From a49f598a4ea25659c220d20fa08535a61fc8bf51 Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 12:35:58 +0200 Subject: [PATCH] Manifests publish software ports; the machine side is the assignment's MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit postgres, distribution, gitea, mailu, only-office and portainer published long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port in a definition (ADR 0038, the migration note). Each now publishes the software's port and names it in listens (mailu's web/web-tls and only-office's and portainer's web said the machine number); mailu's env says ${port:80}/${port:443} instead of 7080/7443. Nothing moves on novox. postgres, distribution and gitea already have their machine ports as novox settings (6852, 5100, 222); mailu, only-office and portainer need theirs set BEFORE this rolls out: settings set mailu {"ports":{"80":7080,"443":7443}} --node novox settings set only-office {"ports":{"80":9070}} --node novox settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox Those pins are accepted by today's manifests too (GivenPorts answers to the container port), so setting them first changes nothing either. Verified with the controller's own publishedOn/portInto/GivenPorts on novox's settings (+ the three pins): every container's published ports and mailu's env file render byte-identical before and after — mesh-store 6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80 7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443. Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a short form cannot express; its monitor port needs its own change. --- modules/distribution/module.json | 2 +- modules/gitea/module.json | 4 ++-- modules/mailu/module.json | 10 +++++----- modules/only-office/module.json | 4 ++-- modules/portainer/module.json | 8 ++++---- modules/postgres/module.json | 2 +- 6 files changed, 15 insertions(+), 15 deletions(-) diff --git a/modules/distribution/module.json b/modules/distribution/module.json index 00c7740..25d61c1 100644 --- a/modules/distribution/module.json +++ b/modules/distribution/module.json @@ -55,7 +55,7 @@ "name": "mesh-registry", "image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373", "ports": [ - "5000:5000" + "5000" ], "volumes": [ "/var/lib/mesh-registry:/var/lib/registry" diff --git a/modules/gitea/module.json b/modules/gitea/module.json index c7f1ac4..24f231b 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -55,7 +55,7 @@ "port": 22, "protocol": "tcp", "from": "mesh", - "why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention \u2014 not 22, which the machine's own daemon holds and a module does not take" + "why": "git over ssh, gitea's own unmodified sshd. Its machine port is the assignment's: never 22, which the machine's own daemon holds and a module does not take" } ], "serves": { @@ -140,7 +140,7 @@ ], "ports": [ "3000", - "222:22" + "22" ], "volumes": [ "${dir:data}:/data" diff --git a/modules/mailu/module.json b/modules/mailu/module.json index 581595e..bc7fdc6 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -117,14 +117,14 @@ }, { "name": "web", - "port": 7080, + "port": 80, "protocol": "tcp", "from": "mesh", "why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy" }, { "name": "web-tls", - "port": 7443, + "port": 443, "protocol": "tcp", "from": "mesh", "why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here" @@ -168,7 +168,7 @@ "type": "file", "path": "${dir:state}/mailu.env", "mode": "0644", - "content": "ADMIN_ADDRESS=mailu-admin\nANTISPAM_ADDRESS=mailu-antispam\nANTIVIRUS_ADDRESS=mailu-antivirus\nIMAP_ADDRESS=mailu-imap\nSMTP_ADDRESS=mailu-smtp\nFRONT_ADDRESS=mailu-front\nWEBMAIL_ADDRESS=mailu-webmail\nWEBDAV_ADDRESS=mailu-webdav\nREDIS_ADDRESS=mailu-redis\nPORTS=25,80,443,465,993,995,4190,110,143,587\nDOMAIN=novox.be\nHOSTNAMES=mail.novox.be\nPOSTMASTER=admin\nSITENAME=Novox\nWEBSITE=https://novox.be\nTLS_FLAVOR=letsencrypt\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=novox.be\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=7080\nHTTPS_PORT=7443\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=mail.novox.be\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=mail.novox.be\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=novox.be\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=142.132.152.141\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\nWELCOME_SUBJECT=Welcome to your new email account\nWELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!\n" + "content": "ADMIN_ADDRESS=mailu-admin\nANTISPAM_ADDRESS=mailu-antispam\nANTIVIRUS_ADDRESS=mailu-antivirus\nIMAP_ADDRESS=mailu-imap\nSMTP_ADDRESS=mailu-smtp\nFRONT_ADDRESS=mailu-front\nWEBMAIL_ADDRESS=mailu-webmail\nWEBDAV_ADDRESS=mailu-webdav\nREDIS_ADDRESS=mailu-redis\nPORTS=25,80,443,465,993,995,4190,110,143,587\nDOMAIN=novox.be\nHOSTNAMES=mail.novox.be\nPOSTMASTER=admin\nSITENAME=Novox\nWEBSITE=https://novox.be\nTLS_FLAVOR=letsencrypt\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=novox.be\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=${port:80}\nHTTPS_PORT=${port:443}\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=mail.novox.be\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=mail.novox.be\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=novox.be\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=142.132.152.141\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\nWELCOME_SUBJECT=Welcome to your new email account\nWELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!\n" }, { "id": "secret-env", @@ -456,8 +456,8 @@ "587", "993", "995", - "7080:80", - "7443:443" + "80", + "443" ], "volumes": [ "${dir:data-certs}:/certs", diff --git a/modules/only-office/module.json b/modules/only-office/module.json index 9285015..533c802 100644 --- a/modules/only-office/module.json +++ b/modules/only-office/module.json @@ -23,7 +23,7 @@ "listens": [ { "name": "web", - "port": 9070, + "port": 80, "protocol": "tcp", "from": "mesh", "why": "the document server over http; the public name office.novox.be is a route grant, and route-proxy reaches it on this published port" @@ -93,7 +93,7 @@ "${dir:state}/server.env" ], "ports": [ - "9070:80" + "80" ], "volumes": [ "${dir:logs}:/var/log/onlyoffice", diff --git a/modules/portainer/module.json b/modules/portainer/module.json index 26844b6..7c639b2 100644 --- a/modules/portainer/module.json +++ b/modules/portainer/module.json @@ -8,10 +8,10 @@ "listens": [ { "name": "web", - "port": 9090, + "port": 9000, "protocol": "tcp", "from": "mesh", - "why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number" + "why": "the dashboard over http; routed, so the proxy reaches it here" }, { "name": "web-tls", @@ -39,8 +39,8 @@ "name": "portainer", "image": "portainer/portainer-ce@sha256:4d616db18cfeb5dd41a69c0958bc825c84483ea9cde1106eb82a5d26f3bd8b0e", "ports": [ - "9090:9000", - "9443:9443" + "9000", + "9443" ], "volumes": [ "${dir:data}:/data", diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 197eade..5fcf84e 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -87,7 +87,7 @@ "PGDATA": "/var/lib/postgresql/data/pgdata" }, "ports": [ - "5432:5432" + "5432" ], "volumes": [ "/var/lib/mesh-store:/var/lib/postgresql/data",