Commit Graph
244 Commits
Author SHA1 Message Date
jschoubben d0fed5b982 Merge pull request 'The forge's own address follows the port the node gave it (hq issue 088)' (#40) from feat/forge-address into main 2026-09-22 23:29:47 +02:00
jschoubben cf30d4b3d0 The forge's sidecar dials the port the machine put the forge on (hq issue 088)
MESH_GITEA_URL named 3000 outright. The forge's container publishes 3000 without
fixing the machine side, so the mesh assigns it — and on a node given that port
as a setting it is the operator's number. The mapping that lets the forge go on
binding 3000 does nothing for a caller dialling the machine's loopback, so the
sidecar dialled a port nothing was listening on wherever the two differed.

${port:3000} is the mesh's answer to exactly that question, and it now resolves
in a container's environment as it always has in a file. The forge declares it
listens on 3000, so it may ask.

Still names 3000: the route contribution (hq issue 089) and the `listens` and
`ports` entries, which are the software's own number and belong there.
2026-09-22 22:36:34 +02:00
jschoubben 5706c00566 Merge pull request 'The builder's package binding is settable per node (hq issue 085)' (#39) from feat/packages-port into main 2026-09-22 21:59:57 +02:00
jschoubben b2e29871fd Protect the address the builder sends its registry password to
`at` was settable. A node setting could point the builder's package binding at
any host, and the builder sends its registry credential there as basic auth — so
a setting meant for a port was a way to hand the password to somebody else.

novox/hq 04-ISSUES/085
2026-09-22 21:56:51 +02:00
jschoubben d63f006cb8 The builder's package binding takes its port from the node, not from the manifest
The forge is raised by hand at genesis, before any module provides
`package-registry`, so the builder carries a binding instead of resolving one —
and the port in it was rewritten, as text, by the installer. A later
registration of this manifest from the catalogue put 3000 back, silently, and
pointed the builder and its registry credential at whatever holds that port.

Made settable instead: the port is a per-node setting the controller holds, and
the catalogue's number is only its default. `provision`, `from` and `as` are
protected — a setting here is about where the forge answers, never about who the
binding is with.

