From 5aacd2538b5a4feae373dcdc5698fcf88013b5c0 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 11 Sep 2026 11:48:51 +0200 Subject: [PATCH] mesh-control: the enrolment endpoint is the substrate's, not the overlay's MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The module said MESH_BROKER_ADDRESS=${machine:at}:5671, and that cannot work in either direction. At genesis it does not resolve at all. `at` is a machine's name on the PRIVATE network, and the mesh only holds one for a node that has an overlay placement and resolves the networking module — neither of which exists when the control plane is installed, which is step 9 of ten, long before anything has been placed anywhere. mesh-control refuses a ${machine:} key it does not hold rather than writing the literal through, so the push would have stopped with "this machine says name". And afterwards it would be the wrong address anyway. This value is what every enrolment token tells a joining node to dial. A machine that has not enrolled is not on the overlay, so an overlay name is precisely the one thing it cannot reach. It is the substrate's own fact — the address the broker advertises, decided by whoever wrote the bundle, which the mesh did not make and cannot invent. So it arrives the way the store connections beside it arrive: an own-secret the installer delivers with `secret accept`, read out of the bundle it produced. mesh-bootstrap already does this for every variable the module fills from a secret; this one simply joins them. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/mesh-control/module.json | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/modules/mesh-control/module.json b/modules/mesh-control/module.json index 3345782..e5e864b 100644 --- a/modules/mesh-control/module.json +++ b/modules/mesh-control/module.json @@ -16,7 +16,8 @@ "identity": "/var/lib/mesh/mesh-control/identity", "licences": "/var/lib/mesh/mesh-control/licences", "broker": "/var/lib/mesh/mesh-control/broker", - "broker-management": "/var/lib/mesh/mesh-control/broker-management" + "broker-management": "/var/lib/mesh/mesh-control/broker-management", + "broker-address": "/var/lib/mesh/mesh-control/broker-address" }, "resources": [ { @@ -30,7 +31,7 @@ "type": "file", "path": "/var/lib/mesh/mesh-control/control.env", "mode": "0600", - "content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${machine:at}:5671\n" + "content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${secret:broker-address}\n" }, { "id": "server",