--- status: located opened: 2026-09-30 located-in: - mesh-controller internal/catalogue/roster.go (the roster's entries for a routed name) fixed-by: amended-design: --- # 157 — A routed name is published with an `.internal` alias that nothing serves ## What was observed Every machine's hosts file carries two entries for each routed name — the name, and the name with `.internal` appended: ``` 10.10.0.1 keycloak.novox.be.internal keycloak.novox.be 10.10.0.1 drive.novox.be.internal drive.novox.be 10.10.0.1 umami.novox.be.internal umami.novox.be ``` The suffixed one resolves and is served by nothing. The proxy refuses it during the handshake, and says so exactly: ``` http: TLS handshake error from 10.10.0.3:33480: no public route for "keycloak.novox.be.internal" in this mesh, so no certificate is asked for ``` A client sees `curl: (35) TLS connect error ... tlsv1 alert internal error` and no peer certificate — a server-side refusal, with nothing in it to say the name was never real. The name the proxy does serve is `