Compare commits
32
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ac8556c590 | ||
|
|
8064e5da8f | ||
|
|
63a255c5cb | ||
|
|
7ad1fbd5c6 | ||
|
|
67f5f4cffd | ||
|
|
8797335fbc | ||
|
|
53dc108603 | ||
|
|
ebf5ba2d4c | ||
|
|
bbac08a7d2 | ||
|
|
784a5a6514 | ||
|
|
0c31499fb0 | ||
|
|
f118344246 | ||
|
|
822df220ab | ||
|
|
9eb1265bc8 | ||
|
|
41cfc70b53 | ||
|
|
acedc5d9d9 | ||
|
|
521a8dd1e2 | ||
|
|
e145e2236c | ||
|
|
4d7e37e319 | ||
|
|
026421fd6e | ||
|
|
af89bb11ff | ||
|
|
7c18cdbd39 | ||
|
|
4fb16b2e6b | ||
|
|
c5af8635c8 | ||
|
|
87366c5f36 | ||
|
|
f8ca36aacf | ||
|
|
812355bf31 | ||
|
|
016ddb2b3a | ||
|
|
ea17bf46d2 | ||
|
|
4258f01614 | ||
|
|
4d9b4fdfa6 | ||
|
|
eff11b1d4d |
+55
-24
@@ -2,12 +2,15 @@
|
|||||||
// module's tools and anything else baserow-specific import it; nothing outside baserow does.
|
// module's tools and anything else baserow-specific import it; nothing outside baserow does.
|
||||||
//
|
//
|
||||||
// Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/.
|
// Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/.
|
||||||
// Those credentials are the mesh's own: a person signs up in Baserow (the standard image creates no
|
// The standard image creates no admin from env, so the account is one a person made in Baserow: its
|
||||||
// admin from env), and the credential is placed in the runtime config file the mesh mounts. Until
|
// password is the module's `admin` secret, accepted from the operator, and its email and the public
|
||||||
// that happens fromEnv throws and the module simply exposes no tools — the same dormant-until-
|
// host Baserow answers to reach the runtime config file the mesh mounts (the email from the
|
||||||
// configured shape gitea uses for its token.
|
// assignment's settings). Until both are there fromEnv throws and the module exposes no tools — the
|
||||||
|
// same dormant-until-configured shape gitea uses for its token.
|
||||||
|
|
||||||
import { readFileSync } from "node:fs";
|
import { readFileSync } from "node:fs";
|
||||||
|
import { request as httpRequest } from "node:http";
|
||||||
|
import { request as httpsRequest } from "node:https";
|
||||||
|
|
||||||
export interface BaserowApplication {
|
export interface BaserowApplication {
|
||||||
id: number;
|
id: number;
|
||||||
@@ -68,35 +71,63 @@ export class BaserowClient {
|
|||||||
return h;
|
return h;
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Exchange email + password for a JWT, caching it for the client's lifetime. Handles both the
|
/**
|
||||||
|
* One HTTP exchange. Not `fetch`: Node's fetch drops a caller's Host header and sends the URL's
|
||||||
|
* own, and Baserow answers only the host of its BASEROW_PUBLIC_URL — any other Host is looked up
|
||||||
|
* as a published builder site and gets 404, `/api/_health/` included. A co-located caller reaching
|
||||||
|
* it by container name must present the public host, so the request is made with node:http, which
|
||||||
|
* sends the Host it is given.
|
||||||
|
*/
|
||||||
|
private send(path: string, method: string, headers: Record<string, string>, body?: string): Promise<{ status: number; text: string }> {
|
||||||
|
const url = new URL(`${this.baseUrl}${path}`);
|
||||||
|
const request = url.protocol === "https:" ? httpsRequest : httpRequest;
|
||||||
|
// A length, never chunked: Baserow's server reads a chunked body as empty.
