Manifests publish software ports; the machine side is the assignment's #173

Closed
mesh-admin wants to merge 2 commits from fix/manifests-publish-software-ports into main
Contributor

postgres, distribution, gitea, mailu, only-office and portainer published
long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port
in a definition (ADR 0038, the migration note). Each now publishes the
software's port and names it in listens (mailu's web/web-tls and
only-office's and portainer's web said the machine number); mailu's env
says ${port:80}/${port:443} instead of 7080/7443.

Nothing moves on novox. postgres, distribution and gitea already have their
machine ports as novox settings (6852, 5100, 222); mailu, only-office and
portainer need theirs set BEFORE this rolls out:
settings set mailu {"ports":{"80":7080,"443":7443}} --node novox
settings set only-office {"ports":{"80":9070}} --node novox
settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox
Those pins are accepted by today's manifests too (GivenPorts answers to the
container port), so setting them first changes nothing either.

Verified with the controller's own publishedOn/portInto/GivenPorts on
novox's settings (+ the three pins): every container's published ports and
mailu's env file render byte-identical before and after — mesh-store
6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80
7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443.

Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a
short form cannot express; its monitor port needs its own change.

postgres, distribution, gitea, mailu, only-office and portainer published long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port in a definition (ADR 0038, the migration note). Each now publishes the software's port and names it in listens (mailu's web/web-tls and only-office's and portainer's web said the machine number); mailu's env says ${port:80}/${port:443} instead of 7080/7443. Nothing moves on novox. postgres, distribution and gitea already have their machine ports as novox settings (6852, 5100, 222); mailu, only-office and portainer need theirs set BEFORE this rolls out: settings set mailu {"ports":{"80":7080,"443":7443}} --node novox settings set only-office {"ports":{"80":9070}} --node novox settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox Those pins are accepted by today's manifests too (GivenPorts answers to the container port), so setting them first changes nothing either. Verified with the controller's own publishedOn/portInto/GivenPorts on novox's settings (+ the three pins): every container's published ports and mailu's env file render byte-identical before and after — mesh-store 6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80 7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443. Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a short form cannot express; its monitor port needs its own change.
mesh-admin added 1 commit 2026-09-30 10:36:00 +00:00
postgres, distribution, gitea, mailu, only-office and portainer published
long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port
in a definition (ADR 0038, the migration note). Each now publishes the
software's port and names it in listens (mailu's web/web-tls and
only-office's and portainer's web said the machine number); mailu's env
says ${port:80}/${port:443} instead of 7080/7443.

Nothing moves on novox. postgres, distribution and gitea already have their
machine ports as novox settings (6852, 5100, 222); mailu, only-office and
portainer need theirs set BEFORE this rolls out:
  settings set mailu {"ports":{"80":7080,"443":7443}} --node novox
  settings set only-office {"ports":{"80":9070}} --node novox
  settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox
Those pins are accepted by today's manifests too (GivenPorts answers to the
container port), so setting them first changes nothing either.

Verified with the controller's own publishedOn/portInto/GivenPorts on
novox's settings (+ the three pins): every container's published ports and
mailu's env file render byte-identical before and after — mesh-store
6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80
7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443.

Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a
short form cannot express; its monitor port needs its own change.
Author
Contributor

Follow-up: gitea is out of this PR. mesh-controller asserts git-over-ssh publishes at 222 by default when no node sets it (TestTheForgesSshPortIsTheMeshsFixedConventionByDefault) — the short form would render 22:22 there and collide with the machine sshd. That is a design decision for the operator, not part of this sweep. Catalogue test on the branch now passes.

Follow-up: gitea is **out** of this PR. mesh-controller asserts git-over-ssh publishes at 222 by default when no node sets it (`TestTheForgesSshPortIsTheMeshsFixedConventionByDefault`) — the short form would render `22:22` there and collide with the machine sshd. That is a design decision for the operator, not part of this sweep. Catalogue test on the branch now passes.
jschoubben added 1 commit 2026-09-30 10:36:26 +00:00
A controller test holds git-over-ssh at 222 as the mesh's fixed convention
when no node says otherwise (TestTheForgesSshPortIsTheMeshsFixedConvention
ByDefault): without a setting, the short form would publish 22:22 and
collide with the machine's own sshd. Changing that is a decision, not part
of this sweep.
Author
Contributor

Closing as superseded: stale against main (two conflicts) and its portainer slice landed as #189. Still true for distribution, mailu, only-office and postgres: their manifests carry host:container machine ports; each gets the same one-line change when its node has a window (ports are the mesh's to assign, no pins).

Closing as superseded: stale against main (two conflicts) and its portainer slice landed as #189. Still true for distribution, mailu, only-office and postgres: their manifests carry `host:container` machine ports; each gets the same one-line change when its node has a window (ports are the mesh's to assign, no pins).
mesh-admin closed this pull request 2026-10-01 09:25:04 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#173