Every module names its endpoints, and every route names the one it serves

75 endpoints across 50 modules, named from what each one is for rather than by a
rule: mail's seven protocol ports are smtp, imaps, submission and the rest; unifi's
nine are inform, stun, discovery, the two portal ports and syslog; minio's two are
s3 and console; the resolver's two are dns-udp and dns-tcp.

And 35 route contributions name the endpoint they serve instead of repeating its
port. A route and a listen both carried a port and nothing said they were the same
thing; now one of them does. gitea's path-level deny rule names neither, because it
is a rule about a name rather than an endpoint.

novox/hq ADR 0138. The words shipped a release ahead in mesh-controller #138 and
#139, and the control plane running today is built from that merge — checked before
this was written, because an unknown manifest key is refused and a catalogue using
one against an older control plane would stop resolving.
This commit is contained in:
2026-09-29 11:51:39 +02:00
parent 822df220ab
commit f118344246
50 changed files with 110 additions and 35 deletions
+2 -1
View File
@@ -14,7 +14,7 @@
}, },
"route": { "route": {
"label": "baserow", "label": "baserow",
"port": 80 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -30,6 +30,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 80, "port": 80,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -13,6 +13,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 6767, "port": 6767,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -110,7 +111,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "subs", "label": "subs",
"port": 6767 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -15,6 +15,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8787, "port": 8787,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -87,7 +88,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "books", "label": "books",
"port": 8787 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -11,7 +11,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "de-spiegel", "label": "de-spiegel",
"port": 35621 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -23,6 +23,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 35621, "port": 35621,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -29,6 +29,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "registry",
"port": 5000, "port": 5000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2
View File
@@ -22,6 +22,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "dns-udp",
"port": 53, "port": 53,
"protocol": "udp", "protocol": "udp",
"from": "mesh", "from": "mesh",
@@ -29,6 +30,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "dns-tcp",
"port": 53, "port": 53,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+3 -1
View File
@@ -13,7 +13,7 @@
"route": { "route": {
"web": { "web": {
"label": "git", "label": "git",
"port": 3000 "endpoint": "web"
}, },
"internal-api-refused": { "internal-api-refused": {
"label": "git", "label": "git",
@@ -44,12 +44,14 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 3000, "port": 3000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the forge, over http" "why": "the forge, over http"
}, },
{ {
"name": "ssh",
"port": 22, "port": 22,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -13,6 +13,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 3000, "port": 3000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -96,7 +97,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "grafana", "label": "grafana",
"port": 3000 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -11,7 +11,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "hello", "label": "hello",
"port": 8080 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -19,6 +19,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -14,6 +14,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8123, "port": 8123,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -85,7 +86,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "home-assistant", "label": "home-assistant",
"port": 8123 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+1
View File
@@ -13,6 +13,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "stream",
"port": 8000, "port": 8000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -9,6 +9,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "api",
"port": 8086, "port": 8086,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+4 -2
View File
@@ -17,11 +17,11 @@
"route": { "route": {
"site": { "site": {
"label": "invoicing", "label": "invoicing",
"port": 80 "endpoint": "web"
}, },
"api": { "api": {
"label": "invoicing-api", "label": "invoicing-api",
"port": 9000 "endpoint": "api"
} }
} }
}, },
@@ -36,12 +36,14 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 80, "port": 80,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the invoicing web frontend; a public name is a route grant later" "why": "the invoicing web frontend; a public name is a route grant later"
}, },
{ {
"name": "api",
"port": 9000, "port": 9000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -6,6 +6,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 9117, "port": 9117,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -82,7 +83,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "indexers", "label": "indexers",
"port": 9117 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -11,7 +11,7 @@
}, },
"route": { "route": {
"label": "keycloak", "label": "keycloak",
"port": 8080 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -34,6 +34,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -24,6 +24,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8283, "port": 8283,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -14,6 +14,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8686, "port": 8686,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -86,7 +87,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "lidarr", "label": "lidarr",
"port": 8686 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+15 -5
View File
@@ -16,27 +16,27 @@
"route": { "route": {
"web": { "web": {
"label": "mail", "label": "mail",
"port": 7443, "endpoint": "web-tls",
"scheme": "https", "scheme": "https",
"insecure": true "insecure": true
}, },
"acme": { "acme": {
"label": "mail", "label": "mail",
"path": "/.well-known/acme-challenge", "path": "/.well-known/acme-challenge",
"port": 7080, "endpoint": "web",
"priority": 100 "priority": 100
}, },
"autoconfig": { "autoconfig": {
"label": "autoconfig", "label": "autoconfig",
"port": 4243 "endpoint": "autoconfig"
}, },
"autodiscover": { "autodiscover": {
"label": "autodiscover", "label": "autodiscover",
"port": 4243 "endpoint": "autoconfig"
}, },
"automx": { "automx": {
"label": "automx", "label": "automx",
"port": 4243 "endpoint": "autoconfig"
} }
} }
}, },
@@ -60,6 +60,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "smtp",
"port": 25, "port": 25,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -67,6 +68,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "pop3",
"port": 110, "port": 110,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -74,6 +76,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "imap",
"port": 143, "port": 143,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -81,6 +84,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "smtps",
"port": 465, "port": 465,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -88,6 +92,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "submission",
"port": 587, "port": 587,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -95,6 +100,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "imaps",
"port": 993, "port": 993,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -102,6 +108,7 @@
"fixed": true "fixed": true
}, },
{ {
"name": "pop3s",
"port": 995, "port": 995,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
@@ -109,18 +116,21 @@
"fixed": true "fixed": true
}, },
{ {
"name": "web",
"port": 7080, "port": 7080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy" "why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
}, },
{ {
"name": "web-tls",
"port": 7443, "port": 7443,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here" "why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
}, },
{ {
"name": "autoconfig",
"port": 4243, "port": 4243,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -6,6 +6,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "api",
"port": 59125, "port": 59125,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+4 -2
View File
@@ -14,11 +14,11 @@
"route": { "route": {
"api": { "api": {
"label": "files-api", "label": "files-api",
"port": 9000 "endpoint": "s3"
}, },
"console": { "console": {
"label": "files", "label": "files",
"port": 9001 "endpoint": "console"
} }
} }
}, },
@@ -31,12 +31,14 @@
], ],
"listens": [ "listens": [
{ {
"name": "s3",
"port": 9000, "port": 9000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the S3 endpoint" "why": "the S3 endpoint"
}, },
{ {
"name": "console",
"port": 9001, "port": 9001,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -20,6 +20,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "database",
"port": 27017, "port": 27017,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2
View File
@@ -34,12 +34,14 @@
}, },
"listens": [ "listens": [
{ {
"name": "mqtt",
"port": 1883, "port": 1883,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "modules on any machine that were granted a topic namespace" "why": "modules on any machine that were granted a topic namespace"
}, },
{ {
"name": "mqtt-websockets",
"port": 8081, "port": 8081,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -20,6 +20,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "database",
"port": 4848, "port": 4848,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -14,7 +14,7 @@
}, },
"route": { "route": {
"label": "n8n", "label": "n8n",
"port": 5682 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -29,6 +29,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 5682, "port": 5682,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -21,6 +21,7 @@
"consumes": [], "consumes": [],
"listens": [ "listens": [
{ {
"name": "bus",
"port": 4222, "port": 4222,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -13,7 +13,7 @@
}, },
"route": { "route": {
"label": "drive", "label": "drive",
"port": 80 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -38,6 +38,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 80, "port": 80,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -12,6 +12,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 1880, "port": 1880,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -81,7 +82,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "nodered", "label": "nodered",
"port": 1880 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -10,7 +10,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "@", "label": "@",
"port": 4000 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -18,6 +18,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 4000, "port": 4000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -15,6 +15,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 6789, "port": 6789,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -12,6 +12,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "api",
"port": 11434, "port": 11434,
"protocol": "tcp", "protocol": "tcp",
"from": "machine", "from": "machine",
+2 -1
View File
@@ -14,6 +14,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 3579, "port": 3579,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -89,7 +90,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "ombi", "label": "ombi",
"port": 3579 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -11,7 +11,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "office", "label": "office",
"port": 9070 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -22,6 +22,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 9070, "port": 9070,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -11,7 +11,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "eef", "label": "eef",
"port": 4012 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -19,6 +19,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 4012, "port": 4012,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -11,7 +11,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "filip", "label": "filip",
