11 modules: a container's ports say the software's port, not the machine's

hq issue 091, measured 2026-09-22: 14 of 46 modules with containers fix the
machine side of a published port in their own manifest -- a fact about one
machine (which port HAL happened to publish it on) written into a
definition meant for any node. ADR 0038 already says the mesh assigns the
machine side and a module says only what it needs; the machinery already
does it (internal/inventory/ports.go's PortFor, declaration.go's
publishedOn rewrites a bare port automatically). These 14 just never
complied.

Fixed 11 of them -- stripped to the bare software port, letting assignment
take over: de-spiegel, gitea, hello-web (the demo module), mailu, mssql,
n8n, novox.be, only-office, photos, photos-eef, photos-filip.

Left alone, the two defensible kinds the issue names: postgres/lavinmq/
distribution (foundation, genesis-rewritten per ADR 0100 -- the number in
the manifest is a default, not a claim) and unifi (protocol/
device-discovery fixes the number; nothing else can find the controller).

gitea was a live one, not just a tidiness fix: its manifest said 2222:22,
but the actual adopted, running container is on 222. Harmless while held,
but the next 'take' would have recreated it on the wrong port and broken
SSH git access. Recorded 222 as novox's own setting for it (settings set
gitea -node novox) so that doesn't happen.
This commit is contained in:
2026-09-24 15:45:58 +02:00
parent 415ad7a168
commit 12f885ffc5
11 changed files with 11 additions and 11 deletions
+1 -1
View File
@@ -58,7 +58,7 @@
"/var/lib/de-spiegel/server.env"
],
"ports": [
"35621:35621"
"35621"
],
"secrets-in-environment": "the application's own code reads SMTP_AUTH_USER/PASS from the environment (de-spiegel server/index.js); converting is that repository's change"
}
+1 -1
View File
@@ -118,7 +118,7 @@
],
"ports": [
"3000",
"2222:22"
"22"
],
"volumes": [
"/services/gitea/gitea:/data"
+1 -1
View File
@@ -50,7 +50,7 @@
"name": "hello-web",
"network": "hello-web",
"ports": [
"8080:8080"
"8080"
],
"volumes": [
"/var/lib/hello-web/index.html:/www/index.html:ro"
+1 -1
View File
@@ -368,7 +368,7 @@
"465",
"587",
"993",
"7080:80"
"80"
],
"volumes": [
"/services/mailu/data/certs:/certs",
+1 -1
View File
@@ -87,7 +87,7 @@
"/var/lib/mssql/sa.env"
],
"ports": [
"4848:1433"
"1433"
],
"volumes": [
"/services/mssql/data:/var/opt/mssql"
+1 -1
View File
@@ -71,7 +71,7 @@
"/var/lib/n8n/server.env"
],
"ports": [
"5682:5678"
"5678"
],
"volumes": [
"/services/n8n/n8n-data:/home/node/.n8n"
+1 -1
View File
@@ -43,7 +43,7 @@
"image": "registry-api.novox.be/novox/www@sha256:aa7ed20a293e1d7444c5c5d59b6d8bdb382bad159559a22e006810e379cae69c",
"network": "novox-be",
"ports": [
"4000:8080"
"8080"
]
}
]
+1 -1
View File
@@ -99,7 +99,7 @@
"/var/lib/only-office/server.env"
],
"ports": [
"9070:80"
"80"
],
"volumes": [
"/services/only-office/logs:/var/log/onlyoffice",
+1 -1
View File
@@ -44,7 +44,7 @@
"image": "registry-api.novox.be/novox/photos-client@sha256:f87d63ee7bfb44c9f9748b99be6ba6dc0daf955a1d463699e9e7e3009693c0ab",
"network": "photos-eef",
"ports": [
"4012:80"
"80"
]
}
]
+1 -1
View File
@@ -44,7 +44,7 @@
"image": "registry-api.novox.be/novox/photos-client@sha256:f87d63ee7bfb44c9f9748b99be6ba6dc0daf955a1d463699e9e7e3009693c0ab",
"network": "photos-filip",
"ports": [
"4013:80"
"80"
]
}
]
+1 -1
View File
@@ -84,7 +84,7 @@
"image": "registry-api.novox.be/novox/photos-admin-client@sha256:f437fa9ed28b29a012f715fb8d9b809a15cff4a672794c620d5d400f57695580",
"network": "photos",
"ports": [
"4001:80"
"80"
]
}
]