unifi: placed data, mesh-assigned ports, an https route, its password as a file #148

Merged
mesh-admin merged 1 commits from feat/unifi-for-ace into main 2026-09-30 14:38:12 +00:00
Contributor

Prepares unifi for ace (HAL -> nox-mesh). Preparation only; nothing is assigned.

  • data: placed directory ${dir:data} (1000:1000, 0700) instead of /services/unifi/data
  • ports: container ports only; the mesh assigns the machine side, ace pins today's numbers in its assignment
  • discovery-l2 names the software's port (1900); ace publishes it on 1902
  • sidecar dials https://127.0.0.1:${port:8443} instead of a literal 8443
  • controller password: own-secret controller in the mergeable config.json (ADR 0086); ace accepts it, not mints
  • web UI contributed as an https/insecure route (label unifi), as HAL's hand-written traefik file does
  • image: manifest-list digest of what ace runs (8.0.24-ls221); the old pin was its amd64 child, so no change in bits

Verified: catalogue tests (MESH_CATALOGUE set); throwaway container of the pinned image answers /status (8.0.24, up) and /inform; sidecar client parses a config.json with an endpoints key and reaches the controller (refused only on dummy creds).

Prepares unifi for ace (HAL -> nox-mesh). Preparation only; nothing is assigned. - data: placed directory `${dir:data}` (1000:1000, 0700) instead of `/services/unifi/data` - ports: container ports only; the mesh assigns the machine side, ace pins today's numbers in its assignment - discovery-l2 names the software's port (1900); ace publishes it on 1902 - sidecar dials `https://127.0.0.1:${port:8443}` instead of a literal 8443 - controller password: own-secret `controller` in the mergeable config.json (ADR 0086); ace **accepts** it, not mints - web UI contributed as an https/insecure route (label `unifi`), as HAL's hand-written traefik file does - image: manifest-list digest of what ace runs (8.0.24-ls221); the old pin was its amd64 child, so no change in bits Verified: catalogue tests (MESH_CATALOGUE set); throwaway container of the pinned image answers /status (8.0.24, up) and /inform; sidecar client parses a config.json with an `endpoints` key and reaches the controller (refused only on dummy creds).
mesh-admin added 1 commit 2026-09-29 21:40:00 +00:00
The module stated /services/unifi/data and fixed machine ports (8443:8443 and
eight more) — one installation's layout and numbers, which a definition may not
carry (ADR 0038, 0112). Data is now a placed directory (${dir:data}, 1000:1000,
0700), the container publishes its own ports and the mesh assigns the machine
side; an assignment pins them where devices already know them. The L2 endpoint
names the port the software uses (1900), not the one a machine published it on.

The sidecar dialled https://127.0.0.1:8443, true only while the machine port
equals the container's; it now asks for ${port:8443}. Its controller password
was a setting (plaintext in the mesh DB); it is now an own-secret written into
the one mergeable file (ADR 0086). The username stays a setting.

The web UI is contributed as a route to the "web" endpoint over https with
insecure upstream (the controller's own self-signed tls), as mailu's web-tls —
what HAL's hand-written traefik file for unifi does today.

Image pinned to the manifest list ace runs (8.0.24-ls221); the old pin was its
amd64 child, so the image is unchanged.

Verified: catalogue tests pass with MESH_CATALOGUE set; a throwaway container
of the pinned image on a fresh 1000:1000/0700 data dir answers /status (8.0.24,
up) and /inform; the sidecar client built from a config.json carrying site,
password, username and an endpoints key reaches it and is refused only on the
dummy credentials.
mesh-admin merged commit 1bfedd2a9e into main 2026-09-30 14:38:12 +00:00
mesh-admin deleted branch feat/unifi-for-ace 2026-09-30 14:38:12 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#148