novox/hq 04-ISSUES/085, ADR 0100
2026-09-22 21:39:54 +02:00
jschoubben 6e88982498 Merge pull request 'Adoption mode: guards, and a filter unit that never flushes the ruleset (hq ADR 0100, 0103)' (#38) from feat/adoption-mode into main 2026-09-22 21:01:56 +02:00
jschoubben 90104d0818 Reload the filter on a rule change rather than restart it, so the node is never unfiltered in between (hq ADR 0102) 2026-09-22 19:47:43 +02:00
jschoubben 84012fab2e Make the stock nftables unit's stop delete only the mesh's table on nodes that still have it enabled (hq ADR 0100) 2026-09-22 18:06:15 +02:00
jschoubben 0c37d7389d Guard the store and management ports on adopted nodes, and load the filter through a unit that never flushes the ruleset (hq ADR 0100) 2026-09-22 17:32:32 +02:00
jschoubben f4097b3c57 Merge pull request 'n8n and baserow no longer take the shared cache (issue 081)' (#37) from multiple-fixes into main 2026-09-22 13:53:14 +02:00
jschoubben 431627c510 baserow: its data directory is 0755, as the image ships it — the cache it runs for itself does so as another user, who must reach its own directory beneath (issue 081) 2026-09-22 13:46:01 +02:00
jschoubben 93634041db baserow: its texts no longer name the shared cache it stopped taking 2026-09-22 12:34:58 +02:00
jschoubben 24cbac816d n8n and baserow no longer take the shared cache: neither can keep its keys and channels under the login it is granted — baserow runs its own, n8n in its shipped mode needs none (novox/hq issue 081) 2026-09-22 12:26:33 +02:00
jschoubben b2a48558ea Merge pull request 'redis: a consumer's ACL loses the dangerous category (issue 080)' (#36) from multiple-fixes into main 2026-09-22 02:19:14 +02:00
jschoubben c71bbd497f redis: INFO is allowed back — client libraries ask it at connect, and it reads nothing a consumer keeps 2026-09-22 02:03:23 +02:00
jschoubben 421f4d8577 redis: a consumer's ACL loses the dangerous category — a key pattern does not confine FLUSHALL (novox/hq issue 080) 2026-09-22 01:39:29 +02:00
jschoubben 54af5e8536 Merge pull request 'route-proxy: the trust gate names the binding it reads; the server names the gate (ADR 0099)' (#35) from multiple-fixes into main 2026-09-21 23:58:48 +02:00
jschoubben 6fb2003b8d route-proxy: the trust gate names the binding it reads and runs again when the authority moved; the server follows it (ADR 0099) 2026-09-21 23:25:06 +02:00
jschoubben 64d62978f6 Merge pull request 'Multiple fixes: five modules keep their secrets from the vault (ADR 0094), the authority makes its own root (076), the builder on the host network, route-proxy declares its bases' (#34) from multiple-fixes into main 2026-09-21 22:58:24 +02:00
jschoubben ac651c7ac2 route-proxy: the trust container names its artifact 2026-09-21 22:55:35 +02:00
jschoubben 1c964cd571 route-proxy: the trust gate retries with a timeout and checks for a certificate; its images are declared artifacts (ADRs 0096, 0097, 0098) 2026-09-21 22:53:29 +02:00
jschoubben 28b8feebfc The authority makes its own root at first start, and the proxy fetches it through a gate
step-ca's root certificate, its key and that key's password were own secrets — random
bytes the mesh minted, which no certificate is (novox/hq 04-ISSUES/076). The mesh
mints only the CA password now; step-ca makes its root at first start and serves it
at /roots.pem, which the manifest now names beside the ACME directory. The route
proxy fetches that root over the mesh network in a run-once step before it starts,
instead of being handed a served fact that could only be written before anything ran
(ADR 0098).
2026-09-21 22:26:28 +02:00
jschoubben 82256fcdb0 The builder runs on the machine's network: it copies images into the mesh's registry itself now
The copy between registries (ADR 0096) reaches the mesh's registry over HTTP from
inside the builder's container, where loopback on the default bridge is not the
machine; docker push never noticed because it went through the machine's daemon.
The builder already holds the runtime's socket, so the host network adds nothing
it did not have.
2026-09-21 22:24:43 +02:00
jschoubben facd41806d Five modules keep their own secrets from the vault, under local names; route-proxy declares its bases
gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs
under a local name (novox/hq ADR 0094); the broker account stays their own. The
route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
2026-09-21 22:16:10 +02:00
jschoubben 126969a829 Merge pull request 'The controller's manifest lives in the controller's repository, not here (hq issue 072)' (#33) from feat/one-controller-manifest into main 2026-09-21 19:23:18 +02:00
jschoubben a514d9827c The controller's manifest lives in the controller's repository, not here
ADR 0069 put it there; genesis now takes it from the build it runs (mesh-host,
novox/hq 04-ISSUES/072). This copy was read by nothing else and had already drifted.
2026-09-21 15:17:47 +02:00
jschoubben e0d34723f7 Merge pull request 'Six modules take their secrets from files; the rest say precisely why not (issue 041)' (#32) from feat/migration-blockers into main 2026-09-21 13:48:46 +02:00
jschoubben 1289510538 mongodb names its secrets' owner: the image drops to its own user before it reads the password file
The official entrypoint re-executes itself as mongodb (uid 999) and only then reads
MONGO_INITDB_ROOT_PASSWORD_FILE, so a root-owned 0600 file is 'Permission denied' at line 83 and
the server never starts. secrets-owner is the mechanism ADR 0086 gives for exactly this.
2026-09-21 13:43:41 +02:00
jschoubben 50b639ff52 The env-file references to files the conversion removed go with them 2026-09-21 12:43:41 +02:00
jschoubben 0b2f3bfbd3 grafana stays a declared exception until a bed exercises its admin password 2026-09-21 12:31:59 +02:00
jschoubben 1a28e5aec6 Six modules take their secrets from files; the rest say precisely why not
From the survey of every env-file secret (ADR 0086, issue 041): amqp-ping,
minio, mongodb and grafana use the _FILE twin their software honours;
mesh-catalog and model-usage read DATABASE_URL_FILE (a file the mesh
templates, mounted where only the runtime reads it); grafana's secret files
belong to its own account. Two dead deliveries removed: a line nothing read
in amqp-email-forwarder, and mailu's secret.env on four containers that
never read it. The 25 exceptions that remain carry the surveyed reason —
convertible and awaiting a bed, convertible through a generated config file,
the application's own code, or not convertible.
2026-09-21 12:29:25 +02:00
jschoubben db597bcb71 Merge pull request 'The controller reads its credentials from files; every other env-file secret says why' (#31) from feat/secret-not-in-environment into main 2026-09-21 11:59:08 +02:00
jschoubben 8647ea6671 The control plane's secret files belong to its own account (secrets-owner) 2026-09-21 10:19:00 +02:00
jschoubben 32dec5f0c2 The controller reads its credentials from files; every other env-file secret says why
ADR 0086. mesh-controller mounts its six own secrets and names them with
_FILE twins, so no credential of its own reaches its environment. The 35
containers that still read a secret through an env-file carry
secrets-in-environment with the reason; converting each where its software
accepts a path is the per-module work of issue 041.
2026-09-21 10:10:33 +02:00
jschoubben d03520f4ed Merge pull request 'Add mesh-vault; redis, postgres and lavinmq take their passwords from files' (#30) from feat/secrets-vault into main 2026-09-21 10:03:12 +02:00
jschoubben 82e513a360 Add the mesh-vault module; redis takes its password from it
mesh-vault provides `secret` (novox/hq ADR 0085, design 24). The value is
the pair credential the controller mints — the vault holds no copy, only a
ledger of who holds one, its fingerprint and every rotation, and two tools that
answer by fingerprint and never by value. Rotation is `rotate secret`,
unchanged machinery pointed at a secret with an owner (design 13). Named in the
mesh's own namespace, beside mesh-controller and mesh-catalog, because it is
the mesh's own code rather than wrapped software.

