Fold public-acme into route-proxy; drop dhcpcd and cloudflare-dns (hq ADR 0226)
public-acme ran nothing and had one consumer. The proxy now states the issuer itself, byte for byte what the binding rendered, so its account directory and every certificate stay put. dhcpcd and cloudflare-dns are assigned nowhere and nothing requires what they provide.
This commit is contained in:
@@ -26,7 +26,7 @@ the same proxy, pointing at the mesh's container instead of the predecessor's.
|
||||
| `serves.route` | `{}` | a route hands back a name, not a credential |
|
||||
| `receives.route` | `…/routes/mesh.json` | the same contributions file, in the same shape |
|
||||
| `listens` | *nothing* | **the point.** It opens no port, so it stands beside the predecessor rather than replacing it |
|
||||
| `requires` | *nothing* | in particular not `acme-ca`: the predecessor holds the certificates and this must not ask for one |
|
||||
| `requires` | *nothing* | in particular no certificate issuer: the predecessor holds the certificates and this must not obtain one |
|
||||
|
||||
Assign **either** this or `route-proxy` to a node, never both — two providers of one mesh-scoped
|
||||
provision is an ambiguity the resolver is right to refuse.
|
||||
@@ -95,7 +95,7 @@ after the module was unassigned.
|
||||
|
||||
Where the predecessor keeps the directory its file provider reads is a fact about **one machine**,
|
||||
so it is a setting laid over the module's default rather than a constant in the catalogue —
|
||||
novox/hq ADR 0100's `ports` is the precedent, and cloudflare-dns's `config.json` is the mechanism:
|
||||
novox/hq ADR 0100's `ports` is the precedent, and the mechanism is
|
||||
a `merge: "json"` file the mesh composes from the module's defaults and the node's layer, mounted
|
||||
into the container.
|
||||
|
||||
@@ -141,7 +141,7 @@ published ports — is a decision for novox/hq, not for a module that is schedul
|
||||
## How it ships
|
||||
|
||||
The tool runtime carrying this module's compiled code, as
|
||||
[cloudflare-dns](../cloudflare-dns/Dockerfile) and [mosquitto](../mosquitto/Dockerfile) do — built
|
||||
[mosquitto](../mosquitto/Dockerfile) does — built
|
||||
from this directory and nothing else. It connects to no broker: reconciling files on the machine it
|
||||
runs on is an offline operation, and `mesh-tools run` gives it exactly that.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user