|
||||||
|
const sent = body === undefined ? headers : { ...headers, "Content-Length": String(Buffer.byteLength(body)) };
|
||||||
|
return new Promise((resolve, reject) => {
|
||||||
|
const req = request(url, { method, headers: sent }, (res) => {
|
||||||
|
let text = "";
|
||||||
|
res.setEncoding("utf8");
|
||||||
|
res.on("data", (chunk: string) => (text += chunk));
|
||||||
|
res.on("end", () => resolve({ status: res.statusCode ?? 0, text }));
|
||||||
|
res.on("error", reject);
|
||||||
|
});
|
||||||
|
req.on("error", reject);
|
||||||
|
if (body !== undefined) req.write(body);
|
||||||
|
req.end();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Exchange email + password for a JWT, caching it until Baserow refuses it. Handles both the
|
||||||
* older `{ token }` and the newer `{ access_token }` response shapes. */
|
* older `{ token }` and the newer `{ access_token }` response shapes. */
|
||||||
async authenticate(): Promise<string> {
|
async authenticate(): Promise<string> {
|
||||||
if (this.token) return this.token;
|
if (this.token) return this.token;
|
||||||
const res = await fetch(`${this.baseUrl}/api/user/token-auth/`, {
|
const res = await this.send(
|
||||||
method: "POST",
|
"/api/user/token-auth/",
|
||||||
headers: this.headers(),
|
"POST",
|
||||||
body: JSON.stringify({ email: this.email, password: this.password }),
|
this.headers(),
|
||||||
});
|
JSON.stringify({ email: this.email, password: this.password }),
|
||||||
if (!res.ok) throw new Error(`baserow auth failed: ${res.status} ${await res.text()}`);
|
);
|
||||||
const data = (await res.json()) as { token?: string; access_token?: string };
|
if (res.status < 200 || res.status >= 300) throw new Error(`baserow auth failed: ${res.status} ${res.text}`);
|
||||||
|
const data = JSON.parse(res.text) as { token?: string; access_token?: string };
|
||||||
const token = data.access_token ?? data.token;
|
const token = data.access_token ?? data.token;
|
||||||
if (!token) throw new Error("baserow auth returned no token");
|
if (!token) throw new Error("baserow auth returned no token");
|
||||||
this.token = token;
|
this.token = token;
|
||||||
return token;
|
return token;
|
||||||
}
|
}
|
||||||
|
|
||||||
private async authed<T>(path: string, options: RequestInit = {}): Promise<T> {
|
/** An authenticated GET. A refused token is dropped and the call made once more with a fresh one:
|
||||||
const token = await this.authenticate();
|
* Baserow's access tokens expire after minutes, and the runtime lives for weeks. */
|
||||||
const res = await fetch(`${this.baseUrl}${path}`, {
|
private async authed<T>(path: string): Promise<T> {
|
||||||
...options,
|
for (let attempt = 0; ; attempt++) {
|
||||||
headers: this.headers({
|
const token = await this.authenticate();
|
||||||
Authorization: `JWT ${token}`,
|
const res = await this.send(path, "GET", this.headers({ Authorization: `JWT ${token}` }));
|
||||||
...(options.headers as Record<string, string> | undefined),
|
if (res.status === 401 && attempt === 0) {
|
||||||
}),
|
this.token = null;
|
||||||
});
|
continue;
|
||||||
if (!res.ok) throw new Error(`baserow ${path}: ${res.status} ${await res.text()}`);
|
}
|
||||||
const text = await res.text();
|
if (res.status < 200 || res.status >= 300) throw new Error(`baserow ${path}: ${res.status} ${res.text}`);
|
||||||
return (text ? JSON.parse(text) : null) as T;
|
return (res.text ? JSON.parse(res.text) : null) as T;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/** The applications (databases) the account can see, across all its workspaces. */
|
/** The applications (databases) the account can see, across all its workspaces. */
|
||||||
|
|||||||
+17
-17
@@ -14,26 +14,27 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "baserow",
|
"label": "baserow",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
"postgres-database": "/var/lib/baserow/database.json",
|
"postgres-database": "${dir:state}/database.json",
|
||||||
"route": "/var/lib/baserow/route.json"
|
"route": "${dir:state}/route.json"
|
||||||
},
|
},
|
||||||
"secrets": {
|
"secrets": {
|
||||||
"postgres-database": "/var/lib/baserow/database.secret"
|
"postgres-database": "${dir:state}/database.secret"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"secret-key": "/var/lib/baserow/secret-key.secret",
|
"admin": "${dir:state}/admin.secret",
|
||||||
"broker": "/var/lib/mesh/baserow/broker"
|
"broker": "/var/lib/mesh/baserow/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the Baserow web UI and REST API; a public name is a route grant later"
|
"why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
@@ -46,22 +47,21 @@
|
|||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/baserow",
|
"mode": "0700",
|
||||||
"mode": "0700"
|
"place": "."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "data",
|
"id": "data",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/services/baserow/data",
|
|
||||||
"mode": "0755",
|
"mode": "0755",
|
||||||
"owner": "9999:9999"
|
"owner": "9999:9999"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "server-env",
|
"id": "server-env",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/baserow/server.env",
|
"path": "${dir:state}/server.env",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n"
|
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "net",
|
