Fold public-acme into route-proxy; drop dhcpcd and cloudflare-dns (hq ADR 0226)

public-acme ran nothing and had one consumer. The proxy now states the issuer itself, byte for byte
what the binding rendered, so its account directory and every certificate stay put. dhcpcd and
cloudflare-dns are assigned nowhere and nothing requires what they provide.
This commit is contained in:
jochen
2026-10-06 02:21:17 +02:00
parent cc2f19123a
commit 82ef84aa49
12 changed files with 26 additions and 427 deletions
+3 -3
View File
@@ -26,7 +26,7 @@ the same proxy, pointing at the mesh's container instead of the predecessor's.
| `serves.route` | `{}` | a route hands back a name, not a credential |
| `receives.route` | `…/routes/mesh.json` | the same contributions file, in the same shape |
| `listens` | *nothing* | **the point.** It opens no port, so it stands beside the predecessor rather than replacing it |
| `requires` | *nothing* | in particular not `acme-ca`: the predecessor holds the certificates and this must not ask for one |
| `requires` | *nothing* | in particular no certificate issuer: the predecessor holds the certificates and this must not obtain one |
Assign **either** this or `route-proxy` to a node, never both — two providers of one mesh-scoped
provision is an ambiguity the resolver is right to refuse.
@@ -95,7 +95,7 @@ after the module was unassigned.
Where the predecessor keeps the directory its file provider reads is a fact about **one machine**,
so it is a setting laid over the module's default rather than a constant in the catalogue —
novox/hq ADR 0100's `ports` is the precedent, and cloudflare-dns's `config.json` is the mechanism:
novox/hq ADR 0100's `ports` is the precedent, and the mechanism is
a `merge: "json"` file the mesh composes from the module's defaults and the node's layer, mounted
into the container.
@@ -141,7 +141,7 @@ published ports — is a decision for novox/hq, not for a module that is schedul
## How it ships
The tool runtime carrying this module's compiled code, as
[cloudflare-dns](../cloudflare-dns/Dockerfile) and [mosquitto](../mosquitto/Dockerfile) do — built
[mosquitto](../mosquitto/Dockerfile) does — built
from this directory and nothing else. It connects to no broker: reconciling files on the machine it
runs on is an offline operation, and `mesh-tools run` gives it exactly that.