route-proxy: a bus account, to read its membership (hq ADR 0167, issue 191) #211

Merged
mesh-admin merged 1 commits from jschoubben/an-internal-only-route AGit into main 2026-10-01 23:49:51 +00:00
Owner

Gives route-proxy a bus account, the way every module that speaks on the bus gets one: an own-secrets.broker, a mesh-state directory, and the credential mounted at MESH_BROKER_FILE. The proxy then reads its routes and the mesh's machine addresses from its membership on the bus (mesh-controller PR 207).

Merge first, then immediately run module issue route-proxy --node <machine> for each machine that runs the proxy, then push. The mesh won't compose a machine whose declared credential hasn't been issued. That machine keeps what it runs meanwhile, but gets no new pushes.

(This PR earlier passed the mesh range as an env var. That approach was dropped in favour of the membership.)

mesh-controller's catalogue tests pass against this manifest.

Gives `route-proxy` a bus account, the way every module that speaks on the bus gets one: an `own-secrets.broker`, a `mesh-state` directory, and the credential mounted at `MESH_BROKER_FILE`. The proxy then reads its routes and the mesh's machine addresses from its membership on the bus (mesh-controller PR 207). **Merge first, then immediately run** `module issue route-proxy --node <machine>` for each machine that runs the proxy, then push. The mesh won't compose a machine whose declared credential hasn't been issued. That machine keeps what it runs meanwhile, but gets no new pushes. (This PR earlier passed the mesh range as an env var. That approach was dropped in favour of the membership.) mesh-controller's catalogue tests pass against this manifest.
jschoubben added 1 commit 2026-10-01 23:48:17 +00:00
The proxy reads its routes and the mesh's addresses from its membership
on the bus rather than from a file alone (novox/hq ADR 0167, issue 191).
jschoubben force-pushed jschoubben/an-internal-only-route from bf818b9fa6 to 4f952ce771 2026-10-01 23:48:17 +00:00 Compare
mesh-admin changed title from route-proxy: tell the proxy the private network's range (hq issue 191) to route-proxy: a bus account, to read its membership (hq ADR 0167, issue 191) 2026-10-01 23:48:38 +00:00
mesh-admin merged commit 1271f797e9 into main 2026-10-01 23:49:51 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#211