"id": "net",
|
||||||
@@ -72,25 +72,25 @@
|
|||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "baserow",
|
"name": "baserow",
|
||||||
"image": "baserow/baserow@sha256:834424a10413798567f76428f255dc259445b7f8dcec56598c05b4073bb2a124",
|
"image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080",
|
||||||
"network": "baserow",
|
"network": "baserow",
|
||||||
"env-file": [
|
"env-file": [
|
||||||
"/var/lib/baserow/server.env"
|
"${dir:state}/server.env"
|
||||||
],
|
],
|
||||||
"ports": [
|
"ports": [
|
||||||
"80"
|
"80"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/services/baserow/data:/baserow/data"
|
"${dir:data}:/baserow/data",
|
||||||
],
|
"${dir:state}/database.secret:/run/secrets/database:ro"
|
||||||
"secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible"
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime-config",
|
"id": "runtime-config",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/baserow/config.json",
|
"path": "/var/lib/mesh/baserow/config.json",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 6767,
|
"port": 6767,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -110,7 +111,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "subs",
|
"label": "subs",
|
||||||
"port": 6767
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -15,6 +15,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8787,
|
"port": 8787,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -87,7 +88,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "books",
|
"label": "books",
|
||||||
"port": 8787
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
{
|
||||||
|
"module": "ca-trust",
|
||||||
|
"version": "1",
|
||||||
|
"slug": "catrust",
|
||||||
|
"capabilities": [
|
||||||
|
"service-manager"
|
||||||
|
],
|
||||||
|
"requires": [
|
||||||
|
"internal-acme-ca"
|
||||||
|
],
|
||||||
|
"seats": [
|
||||||
|
{
|
||||||
|
"name": "the-mesh-trust-anchor",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "the-mesh-trust-anchor",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"resources": [
|
||||||
|
{
|
||||||
|
"id": "state",
|
||||||
|
"type": "directory",
|
||||||
|
"mode": "0700",
|
||||||
|
"place": "."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "anchor",
|
||||||
|
"type": "file",
|
||||||
|
"path": "${dir:state}/anchor",
|
||||||
|
"mode": "0755",
|
||||||
|
"content": "#!/bin/sh\n# The mesh's internal certificate authority, trusted by this machine.\n#\n# Written by the mesh from the ca-trust module's manifest (novox/hq ADR 0147).\n# Editing it here lasts until the next apply.\n#\n# There is no prior trust to verify the fetch against \u2014 this is the thing that\n# establishes it \u2014 so it is made over the mesh's own private network, which is\n# what authenticates it (novox/hq ADR 0098, the same reasoning that lets the\n# route proxy fetch this root for itself). What comes back is checked here: a\n# body that is not a certificate is refused now, rather than believed and then\n# failed by whatever reads the trust store next.\nset -eu\n\nROOTS='https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}'\nANCHORS=/etc/ca-certificates/trust-source/anchors\nANCHOR=\"$ANCHORS/mesh-internal-ca.crt\"\n\n# Arch's layout, said out loud rather than assumed: a machine that keeps its\n# anchors elsewhere fails here, visibly, instead of writing a file nothing\n# reads. That failure is the signal that this belongs in the host, where one\n# operating system's difference lives (novox/hq ADR 0147, option 2).\n[ -d \"$ANCHORS\" ] || {\n\techo \"this machine keeps no trust anchors in $ANCHORS; ca-trust is written for that layout\" >&2\n\texit 1\n}\n\ncase \"${1:-}\" in\ninstall)\n\ttmp=$(mktemp)\n\ttrap 'rm -f \"$tmp\"' EXIT\n\t# The authority may still be starting, or this machine may have come up\n\t# before it: two minutes of asking, then an honest failure.\n\tn=0\n\twhile [ \"$n\" -lt 60 ]; do\n\t\tif curl --fail --silent --show-error --insecure --max-time 10 \\\n\t\t\t--output \"$tmp\" \"$ROOTS\" &&\n\t\t\tgrep -q 'BEGIN CERTIFICATE' \"$tmp\"; then\n\t\t\tinstall -m 0644 \"$tmp\" \"$ANCHOR\"\n\t\t\tupdate-ca-trust\n\t\t\texit 0\n\t\tfi\n\t\tn=$((n + 1))\n\t\tsleep 2\n\tdone\n\techo \"the authority at $ROOTS did not serve a certificate within two minutes\" >&2\n\texit 1\n\t;;\nremove)\n\t# What stopping the unit does, and therefore what being unassigned does.\n\trm -f \"$ANCHOR\"\n\tupdate-ca-trust\n\t;;\n*)\n\techo \"usage: $(basename \"$0\") install|remove\" >&2\n\texit 2\n\t;;\nesac\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "unit",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/system/mesh-ca-trust.service",
|
||||||
|
"mode": "0644",
|
||||||
|
"content": "[Unit]\nDescription=The mesh's internal certificate authority, trusted by this machine\n# novox/hq ADR 0147. Starting this unit places the mesh's root among this\n# machine's trust anchors; stopping it takes the root away again, which is what\n# the host does when the module is no longer assigned here.\nWants=network-online.target\nAfter=network-online.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=${dir:state}/anchor install\nExecStop=${dir:state}/anchor remove\n\n[Install]\nWantedBy=multi-user.target\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "trust",
|
||||||
|
"type": "service",
|
||||||
|