"port": 4013 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -19,6 +19,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 4013, "port": 4013,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+3 -1
View File
@@ -18,7 +18,7 @@
}, },
"route": { "route": {
"label": "photos", "label": "photos",
"port": 4001 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -32,12 +32,14 @@
}, },
"listens": [ "listens": [
{ {
"name": "api",
"port": 9000, "port": 9000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the photos backend API; the client sites on the module network call it" "why": "the photos backend API; the client sites on the module network call it"
}, },
{ {
"name": "web",
"port": 4001, "port": 4001,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -18,6 +18,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "stream",
"port": 32400, "port": 32400,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+3 -1
View File
@@ -7,12 +7,14 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 9090, "port": 9090,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number" "why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
}, },
{ {
"name": "web-tls",
"port": 9443, "port": 9443,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -103,7 +105,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "portainer", "label": "portainer",
"port": 9090 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+1
View File
@@ -26,6 +26,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "database",
"port": 5432, "port": 5432,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+1
View File
@@ -16,6 +16,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -14,6 +14,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 7878, "port": 7878,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -86,7 +87,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "movies", "label": "movies",
"port": 7878 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+1
View File
@@ -40,6 +40,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "cache",
"port": 6379, "port": 6379,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2
View File
@@ -27,12 +27,14 @@
}, },
"listens": [ "listens": [
{ {
"name": "http",
"port": 80, "port": 80,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified" "why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
}, },
{ {
"name": "https",
"port": 443, "port": 443,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
+2 -1
View File
@@ -10,6 +10,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -113,7 +114,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "searxng", "label": "searxng",
"port": 8080 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+1
View File
@@ -43,6 +43,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -14,6 +14,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 8989, "port": 8989,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -91,7 +92,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "series", "label": "series",
"port": 8989 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+1
View File
@@ -7,6 +7,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "ssh",
"port": 22, "port": 22,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
+1
View File
@@ -26,6 +26,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "acme",
"port": 9000, "port": 9000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+2 -1
View File
@@ -12,6 +12,7 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 8181, "port": 8181,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
@@ -85,7 +86,7 @@
"contributes": { "contributes": {
"route": { "route": {
"label": "tautulli", "label": "tautulli",
"port": 8181 "endpoint": "web"
} }
}, },
"binds": { "binds": {
+2 -1
View File
@@ -15,7 +15,7 @@
}, },
"route": { "route": {
"label": "umami", "label": "umami",
"port": 3000 "endpoint": "web"
} }
}, },
"binds": { "binds": {
@@ -49,6 +49,7 @@
}, },
"listens": [ "listens": [
{ {
"name": "web",
"port": 3000, "port": 3000,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
+9
View File
@@ -6,54 +6,63 @@
], ],
"listens": [ "listens": [
{ {
"name": "web",
"port": 8443, "port": 8443,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later" "why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
}, },
{ {
"name": "inform",
"port": 8080, "port": 8080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "device inform \u2014 how APs and switches check in and are adopted" "why": "device inform \u2014 how APs and switches check in and are adopted"
}, },
{ {
"name": "stun",
"port": 3478, "port": 3478,
"protocol": "udp", "protocol": "udp",
"from": "mesh", "from": "mesh",
"why": "STUN, so managed devices can find the controller through NAT" "why": "STUN, so managed devices can find the controller through NAT"
}, },
{ {
"name": "discovery",
"port": 10001, "port": 10001,
"protocol": "udp", "protocol": "udp",
"from": "mesh", "from": "mesh",
"why": "device discovery \u2014 the controller finds unadopted devices on the network" "why": "device discovery \u2014 the controller finds unadopted devices on the network"
}, },
{ {
"name": "discovery-l2",
"port": 1902, "port": 1902,
"protocol": "udp", "protocol": "udp",
"from": "mesh", "from": "mesh",
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900" "why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
}, },
{ {
"name": "portal-tls",
"port": 8843, "port": 8843,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the guest captive portal over https" "why": "the guest captive portal over https"
}, },
{ {
"name": "portal",
"port": 8880, "port": 8880,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the guest captive portal over http" "why": "the guest captive portal over http"
}, },
{ {
"name": "speedtest",
"port": 6789, "port": 6789,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "mobile-app speed-test throughput measurement" "why": "mobile-app speed-test throughput measurement"
}, },
{ {
"name": "syslog",
"port": 5514, "port": 5514,
"protocol": "udp", "protocol": "udp",
"from": "mesh", "from": "mesh",