nodered: settings are files the mesh writes; editor locked with adminAuth; pin 5.0.7 #149
Open
mesh-admin
wants to merge 3 commits from
feat/nodered-for-ace into main
pull from: feat/nodered-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/postgres-is-not-named-after-the-seat
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/jackett-for-ace
:feat/oidc-client-provision
:feat/mosquitto-placed
:feat/nodered-for-ace
:feat/influxdb-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/n8n-for-ace
:feat/letta-for-ace
:feat/baserow-for-ace
:feat/supabase-for-ace
:feat/nzbget-for-ace
:feat/matrix-for-ace
:feat/bazarr-for-ace
:feat/redis-for-ace
:feat/mssql-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/grafana-for-ace
:feat/unifi-for-ace
:feat/icecast-for-ace
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED
editor (which runs arbitrary code) was open to anyone who reached it, and
the module's own tools had no token to present to an install that was locked.
against the admin secret -- a minted password, or the bcrypt hash an
existing install held (accepted), so current logins keep working -- and a
static bearer token (api-token) the sidecar presents. It loads settings.json
beside it, the one mergeable file; endpoints is dropped there, and an
optional timeZone sets process.env.TZ (assignments cannot set env).
tried to parse as JSON.
Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container
started with the generated files: anonymous /flows 401, bearer api-token 200,
bad token 401, password grant 200/403 with a minted password and with a
bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings;
timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy
answers {rev}.
Migration notes for ace (assignment draft in the migration repo):
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED editor (which runs arbitrary code) was open to anyone who reached it, and the module's own tools had no token to present to an install that was locked. - settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked against the admin secret -- a minted password, or the bcrypt hash an existing install held (accepted), so current logins keep working -- and a static bearer token (api-token) the sidecar presents. It loads settings.json beside it, the one mergeable file; endpoints is dropped there, and an optional timeZone sets process.env.TZ (assignments cannot set env). - The sidecar's runtime config is no longer merged; it carries the token. - Directories are placed (state, data), the route binds into state. - Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6. - deployFlows asks for API v2: v1 answers 204 with no body, which the client tried to parse as JSON. Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container started with the generated files: anonymous /flows 401, bearer api-token 200, bad token 401, password grant 200/403 with a minted password and with a bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings; timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy answers {rev}.Node-RED's one broker node pointed at zurag.be:1884, where nothing listens. nodered now requires mqtt-topic (asking for every topic: flows follow the devices' own) and a run-once `mqtt` step — declared last, restarted when the binding, credential or settings change — points the mesh's broker nodes at the bound broker through Node-RED's admin API with the module's api-token: the node the step makes itself when none is named, or the ones an assignment names in `mqtt.brokers`. Only host, port, TLS and the login change; the broker is asked first whether it takes the login; the deploy is against the revision read ("nodes", so only that node restarts) and a digest makes a rerun a no-op. A broker node nobody named is never touched. settings.js keeps `mqtt` and `topics` out of Node-RED.nodered now gets its MQTT broker from the mesh (commit
3c7aafd)mqtt-topic(contributestopics: ["#"], because flows follow the devices' topics), withbindsandsecrets.settings.jsnow keeps themqttandtopicskeys out of Node-RED.mqttstep is declared last. It restarts on the binding, the credential orsettings, and works through Node-RED's admin API with the module'sapi-token:mqtt.brokers, or, when none are named, a node it creates itself (mesh-mqtt-topic, named "mesh: mqtt-topic"). A broker node nobody named is never touched.at(from nodered's container that would be nodered itself).usetls:falseand credentials. It deploys against the revision it read (a 409 is re-read once) with typenodes, so only that node restarts.client.tsgainsflowsWithRev,credentialsanddeployFlowsAt.test/mqtt.test.ts(6 passing). tsc typecheck and build are clean. The catalogue tests pass with #144/#147/#149 merged. A scratch resolution for ace bindsmqtt-topic→ ace.internal:1883 asmesh_ace_nodered, and the step dials127.0.0.1:${port:1880}.settings.js, plus a throwaway mosquitto (all removed):2b0aece9c5f3b307at zurag.be:1884 (dead), anmqtt in→mqtt outpair, and an unrelated broker node.e2e/pinggote2e/pongback through the flow.mesh-mqtt-topic.ace-assignments/nodered.jsonnow names"mqtt": {"brokers": ["2b0aece9c5f3b307"]}. This fixes the MQTT flows that have been dead since 2026-09-20 (they pointed at :1884).ace.internal, which is ADR 0148's machine-side name resolution. Today a bridge container on ace does not resolve it.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.