Add route-proxy provider and hello-web consumer modules

route-proxy is the shipping form of the reference reverse proxy (novox/hq
ADR 0007, 08-connectivity section 3): it provides route, is given every
consumer as the file at receives.route, and forwards by the Host header. It
ships the Go proxy from mesh-control/examples/route-proxy via a multi-stage
Dockerfile; no broker, own-secret or provisioner, since it only reads the file
the mesh writes.

ACME_DIRECTORY defaults to Let's Encrypt staging and is overridable per node to
production, so there is no hardcoded production default -- resolving novox/hq
04-ISSUES/004. hello-web is a minimal consumer that requires route and
contributes name+port, to exercise the grant.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-06 15:07:16 +02:00
parent 9dbbfbb5b4
commit 36640f68e6
4 changed files with 230 additions and 0 deletions
+65
View File
@@ -0,0 +1,65 @@
{
"module": "hello-web",
"version": "1",
"capabilities": [
"container-runtime"
],
"requires": [
"route"
],
"contributes": {
"route": {
"name": "hello.example",
"port": 8080
}
},
"binds": {
"route": "/var/lib/hello-web/route.json"
},
"listens": [
{
"port": 8080,
"protocol": "tcp",
"from": "mesh",
"why": "the demo web page; only the route-proxy reaches it, and the public name is a route grant"
}
],
"resources": [
{
"id": "state",
"type": "directory",
"path": "/var/lib/hello-web",
"mode": "0700"
},
{
"id": "page",
"type": "file",
"path": "/var/lib/hello-web/index.html",
"mode": "0644",
"content": "hello from hello-web, routed by the mesh\n"
},
{
"id": "net",
"type": "network",
"name": "hello-web"
},
{
"id": "server",
"type": "container",
"name": "hello-web",
"image": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b",
"network": "hello-web",
"ports": [
"8080:8080"
],
"volumes": [
"/var/lib/hello-web/index.html:/www/index.html:ro"
],
"args": [
"sh",
"-c",
"while true; do { printf 'HTTP/1.1 200 OK\\r\\nContent-Type: text/plain\\r\\nConnection: close\\r\\n\\r\\n'; cat /www/index.html; } | nc -l -p 8080; done"
]
}
]
}