"unit": "mesh-ca-trust.service",
|
||||||
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
|
"restart-on": [
|
||||||
|
"anchor",
|
||||||
|
"unit"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "de-spiegel",
|
"label": "de-spiegel",
|
||||||
"port": 35621
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -23,6 +23,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 35621,
|
"port": 35621,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -29,6 +29,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "registry",
|
||||||
"port": 5000,
|
"port": 5000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -22,11 +22,20 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "dns-udp",
|
||||||
"port": 53,
|
"port": 53,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "every name for this machine and what it runs \u2014 the mesh's own answered here, the rest forwarded",
|
"why": "every name for this machine and what it runs \u2014 the mesh's own answered here, the rest forwarded",
|
||||||
"fixed": true
|
"fixed": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "dns-tcp",
|
||||||
|
"port": 53,
|
||||||
|
"protocol": "tcp",
|
||||||
|
"from": "mesh",
|
||||||
|
"why": "the same names over tcp, which a resolver answers on as well and is asked for whenever an answer will not fit in a datagram. Declared because the daemon serves it: a declaration that covers one of the two protocols its own service listens on leaves the other closed while everything reports success",
|
||||||
|
"fixed": true
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -33,7 +33,7 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/etc/fail2ban/jail.local",
|
"path": "/etc/fail2ban/jail.local",
|
||||||
"mode": "0644",
|
"mode": "0644",
|
||||||
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\n# Ban through iptables, not through a firewall front-end the machine may not have. ufw is\n# installed on two of this mesh's machines and absent on the other two, and fail2ban finds out\n# only at ban time: the service reports healthy, the jail counts the attempt, the ban command\n# exits 127, and nothing is blocked. Proven on 2026-09-28 -- 'ufw: command not found' on a\n# machine the mesh reported as protected.\n#\n# The action below is this module's own, already used by the recidive jail on every machine\n# here, and it bans in DOCKER-USER as well as INPUT, so a container's published port is\n# covered too.\nbanaction = iptables-allports-dualchain\nbanaction_allports = iptables-allports-dualchain\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "jail-sshd",
|
"id": "jail-sshd",
|
||||||
@@ -42,6 +42,14 @@
|
|||||||
"mode": "0644",
|
"mode": "0644",
|
||||||
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "log",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/var/log/fail2ban.log",
|
||||||
|
"mode": "0640",
|
||||||
|
"create-once": true,
|
||||||
|
"content": ""
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "jail-recidive",
|
"id": "jail-recidive",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"web": {
|
"web": {
|
||||||
"label": "git",
|
"label": "git",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
},
|
},
|
||||||
"internal-api-refused": {
|
"internal-api-refused": {
|
||||||
"label": "git",
|
"label": "git",
|
||||||
@@ -44,12 +44,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the forge, over http"
|
"why": "the forge, over http"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "ssh",
|
||||||
"port": 22,
|
"port": 22,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -96,7 +97,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "grafana",
|
"label": "grafana",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "hello",
|
"label": "hello",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8123,
|
"port": 8123,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -85,7 +86,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "home-assistant",
|
"label": "home-assistant",
|
||||||
"port": 8123
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "stream",
|
||||||
"port": 8000,
|
"port": 8000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 8086,
|
"port": 8086,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -17,11 +17,11 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"site": {
|
"site": {
|
||||||
"label": "invoicing",
|
"label": "invoicing",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
},
|
},
|
||||||
"api": {
|
"api": {
|
||||||
"label": "invoicing-api",
|
"label": "invoicing-api",
|
||||||
"port": 9000
|
"endpoint": "api"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -36,12 +36,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the invoicing web frontend; a public name is a route grant later"
|
"why": "the invoicing web frontend; a public name is a route grant later"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9117,
|
"port": 9117,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -82,7 +83,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "indexers",
|
"label": "indexers",
|
||||||
"port": 9117
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "keycloak",
|
"label": "keycloak",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -34,6 +34,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -24,6 +24,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8283,
|
