route-proxy is the shipping form of the reference reverse proxy (novox/hq ADR 0007, 08-connectivity section 3): it provides route, is given every consumer as the file at receives.route, and forwards by the Host header. It ships the Go proxy from mesh-control/examples/route-proxy via a multi-stage Dockerfile; no broker, own-secret or provisioner, since it only reads the file the mesh writes. ACME_DIRECTORY defaults to Let's Encrypt staging and is overridable per node to production, so there is no hardcoded production default -- resolving novox/hq 04-ISSUES/004. hello-web is a minimal consumer that requires route and contributes name+port, to exercise the grant. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
26 lines
1.3 KiB
Docker
26 lines
1.3 KiB
Docker
# The route-proxy module's runtime image: the reference reverse proxy compiled into a container.
|
|
#
|
|
# **The proxy source is not vendored here.** The canonical proxy — the contract written as something
|
|
# that runs — lives in the mesh-control repository at examples/route-proxy (novox/hq 08-connectivity
|
|
# §3). This module ships the *packaging*, not a second copy of the contract, so the build context is
|
|
# the mesh-control repository root, and this Dockerfile compiles ./examples/route-proxy from it.
|
|
#
|
|
# docker build -f mesh-catalog/modules/route-proxy/Dockerfile \
|
|
# -t mesh-route-proxy:development <path-to>/mesh-control
|
|
#
|
|
# The mesh pins the digest of what this produces; the committed module.json carries the placeholder
|
|
# digest every mesh-built image does, replaced at publish.
|
|
FROM golang:1.25 AS build
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-route-proxy ./examples/route-proxy
|
|
|
|
# A small runtime with the public CA roots the ACME client needs to reach a real authority, and run
|
|
# as root so it can bind :80 and :443 — the two privileged ports a public front door listens on.
|
|
FROM alpine:3.20
|
|
RUN apk add --no-cache ca-certificates
|
|
COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy
|
|
ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"]
|