Files
hq/04-ISSUES/158-the-proxy-re-reads-and-re-logs-every-route-every-two-seconds/00-report.md
T
jschoubben e41eed0852 Issue 129 is live and reproduced, and needs three steps rather than one
The certificate is genuine, from Mesh Internal CA, and nothing on the
workstation trusts it — verbatim the error the report gives. The public
name on the same proxy verifies cleanly, which puts the fault exactly
where the report puts it.

What is in the way is not an assignment. `ca-trust` is merged in the
catalogue and has never been registered with the mesh — 39 of 76
manifests are — so there is no module to assign. It dry-runs clean and
needs no artifact built.

Two findings from reproducing it, both their own issues:

157 — every routed name is published with an `.internal` alias that
nothing serves. The hosts file says keycloak.novox.be.internal; the proxy
serves keycloak.novox.internal and refuses the other by name. The first
three names I tried came from the hosts file and failed with a TLS alert
rather than a verification error, which pointed at a regression that had
not happened.

158 — the proxy re-logs all 52 routes every two seconds, 31 times a
minute. The one line that explained 157 sat between two of them.

Also recorded, because it was nearly filed as a defect and is not one:
step-ca publishes roots as /roots.pem, which is PEM, so ca-trust's fetch
and its refuse-a-non-certificate guard are both right. Its other endpoint
/roots returns JSON that contains the text the guard greps for, so the
guard is sound only because of which path is published.
2026-09-30 01:30:24 +02:00

2.1 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-09-30

158 — The proxy re-reads and re-logs every route it serves, every two seconds

What was observed

The route proxy on the control node logs the whole of what it serves about every two seconds — measured 2026-09-30, 31 times in sixty seconds, each line naming all 52 routes:

23:27:19 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be
23:27:21 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be
23:27:23 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be

Nothing is changing. The route set is identical every time.

Why it matters

It buries the only line that matters. Between two of those entries sits the one error that explained a failing name:

23:27:23 http: TLS handshake error from 10.10.0.3:33480:
  no public route for "keycloak.novox.be.internal" in this mesh, so no certificate is asked for

One line of signal to roughly 5,000 characters of repetition, and the diagnosis it belonged to (issue 157) was found by grepping past it. A log that says the same true thing every two seconds is a log nobody reads, which is the same failure as one that says nothing — and it is the mesh's own accuracy rule pointed the other way: a report that is loud about the unchanging is not reporting.

Whether the re-read is also wasteful is secondary and unmeasured — it may be a cheap file stat. The logging is not in question.

Where to look

Not localised. The proxy is mesh-controller examples/route-proxy; whether it re-reads on a timer or on a file watch, and whether it logs unconditionally or only on change, is the first thing to read. Saying what changed — or saying nothing — is the behaviour wanted, and the mesh already has the rule written down for its own reports: a log that is quiet on success and loud on failure reads as broken when it is working, and one that is loud always reads as nothing.