redis is the first consumer: its own password stops being an own-secret nothing
could rotate and becomes a `secret` it requires, read from the same file into
the same hole. The server now restarts on its config, or it would keep the
password it started with through every rotation (playbook 06).
2026-09-21 00:48:13 +02:00
jschoubben 8105ab6141 Merge pull request 'minio: pull image from quay.io (docker.io denies anonymous pulls)' (#29) from fix/minio-pull-from-quay into main 2026-09-20 22:03:50 +02:00
jschoubben 2ef7eb2a27 minio: pull image from quay.io (docker.io denies anonymous pulls)
Same digest, a registry that serves anonymous pulls. Unblocks raising minio in
the lab and the object-store cutover.
2026-09-20 22:01:20 +02:00
jschoubben 4ce9de6f3a Merge pull request 'Correct lavinmq Dockerfile's stale MESH_TOOL_MODULES comment (061 review)' (#28) from fix/lavinmq-dockerfile-comment into main 2026-09-20 13:42:03 +02:00
jschoubben 17243b72df Correct lavinmq Dockerfile's stale MESH_TOOL_MODULES comment (061 review)
The comment still said the provisioner is not listed and runs via a
container's args — but the 061 fix put it in MESH_TOOL_MODULES (serve
mode) and dropped the args. A future editor trusting the comment could
strip it again and silently reintroduce 061. Comment now matches the
code; only the run-once bootstrap runs via args.
2026-09-20 13:32:47 +02:00
jschoubben 43c9c973e2 Merge pull request 'The mesh builds its own catalogue (issue 060)' (#27) from feat/the-mesh-builds-its-catalogue into main 2026-09-20 12:53:04 +02:00
jschoubben 965c58fe44 Defer minio from the buildable set too (issue 060)
minio's runtime copies the `mc` client from minio/mc:latest — a
Docker Hub pull the mesh build environment cannot make (its docker
reaches the mesh registry, not public Hub), the same isolation that
blocks npm deps. apt-based installs (mongodb's mongosh, mosquitto)
build fine because the build has real internet for apt; only npm and
Docker Hub are redirected. Delivering an external binary or image layer
into a mesh build is the same open question as the npm deps — deferred
with them.
2026-09-18 02:51:09 +02:00
jschoubben b8d390cbae Defer model-usage and anthropic-manager from the buildable set (issue 060)
Both carry third-party runtime deps (pg; tweetnacl + sealedbox) that
their Dockerfile installs with npm — which 404s in a mesh build, whose
npm points at the mesh's own registry, not public npm. The workstation
build script got away with it by installing on a host with public npm.
Delivering a module's third-party deps into a mesh build is an open
question (how: publish to the mesh registry, or proxy); until it is
answered these two stay on the placeholder path they were already on.
The other 37 modules build from their own directory with no external
fetch.
2026-09-18 02:48:09 +02:00
jschoubben e362fb951c The rest of the catalogue becomes mesh-buildable (issue 060, batch 2)
The 21 media/home modules, the SaaS tool modules (cloudflare-dns,
confluence, gitlab, jira), model-usage, and the model-access trio get
the same Dockerfile + build section as batch 1. Scheduled-only modules
(anthropic-consumer, anthropic-manager, openai-consumer) deliberately
declare no MESH_TOOL_MODULES — every container of theirs names its
command. mosquitto's run-once bootstrap container builds from the same
artifact. Modules with third-party deps (model-usage: pg;
anthropic-manager: tweetnacl) install them beside their compiled code.

