Productionizes the reference reverse-proxy (mesh-control/examples/route-proxy) into a shipping catalog module — the traefik replacement, per the decided connectivity design (ADR 0007/0044/0045).
route-proxy — provides: route; listens 80/443 from: anywhere (the firewall opens them for free); reads the mesh-written contributions file (receives: route) and routes by Host header over the overlay to each consumer's at; terminates public TLS via ACME (LE staging default — ISSUE 004's production-default defect stays closed; a public-facing node overrides ACME_DIRECTORY to production). Ships the Go proxy via a cross-repo Dockerfile (context = mesh-control, compiles the example — the example stays the single source of truth).
hello-web — a tiny demo consumer: requires: route, contributes {name, port}, listens {from: mesh} (only the proxy reaches it), slug to fit the 20-char identity bound.
Lab-proven: route-forwarding (mesh-lab) — a public name routes through the proxy to the consumer and withdraws on unassign; public-ACME TLS is proven by the existing certificates.test.ts.
Productionizes the reference reverse-proxy (`mesh-control/examples/route-proxy`) into a shipping catalog module — the traefik replacement, per the decided connectivity design (ADR 0007/0044/0045).
- **`route-proxy`** — `provides: route`; listens 80/443 `from: anywhere` (the firewall opens them for free); reads the mesh-written contributions file (`receives: route`) and routes by Host header over the overlay to each consumer's `at`; terminates public TLS via ACME (LE **staging** default — ISSUE 004's production-default defect stays closed; a public-facing node overrides `ACME_DIRECTORY` to production). Ships the Go proxy via a cross-repo Dockerfile (context = mesh-control, compiles the example — the example stays the single source of truth).
- **`hello-web`** — a tiny demo consumer: `requires: route`, contributes `{name, port}`, `listens {from: mesh}` (only the proxy reaches it), `slug` to fit the 20-char identity bound.
Lab-proven: `route-forwarding` (mesh-lab) — a public name routes through the proxy to the consumer and **withdraws on unassign**; public-ACME TLS is proven by the existing `certificates.test.ts`.
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
route-proxy is the shipping form of the reference reverse proxy (novox/hq
ADR 0007, 08-connectivity section 3): it provides route, is given every
consumer as the file at receives.route, and forwards by the Host header. It
ships the Go proxy from mesh-control/examples/route-proxy via a multi-stage
Dockerfile; no broker, own-secret or provisioner, since it only reads the file
the mesh writes.
ACME_DIRECTORY defaults to Let's Encrypt staging and is overridable per node to
production, so there is no hardcoded production default -- resolving novox/hq
04-ISSUES/004. hello-web is a minimal consumer that requires route and
contributes name+port, to exercise the grant.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Productionizes the reference reverse-proxy (
mesh-control/examples/route-proxy) into a shipping catalog module — the traefik replacement, per the decided connectivity design (ADR 0007/0044/0045).route-proxy—provides: route; listens 80/443from: anywhere(the firewall opens them for free); reads the mesh-written contributions file (receives: route) and routes by Host header over the overlay to each consumer'sat; terminates public TLS via ACME (LE staging default — ISSUE 004's production-default defect stays closed; a public-facing node overridesACME_DIRECTORYto production). Ships the Go proxy via a cross-repo Dockerfile (context = mesh-control, compiles the example — the example stays the single source of truth).hello-web— a tiny demo consumer:requires: route, contributes{name, port},listens {from: mesh}(only the proxy reaches it),slugto fit the 20-char identity bound.Lab-proven:
route-forwarding(mesh-lab) — a public name routes through the proxy to the consumer and withdraws on unassign; public-ACME TLS is proven by the existingcertificates.test.ts.https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF