026-10-04 located-in: [mesh-catalog modules/photos] fixed-by: amended-design: --- # 227 — The photo app's admin client asks for port 80, which the reverse proxy holds, so it cannot start ## What was observed Applying the control machine, 2026-10-04: ``` applying "photos.admin-client": starting container photos-admin-client: failed to bind host port 0.0.0.0:80/tcp: address already in use ``` Port 80 on that machine belongs to the reverse proxy (`mesh-route-proxy`, confirmed with `ss`), which is the whole arrangement: the proxy holds the public ports and every module is reached through it. A module that publishes 80 itself can never start beside it. Everything else on the machine applied; this one resource fails every pass. ## How it surfaced `photos` had been pinned at a commit from 2026-09-28 and was rebuilt to `main` on 2026-10-04 — forced by [ADR 0202](../../02-DECISIONS/0202-a-provider-declares-what-it-derives-for-each-consumer.md)'s refusal of its transcribed bucket name. The admin client is one of the changes that came with the rest of `main`. The rebuild did not create the conflict; it delivered it. **A module pinned months behind carries whatever its branch gained, all at once, the first time something makes it move.** That is the cost of a pin, and it is paid in full rather than gradually. ## What a fix has to settle - Which port the admin client should ask for, or whether it should be reached through the proxy like everything else and publish nothing. - Whether a module declaring a port the machine's proxy already holds should be refused when it is composed, rather than failing on the machine every pass. The mesh assigns ports ([ADR 0038](../../02-DECISIONS/0038-the-mesh-assigns-the-port.md)); a fixed 80 beside a proxy is a statement it could check.