From f118344246c67b3b56ff1cc97cd31a0d03aa3662 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 29 Sep 2026 11:51:39 +0200 Subject: [PATCH] Every module names its endpoints, and every route names the one it serves MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 75 endpoints across 50 modules, named from what each one is for rather than by a rule: mail's seven protocol ports are smtp, imaps, submission and the rest; unifi's nine are inform, stun, discovery, the two portal ports and syslog; minio's two are s3 and console; the resolver's two are dns-udp and dns-tcp. And 35 route contributions name the endpoint they serve instead of repeating its port. A route and a listen both carried a port and nothing said they were the same thing; now one of them does. gitea's path-level deny rule names neither, because it is a rule about a name rather than an endpoint. novox/hq ADR 0138. The words shipped a release ahead in mesh-controller #138 and #139, and the control plane running today is built from that merge — checked before this was written, because an unknown manifest key is refused and a catalogue using one against an older control plane would stop resolving. --- modules/baserow/module.json | 3 ++- modules/bazarr/module.json | 3 ++- modules/bookshelf/module.json | 3 ++- modules/de-spiegel/module.json | 3 ++- modules/distribution/module.json | 1 + modules/dnsmasq/module.json | 2 ++ modules/gitea/module.json | 4 +++- modules/grafana/module.json | 3 ++- modules/hello-web/module.json | 3 ++- modules/home-assistant/module.json | 3 ++- modules/icecast/module.json | 1 + modules/influxdb/module.json | 1 + modules/invoicing/module.json | 6 ++++-- modules/jackett/module.json | 3 ++- modules/keycloak/module.json | 3 ++- modules/letta/module.json | 1 + modules/lidarr/module.json | 3 ++- modules/mailu/module.json | 20 +++++++++++++++----- modules/marrytts/module.json | 1 + modules/minio/module.json | 6 ++++-- modules/mongodb/module.json | 1 + modules/mosquitto/module.json | 2 ++ modules/mssql/module.json | 1 + modules/n8n/module.json | 3 ++- modules/nats/module.json | 1 + modules/nextcloud/module.json | 3 ++- modules/nodered/module.json | 3 ++- modules/novox.be/module.json | 3 ++- modules/nzbget/module.json | 1 + modules/ollama/module.json | 1 + modules/ombi/module.json | 3 ++- modules/only-office/module.json | 3 ++- modules/photos-eef/module.json | 3 ++- modules/photos-filip/module.json | 3 ++- modules/photos/module.json | 4 +++- modules/plex/module.json | 1 + modules/portainer/module.json | 4 +++- modules/postgres/module.json | 1 + modules/qbittorrent/module.json | 1 + modules/radarr/module.json | 3 ++- modules/redis/module.json | 1 + modules/route-proxy/module.json | 2 ++ modules/searxng/module.json | 3 ++- modules/showcase/module.json | 1 + modules/sonarr/module.json | 3 ++- modules/sshd/module.json | 1 + modules/step-ca/module.json | 1 + modules/tautulli/module.json | 3 ++- modules/umami/module.json | 3 ++- modules/unifi/module.json | 9 +++++++++ 50 files changed, 110 insertions(+), 35 deletions(-) diff --git a/modules/baserow/module.json b/modules/baserow/module.json index bf8a057..d9c2777 100644 --- a/modules/baserow/module.json +++ b/modules/baserow/module.json @@ -14,7 +14,7 @@ }, "route": { "label": "baserow", - "port": 80 + "endpoint": "web" } }, "binds": { @@ -30,6 +30,7 @@ }, "listens": [ { + "name": "web", "port": 80, "protocol": "tcp", "from": "mesh", diff --git a/modules/bazarr/module.json b/modules/bazarr/module.json index 00bd0dc..1171144 100644 --- a/modules/bazarr/module.json +++ b/modules/bazarr/module.json @@ -13,6 +13,7 @@ }, "listens": [ { + "name": "web", "port": 6767, "protocol": "tcp", "from": "mesh", @@ -110,7 +111,7 @@ "contributes": { "route": { "label": "subs", - "port": 6767 + "endpoint": "web" } }, "binds": { diff --git a/modules/bookshelf/module.json b/modules/bookshelf/module.json index 17a96b0..4447e4b 100644 --- a/modules/bookshelf/module.json +++ b/modules/bookshelf/module.json @@ -15,6 +15,7 @@ }, "listens": [ { + "name": "web", "port": 8787, "protocol": "tcp", "from": "mesh", @@ -87,7 +88,7 @@ "contributes": { "route": { "label": "books", - "port": 8787 + "endpoint": "web" } }, "binds": { diff --git a/modules/de-spiegel/module.json b/modules/de-spiegel/module.json index 18d108c..9875cd4 100644 --- a/modules/de-spiegel/module.json +++ b/modules/de-spiegel/module.json @@ -11,7 +11,7 @@ "contributes": { "route": { "label": "de-spiegel", - "port": 35621 + "endpoint": "web" } }, "binds": { @@ -23,6 +23,7 @@ }, "listens": [ { + "name": "web", "port": 35621, "protocol": "tcp", "from": "mesh", diff --git a/modules/distribution/module.json b/modules/distribution/module.json index 52a9da3..00c7740 100644 --- a/modules/distribution/module.json +++ b/modules/distribution/module.json @@ -29,6 +29,7 @@ }, "listens": [ { + "name": "registry", "port": 5000, "protocol": "tcp", "from": "mesh", diff --git a/modules/dnsmasq/module.json b/modules/dnsmasq/module.json index a4ff39f..2fa4743 100644 --- a/modules/dnsmasq/module.json +++ b/modules/dnsmasq/module.json @@ -22,6 +22,7 @@ ], "listens": [ { + "name": "dns-udp", "port": 53, "protocol": "udp", "from": "mesh", @@ -29,6 +30,7 @@ "fixed": true }, { + "name": "dns-tcp", "port": 53, "protocol": "tcp", "from": "mesh", diff --git a/modules/gitea/module.json b/modules/gitea/module.json index edb5e1d..c7f1ac4 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -13,7 +13,7 @@ "route": { "web": { "label": "git", - "port": 3000 + "endpoint": "web" }, "internal-api-refused": { "label": "git", @@ -44,12 +44,14 @@ ], "listens": [ { + "name": "web", "port": 3000, "protocol": "tcp", "from": "mesh", "why": "the forge, over http" }, { + "name": "ssh", "port": 22, "protocol": "tcp", "from": "mesh", diff --git a/modules/grafana/module.json b/modules/grafana/module.json index fe877ff..6911f08 100644 --- a/modules/grafana/module.json +++ b/modules/grafana/module.json @@ -13,6 +13,7 @@ ], "listens": [ { + "name": "web", "port": 3000, "protocol": "tcp", "from": "mesh", @@ -96,7 +97,7 @@ "contributes": { "route": { "label": "grafana", - "port": 3000 + "endpoint": "web" } }, "binds": { diff --git a/modules/hello-web/module.json b/modules/hello-web/module.json index 0cf69d7..55e1c10 100644 --- a/modules/hello-web/module.json +++ b/modules/hello-web/module.json @@ -11,7 +11,7 @@ "contributes": { "route": { "label": "hello", - "port": 8080 + "endpoint": "web" } }, "binds": { @@ -19,6 +19,7 @@ }, "listens": [ { + "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", diff --git a/modules/home-assistant/module.json b/modules/home-assistant/module.json index e860c1f..10406c5 100644 --- a/modules/home-assistant/module.json +++ b/modules/home-assistant/module.json @@ -14,6 +14,7 @@ }, "listens": [ { + "name": "web", "port": 8123, "protocol": "tcp", "from": "mesh", @@ -85,7 +86,7 @@ "contributes": { "route": { "label": "home-assistant", - "port": 8123 + "endpoint": "web" } }, "binds": { diff --git a/modules/icecast/module.json b/modules/icecast/module.json index 51c6296..3a3e5a6 100644 --- a/modules/icecast/module.json +++ b/modules/icecast/module.json @@ -13,6 +13,7 @@ }, "listens": [ { + "name": "stream", "port": 8000, "protocol": "tcp", "from": "mesh", diff --git a/modules/influxdb/module.json b/modules/influxdb/module.json index 54d4a93..a1c48ac 100644 --- a/modules/influxdb/module.json +++ b/modules/influxdb/module.json @@ -9,6 +9,7 @@ }, "listens": [ { + "name": "api", "port": 8086, "protocol": "tcp", "from": "mesh", diff --git a/modules/invoicing/module.json b/modules/invoicing/module.json index 5337417..bc1ce77 100644 --- a/modules/invoicing/module.json +++ b/modules/invoicing/module.json @@ -17,11 +17,11 @@ "route": { "site": { "label": "invoicing", - "port": 80 + "endpoint": "web" }, "api": { "label": "invoicing-api", - "port": 