"port": 8283,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8686,
|
"port": 8686,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -86,7 +87,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "lidarr",
|
"label": "lidarr",
|
||||||
"port": 8686
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -16,27 +16,27 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"web": {
|
"web": {
|
||||||
"label": "mail",
|
"label": "mail",
|
||||||
"port": 7443,
|
"endpoint": "web-tls",
|
||||||
"scheme": "https",
|
"scheme": "https",
|
||||||
"insecure": true
|
"insecure": true
|
||||||
},
|
},
|
||||||
"acme": {
|
"acme": {
|
||||||
"label": "mail",
|
"label": "mail",
|
||||||
"path": "/.well-known/acme-challenge",
|
"path": "/.well-known/acme-challenge",
|
||||||
"port": 7080,
|
"endpoint": "web",
|
||||||
"priority": 100
|
"priority": 100
|
||||||
},
|
},
|
||||||
"autoconfig": {
|
"autoconfig": {
|
||||||
"label": "autoconfig",
|
"label": "autoconfig",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
},
|
},
|
||||||
"autodiscover": {
|
"autodiscover": {
|
||||||
"label": "autodiscover",
|
"label": "autodiscover",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
},
|
},
|
||||||
"automx": {
|
"automx": {
|
||||||
"label": "automx",
|
"label": "automx",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -60,6 +60,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "smtp",
|
||||||
"port": 25,
|
"port": 25,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -67,6 +68,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "pop3",
|
||||||
"port": 110,
|
"port": 110,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -74,6 +76,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "imap",
|
||||||
"port": 143,
|
"port": 143,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -81,6 +84,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "smtps",
|
||||||
"port": 465,
|
"port": 465,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -88,6 +92,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "submission",
|
||||||
"port": 587,
|
"port": 587,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -95,6 +100,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "imaps",
|
||||||
"port": 993,
|
"port": 993,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -102,6 +108,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "pop3s",
|
||||||
"port": 995,
|
"port": 995,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -109,18 +116,21 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 7080,
|
"port": 7080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
|
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web-tls",
|
||||||
"port": 7443,
|
"port": 7443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
|
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "autoconfig",
|
||||||
"port": 4243,
|
"port": 4243,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 59125,
|
"port": 59125,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ COPY . .
|
|||||||
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
||||||
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
||||||
# was assembled.
|
# was assembled.
|
||||||
RUN node /app/node_modules/typescript/bin/tsc pg.d.ts store.ts index.ts tools/index.ts \
|
RUN node /app/node_modules/typescript/bin/tsc pg.d.ts store.ts index.ts tools/index.ts prepare/index.ts \
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||||
|
|
||||||
# **A module may need something the base image does not carry.** The base holds what every module
|
# **A module may need something the base image does not carry.** The base holds what every module
|
||||||
@@ -48,3 +48,8 @@ COPY --from=build /deps/node_modules /app/modules/mesh-catalog/node_modules
|
|||||||
# to listen for what the builder announces. Serve binds the broker first, then imports these, so
|
# to listen for what the builder announces. Serve binds the broker first, then imports these, so
|
||||||
# `on()` has something to subscribe to.
|
# `on()` has something to subscribe to.
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/mesh-catalog/dist/index.js,/app/modules/mesh-catalog/dist/tools/index.js
|
ENV MESH_TOOL_MODULES=/app/modules/mesh-catalog/dist/index.js,/app/modules/mesh-catalog/dist/tools/index.js
|
||||||
|
|
||||||
|
# And what prepares this module's state, for the runtime's `prepare` mode (novox/hq ADR 0135). Named
|
||||||
|
# here, beside the entrypoints above, because the module knows which of its files prepares its state
|
||||||
|
# and nothing else could: the mesh asks one word and this says what answers it.
|
||||||
|
ENV MESH_PREPARE=/app/modules/mesh-catalog/dist/prepare/index.js
|
||||||
|
|||||||
@@ -14,10 +14,12 @@ import { Graph, type Made } from "./store.js";
|
|||||||
|
|
||||||
const graph = Graph.fromEnv();
|
const graph = Graph.fromEnv();
|
||||||
|
|
||||||
// Before subscribing, and idempotent. The runtime is restarted until its store is reachable, which
|
// The schema is not brought up here. The mesh prepares this module's state before it starts this
|
||||||
// is the same arrangement model-usage uses: a schema step that had to reach the provider over the
|
// version, and does not start it if that failed (novox/hq ADR 0135) — see prepare/index.ts. Doing it
|
||||||
// overlay would block the very apply that brings the overlay up.
