route-proxy is the shipping form of the reference reverse proxy (novox/hq ADR 0007, 08-connectivity section 3): it provides route, is given every consumer as the file at receives.route, and forwards by the Host header. It ships the Go proxy from mesh-control/examples/route-proxy via a multi-stage Dockerfile; no broker, own-secret or provisioner, since it only reads the file the mesh writes. ACME_DIRECTORY defaults to Let's Encrypt staging and is overridable per node to production, so there is no hardcoded production default -- resolving novox/hq 04-ISSUES/004. hello-web is a minimal consumer that requires route and contributes name+port, to exercise the grant. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
72 lines
1.6 KiB
JSON
72 lines
1.6 KiB
JSON
{
|
|
"module": "route-proxy",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "route",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"serves": {
|
|
"route": {}
|
|
},
|
|
"receives": {
|
|
"route": "/var/lib/route-proxy/routes/mesh.json"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "anywhere",
|
|
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
|
},
|
|
{
|
|
"port": 443,
|
|
"protocol": "tcp",
|
|
"from": "anywhere",
|
|
"why": "public HTTPS for every name the mesh routes here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "routes-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy/routes",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "acme-cache",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy/acme",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "route-proxy",
|
|
"image": "mesh-route-proxy@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/route-proxy/routes:/routes:ro",
|
|
"/var/lib/route-proxy/acme:/acme"
|
|
],
|
|
"env": {
|
|
"ROUTES": "/routes/mesh.json",
|
|
"LISTEN": ":80",
|
|
"TLS_LISTEN": ":443",
|
|
"ACME_CACHE": "/acme",
|
|
"ACME_DIRECTORY": "https://acme-staging-v02.api.letsencrypt.org/directory"
|
|
}
|
|
}
|
|
]
|
|
}
|