9000 + "endpoint": "api" } } }, @@ -36,12 +36,14 @@ }, "listens": [ { + "name": "web", "port": 80, "protocol": "tcp", "from": "mesh", "why": "the invoicing web frontend; a public name is a route grant later" }, { + "name": "api", "port": 9000, "protocol": "tcp", "from": "mesh", diff --git a/modules/jackett/module.json b/modules/jackett/module.json index a2a5d06..0b61232 100644 --- a/modules/jackett/module.json +++ b/modules/jackett/module.json @@ -6,6 +6,7 @@ ], "listens": [ { + "name": "web", "port": 9117, "protocol": "tcp", "from": "mesh", @@ -82,7 +83,7 @@ "contributes": { "route": { "label": "indexers", - "port": 9117 + "endpoint": "web" } }, "binds": { diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index ae6f921..bfef938 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -11,7 +11,7 @@ }, "route": { "label": "keycloak", - "port": 8080 + "endpoint": "web" } }, "binds": { @@ -34,6 +34,7 @@ ], "listens": [ { + "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", diff --git a/modules/letta/module.json b/modules/letta/module.json index c72c784..4cd08c0 100644 --- a/modules/letta/module.json +++ b/modules/letta/module.json @@ -24,6 +24,7 @@ }, "listens": [ { + "name": "web", "port": 8283, "protocol": "tcp", "from": "mesh", diff --git a/modules/lidarr/module.json b/modules/lidarr/module.json index 6d424b6..30c71fa 100644 --- a/modules/lidarr/module.json +++ b/modules/lidarr/module.json @@ -14,6 +14,7 @@ }, "listens": [ { + "name": "web", "port": 8686, "protocol": "tcp", "from": "mesh", @@ -86,7 +87,7 @@ "contributes": { "route": { "label": "lidarr", - "port": 8686 + "endpoint": "web" } }, "binds": { diff --git a/modules/mailu/module.json b/modules/mailu/module.json index 3df5469..581595e 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -16,27 +16,27 @@ "route": { "web": { "label": "mail", - "port": 7443, + "endpoint": "web-tls", "scheme": "https", "insecure": true }, "acme": { "label": "mail", "path": "/.well-known/acme-challenge", - "port": 7080, + "endpoint": "web", "priority": 100 }, "autoconfig": { "label": "autoconfig", - "port": 4243 + "endpoint": "autoconfig" }, "autodiscover": { "label": "autodiscover", - "port": 4243 + "endpoint": "autoconfig" }, "automx": { "label": "automx", - "port": 4243 + "endpoint": "autoconfig" } } }, @@ -60,6 +60,7 @@ ], "listens": [ { + "name": "smtp", "port": 25, "protocol": "tcp", "from": "anywhere", @@ -67,6 +68,7 @@ "fixed": true }, { + "name": "pop3", "port": 110, "protocol": "tcp", "from": "anywhere", @@ -74,6 +76,7 @@ "fixed": true }, { + "name": "imap", "port": 143, "protocol": "tcp", "from": "anywhere", @@ -81,6 +84,7 @@ "fixed": true }, { + "name": "smtps", "port": 465, "protocol": "tcp", "from": "anywhere", @@ -88,6 +92,7 @@ "fixed": true }, { + "name": "submission", "port": 587, "protocol": "tcp", "from": "anywhere", @@ -95,6 +100,7 @@ "fixed": true }, { + "name": "imaps", "port": 993, "protocol": "tcp", "from": "anywhere", @@ -102,6 +108,7 @@ "fixed": true }, { + "name": "pop3s", "port": 995, "protocol": "tcp", "from": "anywhere", @@ -109,18 +116,21 @@ "fixed": true }, { + "name": "web", "port": 7080, "protocol": "tcp", "from": "mesh", "why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy" }, { + "name": "web-tls", "port": 7443, "protocol": "tcp", "from": "mesh", "why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here" }, { + "name": "autoconfig", "port": 4243, "protocol": "tcp", "from": "mesh", diff --git a/modules/marrytts/module.json b/modules/marrytts/module.json index 308ab9b..e14ef44 100644 --- a/modules/marrytts/module.json +++ b/modules/marrytts/module.json @@ -6,6 +6,7 @@ ], "listens": [ { + "name": "api", "port": 59125, "protocol": "tcp", "from": "mesh", diff --git a/modules/minio/module.json b/modules/minio/module.json index 56c933d..a251ddb 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -14,11 +14,11 @@ "route": { "api": { "label": "files-api", - "port": 