|
// at start made a schema that could not be reached a crash loop instead of a stop, with the graph
|
||||||
await graph.migrate();
|
// keeping a gap and nothing saying so. The reason it used to be here — that a step blocking the apply
|
||||||
|
// would block the very apply that brings the overlay up — stopped being true when a step's failure
|
||||||
|
// became this module's business and not the machine's (ADR 0136).
|
||||||
|
|
||||||
/** What the builder says when it has built something. */
|
/** What the builder says when it has built something. */
|
||||||
interface Built {
|
interface Built {
|
||||||
@@ -47,7 +49,15 @@ interface Built {
|
|||||||
replay?: boolean;
|
replay?: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
await on("mesh-build-machine.built", async (event) => {
|
/**
|
||||||
|
* What a build means for the graph, wherever it came from.
|
||||||
|
*
|
||||||
|
* Two emitters say the same thing and neither is a mistake: the build machine says it as it happens,
|
||||||
|
* and the control plane says what it already held when this module asks what it missed
|
||||||
|
* (novox/hq ADR 0134). A replay is marked as one in its body, so nothing acts on a module that moved
|
||||||
|
* months ago — see `replay` above.
|
||||||
|
*/
|
||||||
|
const placeTheBuild = async (event: { body: unknown }): Promise<void> => {
|
||||||
const body = event.body as Built;
|
const body = event.body as Built;
|
||||||
if (!body.module || !body.commit) {
|
if (!body.module || !body.commit) {
|
||||||
// Said rather than dropped: a build that announced itself without saying what it built is a
|
// Said rather than dropped: a build that announced itself without saying what it built is a
|
||||||
@@ -89,7 +99,11 @@ await on("mesh-build-machine.built", async (event) => {
|
|||||||
because: next.because,
|
because: next.because,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
});
|
};
|
||||||
|
|
||||||
|
// As it happens, and what the mesh already held when this module asked what it missed.
|
||||||
|
await on("mesh-build-machine.built", placeTheBuild);
|
||||||
|
await on("mesh-controller.built-before", placeTheBuild);
|
||||||
|
|
||||||
// **And ask for what was built before this catalogue existed** (novox/hq 04-ISSUES/050).
|
// **And ask for what was built before this catalogue existed** (novox/hq 04-ISSUES/050).
|
||||||
//
|
//
|
||||||
|
|||||||
@@ -29,13 +29,16 @@
|
|||||||
"broker": "/var/lib/mesh/mesh-catalog/broker"
|
"broker": "/var/lib/mesh/mesh-catalog/broker"
|
||||||
},
|
},
|
||||||
"consumes": [
|
"consumes": [
|
||||||
"mesh-build-machine.built"
|
"mesh-build-machine.built",
|
||||||
|
"mesh-controller.built-before"
|
||||||
],
|
],
|
||||||
"emits": [
|
"emits": [
|
||||||
"registered",
|
"registered",
|
||||||
"upgraded",
|
"upgraded",
|
||||||
"rebuild-needed"
|
"rebuild-needed",
|
||||||
|
"catching-up"
|
||||||
],
|
],
|
||||||
|
"prepares": true,
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
"id": "mesh-state",
|
"id": "mesh-state",
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
// The catalogue's state, brought to the shape this version needs (novox/hq ADR 0135).
|
||||||
|
//
|
||||||
|
// **The mesh runs this before the version that needs it, and does not start that version if it
|
||||||
|
// fails** — and the refusal reaches this module and nothing else on the machine
|
||||||
|
// (novox/hq ADR 0136). That is the whole difference from where this used to happen: at start, inside
|
||||||
|
// the runtime, a schema that could not be brought up was a crash loop, the graph kept a gap, and
|
||||||
|
// nothing anywhere said so.
|
||||||
|
//
|
||||||
|
// Nothing here connects to the broker. Preparation runs before the version that would use it, so
|
||||||
|
// there is nothing yet to talk to; the runtime's `prepare` mode imports this and awaits it, and this
|
||||||
|
// process exiting non-zero is how the host knows not to start the runtime.
