Gives route-proxy a bus account, the way every module that speaks on the bus gets one: an own-secrets.broker, a mesh-state directory, and the credential mounted at MESH_BROKER_FILE. The proxy then reads its routes and the mesh's machine addresses from its membership on the bus (mesh-controller PR 207).
Merge first, then immediately runmodule issue route-proxy --node <machine> for each machine that runs the proxy, then push. The mesh won't compose a machine whose declared credential hasn't been issued. That machine keeps what it runs meanwhile, but gets no new pushes.
(This PR earlier passed the mesh range as an env var. That approach was dropped in favour of the membership.)
mesh-controller's catalogue tests pass against this manifest.
Gives `route-proxy` a bus account, the way every module that speaks on the bus gets one: an `own-secrets.broker`, a `mesh-state` directory, and the credential mounted at `MESH_BROKER_FILE`. The proxy then reads its routes and the mesh's machine addresses from its membership on the bus (mesh-controller PR 207).
**Merge first, then immediately run** `module issue route-proxy --node <machine>` for each machine that runs the proxy, then push. The mesh won't compose a machine whose declared credential hasn't been issued. That machine keeps what it runs meanwhile, but gets no new pushes.
(This PR earlier passed the mesh range as an env var. That approach was dropped in favour of the membership.)
mesh-controller's catalogue tests pass against this manifest.
mesh-admin
changed title from route-proxy: tell the proxy the private network's range (hq issue 191) to route-proxy: a bus account, to read its membership (hq ADR 0167, issue 191)2026-10-01 23:48:38 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Gives
route-proxya bus account, the way every module that speaks on the bus gets one: anown-secrets.broker, amesh-statedirectory, and the credential mounted atMESH_BROKER_FILE. The proxy then reads its routes and the mesh's machine addresses from its membership on the bus (mesh-controller PR 207).Merge first, then immediately run
module issue route-proxy --node <machine>for each machine that runs the proxy, then push. The mesh won't compose a machine whose declared credential hasn't been issued. That machine keeps what it runs meanwhile, but gets no new pushes.(This PR earlier passed the mesh range as an env var. That approach was dropped in favour of the membership.)
mesh-controller's catalogue tests pass against this manifest.
bf818b9fa6to4f952ce771route-proxy: tell the proxy the private network's range (hq issue 191)to route-proxy: a bus account, to read its membership (hq ADR 0167, issue 191)