9000 + "endpoint": "s3" }, "console": { "label": "files", - "port": 9001 + "endpoint": "console" } } }, @@ -31,12 +31,14 @@ ], "listens": [ { + "name": "s3", "port": 9000, "protocol": "tcp", "from": "mesh", "why": "the S3 endpoint" }, { + "name": "console", "port": 9001, "protocol": "tcp", "from": "mesh", diff --git a/modules/mongodb/module.json b/modules/mongodb/module.json index f93fc34..61849f3 100644 --- a/modules/mongodb/module.json +++ b/modules/mongodb/module.json @@ -20,6 +20,7 @@ ], "listens": [ { + "name": "database", "port": 27017, "protocol": "tcp", "from": "mesh", diff --git a/modules/mosquitto/module.json b/modules/mosquitto/module.json index 267c24f..83c0476 100644 --- a/modules/mosquitto/module.json +++ b/modules/mosquitto/module.json @@ -34,12 +34,14 @@ }, "listens": [ { + "name": "mqtt", "port": 1883, "protocol": "tcp", "from": "mesh", "why": "modules on any machine that were granted a topic namespace" }, { + "name": "mqtt-websockets", "port": 8081, "protocol": "tcp", "from": "mesh", diff --git a/modules/mssql/module.json b/modules/mssql/module.json index 68909ec..20fca53 100644 --- a/modules/mssql/module.json +++ b/modules/mssql/module.json @@ -20,6 +20,7 @@ ], "listens": [ { + "name": "database", "port": 4848, "protocol": "tcp", "from": "mesh", diff --git a/modules/n8n/module.json b/modules/n8n/module.json index 0a2bacf..a1810e8 100644 --- a/modules/n8n/module.json +++ b/modules/n8n/module.json @@ -14,7 +14,7 @@ }, "route": { "label": "n8n", - "port": 5682 + "endpoint": "web" } }, "binds": { @@ -29,6 +29,7 @@ }, "listens": [ { + "name": "web", "port": 5682, "protocol": "tcp", "from": "mesh", diff --git a/modules/nats/module.json b/modules/nats/module.json index d2db8f0..57e5493 100644 --- a/modules/nats/module.json +++ b/modules/nats/module.json @@ -21,6 +21,7 @@ "consumes": [], "listens": [ { + "name": "bus", "port": 4222, "protocol": "tcp", "from": "mesh", diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index fc82b7b..5b82238 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -13,7 +13,7 @@ }, "route": { "label": "drive", - "port": 80 + "endpoint": "web" } }, "binds": { @@ -38,6 +38,7 @@ ], "listens": [ { + "name": "web", "port": 80, "protocol": "tcp", "from": "mesh", diff --git a/modules/nodered/module.json b/modules/nodered/module.json index cd8e801..181edf8 100644 --- a/modules/nodered/module.json +++ b/modules/nodered/module.json @@ -12,6 +12,7 @@ ], "listens": [ { + "name": "web", "port": 1880, "protocol": "tcp", "from": "mesh", @@ -81,7 +82,7 @@ "contributes": { "route": { "label": "nodered", - "port": 1880 + "endpoint": "web" } }, "binds": { diff --git a/modules/novox.be/module.json b/modules/novox.be/module.json index cbf1d8f..d502281 100644 --- a/modules/novox.be/module.json +++ b/modules/novox.be/module.json @@ -10,7 +10,7 @@ "contributes": { "route": { "label": "@", - "port": 4000 + "endpoint": "web" } }, "binds": { @@ -18,6 +18,7 @@ }, "listens": [ { + "name": "web", "port": 4000, "protocol": "tcp", "from": "mesh", diff --git a/modules/nzbget/module.json b/modules/nzbget/module.json index 87f2cf6..ce3c33d 100644 --- a/modules/nzbget/module.json +++ b/modules/nzbget/module.json @@ -15,6 +15,7 @@ }, "listens": [ { + "name": "web", "port": 6789, "protocol": "tcp", "from": "mesh", diff --git a/modules/ollama/module.json b/modules/ollama/module.json index 73d8b02..dcb6ce3 100644 --- a/modules/ollama/module.json +++ b/modules/ollama/module.json @@ -12,6 +12,7 @@ ], "listens": [ { + "name": "api", "port": 11434, "protocol": "tcp", "from": "machine", diff --git a/modules/ombi/module.json b/modules/ombi/module.json index 4f73efa..e70cd3d 100644 --- a/modules/ombi/module.json +++ b/modules/ombi/module.json @@ -14,6 +14,7 @@ }, "listens": [ { + "name": "web", "port": 3579, "protocol": "tcp", "from": "mesh", @@ -89,7 +90,7 @@ "contributes": { "route": { "label": "ombi", - "port": 3579 + "endpoint": "web" } }, "binds": { diff --git a/modules/only-office/module.json b/modules/only-office/module.json index c9562e2..9285015 100644 --- a/modules/only-office/module.json +++ b/modules/only-office/module.json @@ -11,7 +11,7 @@ "contributes": { "route": { "label": "office", - "port": 9070 + "endpoint": "web" } }, "binds": { @@ -22,6 +22,7 @@ }, "listens": [ { + "name": "web", "port": 9070, "protocol": "tcp", "from": "mesh", diff --git a/modules/photos-eef/module.json b/modules/photos-eef/module.json index 80fdaf5..b090d4c 100644 --- a/modules/photos-eef/module.json +++ b/modules/photos-eef/module.json @@ -11,7 +11,7 @@ "contributes": { "route": { "label": "eef", - "port": 4012 + "endpoint": "web" } }, "binds": { @@ -19,6 +19,7 @@ }, "listens": [ { + "name": "web", "port": 4012, "protocol": "tcp", "from": "mesh", diff --git a/modules/photos-filip/module.json b/modules/photos-filip/module.json index 0c44daf..9e9130f 100644 --- a/modules/photos-filip/module.json +++ b/modules/photos-filip/module.json @@ -11,7 +11,7 @@ "contributes": { "route": { "label": "filip", - "port": 4013 + "endpoint": "web" } }, "binds": { @@ -19,6 +19,7 @@ }, "listens": [ { + "name": "web", "port": 4013, "protocol": "tcp", "from": "mesh", diff --git a/modules/photos/module.json b/modules/photos/module.json index 235ddbc..df458a4 100644 --- a/modules/photos/module.json +++ b/modules/photos/module.json @@ -18,7 +18,7 @@ }, "route": { "label": "photos", - "port": 4001 + "endpoint": "web" } }, "binds": { @@ -32,12 +32,14 @@ }, "listens": [ { + "name": "api", "port": 9000, "protocol": "tcp", "from": "mesh", "why": "the photos backend API; the client sites on the module network call it" }, { + "name": "web", "port": 4001, "protocol": "tcp", "from": "mesh", diff --git a/modules/plex/module.json b/modules/plex/module.json index ae2c1bd..426a70f 100644 --- a/modules/plex/module.json +++ b/modules/plex/module.json @@ -18,6 +18,7 @@ }, "listens": [ { + "name": "stream", "port": 32400, "protocol": "tcp", "from": "mesh", diff --git a/modules/portainer/module.json b/modules/portainer/module.json index f7fdc2f..26844b6 100644 --- a/modules/portainer/module.json +++ b/modules/portainer/module.json @@ -7,12 +7,14 @@ ], "listens": [ { + "name": "web", "port": 9090, "protocol": "tcp", "from": "mesh", "why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number" }, { + "name": "web-tls", "port": 9443, "protocol": "tcp", "from": "mesh", @@ -103,7 +105,7 @@ "contributes": { "route": { "label": "portainer", - "port": 9090 + "endpoint": "web" } }, "binds": { diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 68f3259..197eade 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -26,6 +26,7 @@ ], "listens": [ { + "name": "database", "port": 5432, "protocol": "tcp", "from": "mesh", diff --git a/modules/qbittorrent/module.json b/modules/qbittorrent/module.json index 0cea981..1efef1a 100644 --- a/modules/qbittorrent/module.json +++ b/modules/qbittorrent/module.json @@ -16,6 +16,7 @@ }, "listens": [ { + "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", diff --git a/modules/radarr/module.json b/modules/radarr/module.json index 76701d4..351fcb3 100644 --- a/modules/radarr/module.json +++ b/modules/radarr/module.json @@ -14,6 +14,7 @@ }, "listens": [ { + "name": "web", "port": 7878, "protocol": "tcp", "from": "mesh", @@ -86,7 +87,7 @@ "contributes": { "route": { "label": "movies", - "port": 7878 + "endpoint": "web" } }, "binds": { diff --git a/modules/redis/module.json b/modules/redis/module.json index c4d77d0..f976dd6 100644 --- a/modules/redis/module.json +++ b/modules/redis/module.json @@ -40,6 +40,7 @@ }, "listens": [ { + "name": "cache", "port": 6379, "protocol": "tcp", "from": "mesh", diff --git a/modules/route-proxy/module.json b/modules/route-proxy/module.json index e212870..e861991 100644 --- a/modules/route-proxy/module.json +++ b/modules/route-proxy/module.json @@ -27,12 +27,14 @@ }, "listens": [ { + "name": "http", "port": 80, "protocol": "tcp", "from": "anywhere", "why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified" }, { + "name": "https", "port": 443, "protocol": "tcp", "from": "anywhere", diff --git a/modules/searxng/module.json b/modules/searxng/module.json index b8e836a..be03aa3 100644 --- a/modules/searxng/module.json +++ b/modules/searxng/module.json @@ -10,6 +10,7 @@ }, "listens": [ { + "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", @@ -113,7 +114,7 @@ "contributes": { "route": { "label": "searxng", - "port": 8080 + "endpoint": "web" } }, "binds": { diff --git a/modules/showcase/module.json b/modules/showcase/module.json index 82af1eb..7936d5d 100644 --- a/modules/showcase/module.json +++ b/modules/showcase/module.json @@ -43,6 +43,7 @@ ], "listens": [ { + "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", diff --git a/modules/sonarr/module.json b/modules/sonarr/module.json index 1806886..d91708b 100644 --- a/modules/sonarr/module.json +++ b/modules/sonarr/module.json @@ -14,6 +14,7 @@ }, "listens": [ { + "name": "web", "port": 8989, "protocol": "tcp", "from": "mesh", @@ -91,7 +92,7 @@ "contributes": { "route": { "label": "series", - "port": 8989 + "endpoint": "web" } }, "binds": { diff --git a/modules/sshd/module.json b/modules/sshd/module.json index 3739504..f2384cf 100644 --- a/modules/sshd/module.json +++ b/modules/sshd/module.json @@ -7,6 +7,7 @@ ], "listens": [ { + "name": "ssh", "port": 22, "protocol": "tcp", "from": "anywhere", diff --git a/modules/step-ca/module.json b/modules/step-ca/module.json index d73f612..74d694e 100644 --- a/modules/step-ca/module.json +++ b/modules/step-ca/module.json @@ -26,6 +26,7 @@ }, "listens": [ { + "name": "acme", "port": 9000, "protocol": "tcp", "from": "mesh", diff --git a/modules/tautulli/module.json b/modules/tautulli/module.json index ce94a77..f59f22a 100644 --- a/modules/tautulli/module.json +++ b/modules/tautulli/module.json @@ -12,6 +12,7 @@ ], "listens": [ { + "name": "web", "port": 8181, "protocol": "tcp", "from": "mesh", @@ -85,7 +86,7 @@ "contributes": { "route": { "label": "tautulli", - "port": 8181 + "endpoint": "web" } }, "binds": { diff --git a/modules/umami/module.json b/modules/umami/module.json index 853fdee..35c37c3 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -15,7 +15,7 @@ }, "route": { "label": "umami", - "port": 3000 + "endpoint": "web" } }, "binds": { @@ -49,6 +49,7 @@ }, "listens": [ { + "name": "web", "port": 3000, "protocol": "tcp", "from": "mesh", diff --git a/modules/unifi/module.json b/modules/unifi/module.json index a2b1573..c6a3912 100644 --- a/modules/unifi/module.json +++ b/modules/unifi/module.json @@ -6,54 +6,63 @@ ], "listens": [ { + "name": "web", "port": 8443, "protocol": "tcp", "from": "mesh", "why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later" }, { + "name": "inform", "port": 8080, "protocol": "tcp", "from": "mesh", "why": "device inform \u2014 how APs and switches check in and are adopted" }, { + "name": "stun", "port": 3478, "protocol": "udp", "from": "mesh", "why": "STUN, so managed devices can find the controller through NAT" }, { + "name": "discovery", "port": 10001, "protocol": "udp", "from": "mesh", "why": "device discovery \u2014 the controller finds unadopted devices on the network" }, { + "name": "discovery-l2", "port": 1902, "protocol": "udp", "from": "mesh", "why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900" }, { + "name": "portal-tls", "port": 8843, "protocol": "tcp", "from": "mesh", "why": "the guest captive portal over https" }, { + "name": "portal", "port": 8880, "protocol": "tcp", "from": "mesh", "why": "the guest captive portal over http" }, { + "name": "speedtest", "port": 6789, "protocol": "tcp", "from": "mesh", "why": "mobile-app speed-test throughput measurement" }, { + "name": "syslog", "port": 5514, "protocol": "udp", "from": "mesh", -- 2.54.0