|
||||||
|
import { Graph } from "../store.js";
|
||||||
|
|
||||||
|
const graph = Graph.fromEnv();
|
||||||
|
await graph.migrate();
|
||||||
|
console.log("[mesh-catalog] the module graph's schema is what this version needs");
|
||||||
|
await graph.close();
|
||||||
@@ -12,6 +12,7 @@
|
|||||||
"pg.d.ts",
|
"pg.d.ts",
|
||||||
"store.ts",
|
"store.ts",
|
||||||
"index.ts",
|
"index.ts",
|
||||||
"tools/index.ts"
|
"tools/index.ts",
|
||||||
|
"prepare/index.ts"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,11 +14,11 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"api": {
|
"api": {
|
||||||
"label": "files-api",
|
"label": "files-api",
|
||||||
"port": 9000
|
"endpoint": "s3"
|
||||||
},
|
},
|
||||||
"console": {
|
"console": {
|
||||||
"label": "files",
|
"label": "files",
|
||||||
"port": 9001
|
"endpoint": "console"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -31,12 +31,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "s3",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the S3 endpoint"
|
"why": "the S3 endpoint"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "console",
|
||||||
"port": 9001,
|
"port": 9001,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 27017,
|
"port": 27017,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -34,12 +34,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "mqtt",
|
||||||
"port": 1883,
|
"port": 1883,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "modules on any machine that were granted a topic namespace"
|
"why": "modules on any machine that were granted a topic namespace"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "mqtt-websockets",
|
||||||
"port": 8081,
|
"port": 8081,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 4848,
|
"port": 4848,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "n8n",
|
"label": "n8n",
|
||||||
"port": 5682
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -29,6 +29,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 5682,
|
"port": 5682,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
"consumes": [],
|
"consumes": [],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "bus",
|
||||||
"port": 4222,
|
"port": 4222,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "drive",
|
"label": "drive",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -38,6 +38,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 1880,
|
"port": 1880,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -81,7 +82,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "nodered",
|
"label": "nodered",
|
||||||
"port": 1880
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "@",
|
"label": "@",
|
||||||
"port": 4000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -18,6 +18,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4000,
|
"port": 4000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -15,6 +15,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 6789,
|
"port": 6789,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 11434,
|
"port": 11434,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "machine",
|
"from": "machine",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3579,
|
"port": 3579,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -89,7 +90,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "ombi",
|
"label": "ombi",
|
||||||
"port": 3579
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "office",
|
"label": "office",
|
||||||
"port": 9070
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -22,6 +22,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9070,
|
"port": 9070,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "eef",
|
"label": "eef",
|
||||||
"port": 4012
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4012,
|
"port": 4012,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "filip",
|
"label": "filip",
|
||||||
"port": 4013
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4013,
|
"port": 4013,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -18,7 +18,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "photos",
|
"label": "photos",
|
||||||
"port": 4001
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -32,12 +32,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the photos backend API; the client sites on the module network call it"
|
"why": "the photos backend API; the client sites on the module network call it"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4001,
|
"port": 4001,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -18,6 +18,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "stream",
|
||||||
"port": 32400,
|
"port": 32400,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -7,12 +7,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9090,
|
"port": 9090,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web-tls",
|
||||||
"port": 9443,
|
"port": 9443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -103,7 +105,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "portainer",
|
"label": "portainer",
|
||||||
"port": 9090
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -26,6 +26,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 5432,
|
"port": 5432,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -16,6 +16,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 7878,
|
"port": 7878,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -86,7 +87,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "movies",
|
"label": "movies",
|
||||||
"port": 7878
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -40,6 +40,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "cache",
|
||||||
"port": 6379,
|
"port": 6379,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -27,12 +27,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "http",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "https",
|
||||||
"port": 443,
|
"port": 443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
|
|||||||
+23
-21
@@ -5,11 +5,12 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"secret": "/var/lib/searxng-module/secret.secret",
|
"secret": "/var/lib/mesh/searxng/secret",
|
||||||
"broker": "/var/lib/mesh/searxng/broker"
|
"broker": "/var/lib/mesh/searxng/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -26,22 +27,14 @@
|
|||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module",
