route-proxy: the native ingress module (drop traefik) #14

Merged
jschoubben merged 2 commits from feat/route-proxy-module into main 2026-09-06 13:17:22 +00:00
Owner

Productionizes the reference reverse-proxy (mesh-control/examples/route-proxy) into a shipping catalog module — the traefik replacement, per the decided connectivity design (ADR 0007/0044/0045).

  • route-proxy — provides: route; listens 80/443 from: anywhere (the firewall opens them for free); reads the mesh-written contributions file (receives: route) and routes by Host header over the overlay to each consumer's at; terminates public TLS via ACME (LE staging default — ISSUE 004's production-default defect stays closed; a public-facing node overrides ACME_DIRECTORY to production). Ships the Go proxy via a cross-repo Dockerfile (context = mesh-control, compiles the example — the example stays the single source of truth).
  • hello-web — a tiny demo consumer: requires: route, contributes {name, port}, listens {from: mesh} (only the proxy reaches it), slug to fit the 20-char identity bound.

Lab-proven: route-forwarding (mesh-lab) — a public name routes through the proxy to the consumer and withdraws on unassign; public-ACME TLS is proven by the existing certificates.test.ts.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Productionizes the reference reverse-proxy (`mesh-control/examples/route-proxy`) into a shipping catalog module — the traefik replacement, per the decided connectivity design (ADR 0007/0044/0045). - **`route-proxy`** — `provides: route`; listens 80/443 `from: anywhere` (the firewall opens them for free); reads the mesh-written contributions file (`receives: route`) and routes by Host header over the overlay to each consumer's `at`; terminates public TLS via ACME (LE **staging** default — ISSUE 004's production-default defect stays closed; a public-facing node overrides `ACME_DIRECTORY` to production). Ships the Go proxy via a cross-repo Dockerfile (context = mesh-control, compiles the example — the example stays the single source of truth). - **`hello-web`** — a tiny demo consumer: `requires: route`, contributes `{name, port}`, `listens {from: mesh}` (only the proxy reaches it), `slug` to fit the 20-char identity bound. Lab-proven: `route-forwarding` (mesh-lab) — a public name routes through the proxy to the consumer and **withdraws on unassign**; public-ACME TLS is proven by the existing `certificates.test.ts`. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 2 commits 2026-09-06 13:17:11 +00:00
route-proxy is the shipping form of the reference reverse proxy (novox/hq
ADR 0007, 08-connectivity section 3): it provides route, is given every
consumer as the file at receives.route, and forwards by the Host header. It
ships the Go proxy from mesh-control/examples/route-proxy via a multi-stage
Dockerfile; no broker, own-secret or provisioner, since it only reads the file
the mesh writes.

ACME_DIRECTORY defaults to Let's Encrypt staging and is overridable per node to
production, so there is no hardcoded production default -- resolving novox/hq
04-ISSUES/004. hello-web is a minimal consumer that requires route and
contributes name+port, to exercise the grant.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
mesh_anchor_hello_web is 21 chars, one over the S3 access-key bound; slug 'hello' brings it to 17.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit 090a839d42 into main 2026-09-06 13:17:22 +00:00
jschoubben deleted branch feat/route-proxy-module 2026-09-06 13:17:22 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#14