From e0c92195d4240841bfcf4b4a9ef869d5afeca331 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 14 Sep 2026 22:38:05 +0200 Subject: [PATCH] The builder names the registry by loopback until there is a certificate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Naming it from the binding was right and arrived too early. The moment the machine had a name, the builder pushed to .internal:5000 and the runtime refused it: "http: server gave HTTP response to HTTPS client". The registry serves plaintext, and anything that is not loopback is required to be HTTPS. So there are two phases, and this is the first. Before the mesh has a certificate authority of its own, loopback is the only trusted path that is honest — it is trusted because it cannot leave the machine, not because anyone checked anything. The mesh-reachable name belongs to the second phase, with TLS from the mesh's own CA, and the binding expression returns then. Not a revert of the reasoning: novox/hq issue 048 stays open and this is why. The same one-line change lands again once a certificate module is running. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- modules/builder/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/builder/module.json b/modules/builder/module.json index 0444466..d061ed7 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -37,7 +37,7 @@ "type": "file", "path": "/var/lib/mesh/builder/builder.env", "mode": "0600", - "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_WORKSPACE=/workspace\n" + "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=127.0.0.1:${bound:artifact-store:port}\nMESH_WORKSPACE=/workspace\n" }, { "id": "server",