Also fixes cloudflare-dns's package.json, unparseable since its
description lost a closing quote.

Deliberately still without build sections: builder and mesh-controller
(the foundation builds them by its own path), distribution (provides
the artifact store — building it through itself is refused by design),
route-proxy (cross-repo build context, deferred), and the
upstream-image-only modules, which have no code to build.
2026-09-18 02:14:09 +02:00
jschoubben 591b26f712 Ten migration-critical modules become mesh-buildable (issue 060)
keycloak, mailu, minio, mongodb, mssql, nextcloud, portainer, redis,
umami and verdaccio get the Dockerfile + build section the eight
buildable modules already had; their runtime containers name the
artifact instead of a placeholder digest.

One convention, settled (060's open question, informed by 061): the
runtime container runs serve mode with every serve-time entrypoint in
MESH_TOOL_MODULES — tools serve, events flow, and a provider's
provisioner reconciles in the same process with the broker connected.
postgres, gitea and lavinmq are retrofitted from args-run provisioners,
which served no tools and emitted lifecycle events nowhere.

route-proxy is deferred: its build context is the mesh-controller
repository, a cross-repo shape the build section cannot yet express.
2026-09-18 02:02:21 +02:00
jschoubben 83a78b4fb3 Merge pull request 'Refs name the registry; lavinmq's runtime runs its provisioner (042/048/061)' (#26) from feat/refs-name-the-registry into main 2026-09-18 01:00:43 +02:00
jschoubben 1891b09c65 lavinmq's runtime container runs its provisioner
The runtime container named no command, so it ran the image default —
the tool host — and the provisioner entrypoint compiled beside it never
ran anywhere: no vhost was ever minted, while the grants sat applied in
its mounted directory. postgres already names its provisioner in args;
lavinmq now does the same. Surfaced by the built-store-cross-node bed,
run 9 — the first bed to reach the vhost assertion honestly.
2026-09-17 23:54:56 +02:00
jschoubben 2dab3069d2 The builder names the registry by the binding again (ADR 0082)
The one-line change e0c9219 parked "until there is a certificate" returns — with the
overlay recorded as the registry's transport security and every node's runtime told the
store speaks plain HTTP, a reference under the provider's internal name is one every
machine can pull. References minted at genesis stay loopback and are valid where they
matter, on the machine that made them.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 23:05:25 +02:00
jschoubben 728922a016 Merge pull request 'Foundation modules claim a mesh-scoped seat named after their server' (#25) from multi-node/foundation-seats into main 2026-09-17 02:15:59 +02:00
jschoubben fccc1e6552 The foundation modules claim a mesh-scoped seat named after their server
postgres claims mesh-store, lavinmq claims mesh-broker, and the controller's seat is
renamed the-controller -> mesh-controller so all three follow one convention. The resolver
refuses a second holder mesh-wide, so an adopted foundation module assigned to a second node
is refused rather than silently raising a second server. Closes hq issue 056 (ADR 0079).

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 02:13:26 +02:00