A routed module listens from the mesh, not from anywhere #138

Merged
mesh-admin merged 1 commits from fix/a-routed-module-listens-from-the-mesh into main 2026-09-29 00:58:39 +00:00
Contributor
No description provided.
mesh-admin added 1 commit 2026-09-29 00:54:12 +00:00
umami declared its port reachable from anywhere, reasoning that the collection
endpoint tracked browsers POST to must be public. That is true of the name and
not of the port: both its surfaces are served through the proxy by name, so the
port is how the proxy reaches it and nothing else (ADR 0045).

Measured, which is how this was found: with the port open to the internet, the
dashboard's login page was served over plain HTTP directly on the machine's port,
bypassing every rule the proxy applies by path. The route stays exactly as it was,
so the collection endpoint keeps working.
mesh-admin merged commit 822df220ab into main 2026-09-29 00:58:39 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#138