Manifests publish software ports; the machine side is the assignment's #173
Closed
mesh-admin
wants to merge 2 commits from
fix/manifests-publish-software-ports into main
pull from: fix/manifests-publish-software-ports
merge into: :main
:main
:feat/the-store-keeps-what-the-records-name
:feat/a-provider-declares-what-it-derives
:feat/the-operators-machine
:fix/adr-0170-cited
:feat/the-firewall-seat-serves-its-verbs
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/nzbget-for-ace
:feat/bazarr-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
postgres, distribution, gitea, mailu, only-office and portainer published
long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port
in a definition (ADR 0038, the migration note). Each now publishes the
software's port and names it in listens (mailu's web/web-tls and
only-office's and portainer's web said the machine number); mailu's env
says ${port:80}/${port:443} instead of 7080/7443.
Nothing moves on novox. postgres, distribution and gitea already have their
machine ports as novox settings (6852, 5100, 222); mailu, only-office and
portainer need theirs set BEFORE this rolls out:
settings set mailu {"ports":{"80":7080,"443":7443}} --node novox
settings set only-office {"ports":{"80":9070}} --node novox
settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox
Those pins are accepted by today's manifests too (GivenPorts answers to the
container port), so setting them first changes nothing either.
Verified with the controller's own publishedOn/portInto/GivenPorts on
novox's settings (+ the three pins): every container's published ports and
mailu's env file render byte-identical before and after — mesh-store
6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80
7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443.
Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a
short form cannot express; its monitor port needs its own change.
postgres, distribution, gitea, mailu, only-office and portainer published long-form mappings (5432:5432, 222:22, 7080:80, 9090:9000 …): a machine port in a definition (ADR 0038, the migration note). Each now publishes the software's port and names it in listens (mailu's web/web-tls and only-office's and portainer's web said the machine number); mailu's env says ${port:80}/${port:443} instead of 7080/7443. Nothing moves on novox. postgres, distribution and gitea already have their machine ports as novox settings (6852, 5100, 222); mailu, only-office and portainer need theirs set BEFORE this rolls out: settings set mailu {"ports":{"80":7080,"443":7443}} --node novox settings set only-office {"ports":{"80":9070}} --node novox settings set portainer {"ports":{"9000":9090,"9443":9443}} --node novox Those pins are accepted by today's manifests too (GivenPorts answers to the container port), so setting them first changes nothing either. Verified with the controller's own publishedOn/portInto/GivenPorts on novox's settings (+ the three pins): every container's published ports and mailu's env file render byte-identical before and after — mesh-store 6852:5432, mesh-registry 5100:5000, gitea 222:22, mailu-front 7080:80 7443:443 (+ mail ports), only-office 9070:80, portainer 9090:9000 9443:9443. Not included: nats publishes 127.0.0.1:8222:8222 — a loopback bind, which a short form cannot express; its monitor port needs its own change.Follow-up: gitea is out of this PR. mesh-controller asserts git-over-ssh publishes at 222 by default when no node sets it (
TestTheForgesSshPortIsTheMeshsFixedConventionByDefault) — the short form would render22:22there and collide with the machine sshd. That is a design decision for the operator, not part of this sweep. Catalogue test on the branch now passes.Closing as superseded: stale against main (two conflicts) and its portainer slice landed as #189. Still true for distribution, mailu, only-office and postgres: their manifests carry
host:containermachine ports; each gets the same one-line change when its node has a window (ports are the mesh's to assign, no pins).Pull request closed