|
"mode": "0700",
|
||||||
"mode": "0700"
|
"place": "."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "valkey-data",
|
"id": "valkey-data",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module/valkey-data",
|
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "server-env",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/searxng-module/server.env",
|
|
||||||
"mode": "0600",
|
|
||||||
"content": "SEARXNG_SECRET=${secret:secret}\nSEARXNG_VALKEY_URL=valkey://valkey:6379/0\n"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "net",
|
"id": "net",
|
||||||
"type": "network",
|
"type": "network",
|
||||||
@@ -62,30 +55,39 @@
|
|||||||
"warning"
|
"warning"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/searxng-module/valkey-data:/data"
|
"${dir:valkey-data}:/data"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "settings",
|
||||||
|
"type": "file",
|
||||||
|
"path": "${dir:state}/settings.yml",
|
||||||
|
"mode": "0600",
|
||||||
|
"merge": "json",
|
||||||
|
"content": "{\n \"use_default_settings\": true,\n \"server\": {\n \"secret_key\": \"${secret:secret}\",\n \"base_url\": false,\n \"limiter\": false,\n \"image_proxy\": false,\n \"public_instance\": false\n },\n \"search\": {\n \"formats\": [\"html\", \"json\"]\n },\n \"valkey\": {\n \"url\": \"valkey://valkey:6379/0\"\n }\n}\n"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "searxng",
|
"name": "searxng",
|
||||||
"image": "searxng/searxng@sha256:c7cc75852051bf6254afda6ed1b920dd1677d8efe4ab141bf558f02e582f4371",
|
"image": "searxng/searxng@sha256:cd8812607ab73730a0b1a0dc4990223fe1b9e383f6f35947114d0bef7f8bb441",
|
||||||
"network": "searxng",
|
"network": "searxng",
|
||||||
"env-file": [
|
|
||||||
"/var/lib/searxng-module/server.env"
|
|
||||||
],
|
|
||||||
"ports": [
|
"ports": [
|
||||||
"8080"
|
"8080"
|
||||||
],
|
],
|
||||||
"secrets-in-environment": "SEARXNG_SECRET is env-only, but settings.yml carries server.secret_key; convertible by mounting a generated settings.yml, not yet done"
|
"volumes": [
|
||||||
|
"${dir:state}/settings.yml:/etc/searxng/settings.yml:ro"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"settings"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime-config",
|
"id": "runtime-config",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/searxng/config.json",
|
"path": "/var/lib/mesh/searxng/config.json",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n"
|
||||||
"merge": "json"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "runtime",
|
||||||
@@ -113,11 +115,11 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "searxng",
|
"label": "searxng",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
"route": "/var/lib/searxng-module/route.json"
|
"route": "${dir:state}/route.json"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
"on": [
|
||||||
|
|||||||
@@ -43,6 +43,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8989,
|
"port": 8989,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -91,7 +92,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "series",
|
"label": "series",
|
||||||
"port": 8989
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -7,6 +7,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "ssh",
|
||||||
"port": 22,
|
"port": 22,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -31,6 +32,7 @@
|
|||||||
"type": "service",
|
"type": "service",
|
||||||
"unit": "sshd.service",
|
"unit": "sshd.service",
|
||||||
"state": "running",
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
"config"
|
"config"
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -26,6 +26,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "acme",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8181,
|
"port": 8181,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -85,7 +86,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "tautulli",
|
"label": "tautulli",
|
||||||
"port": 8181
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "umami",
|
"label": "umami",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -49,10 +49,11 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "mesh",
|
||||||
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to \u2014 so the port itself must be reachable from anywhere"
|
"why": "one port serves two surfaces \u2014 the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -6,54 +6,63 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8443,
|
"port": 8443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
|
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "inform",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "device inform \u2014 how APs and switches check in and are adopted"
|
"why": "device inform \u2014 how APs and switches check in and are adopted"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "stun",
|
||||||
"port": 3478,
|
"port": 3478,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "STUN, so managed devices can find the controller through NAT"
|
"why": "STUN, so managed devices can find the controller through NAT"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "discovery",
|
||||||
"port": 10001,
|
"port": 10001,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
|
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "discovery-l2",
|
||||||
"port": 1902,
|
"port": 1902,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
|
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "portal-tls",
|
||||||
"port": 8843,
|
"port": 8843,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the guest captive portal over https"
|
"why": "the guest captive portal over https"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "portal",
|
||||||
"port": 8880,
|
"port": 8880,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the guest captive portal over http"
|
"why": "the guest captive portal over http"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "speedtest",
|
||||||
"port": 6789,
|
"port": 6789,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "mobile-app speed-test throughput measurement"
|
"why": "mobile-app speed-test throughput measurement"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "syslog",
|
||||||
"port": 5514,
|
"port": 5514,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
Reference in New Issue
Block a user