From e62201e227abda571793c3dde7139a550c6d986f Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 28 Sep 2026 04:05:32 +0200 Subject: [PATCH] rollout check dials the bus the way the mesh does MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The probe connected bare, and a bus that requires TLS and a user refused it at the handshake — so the check reported the standing server as absent. It now dials with the controller's own credential and pin, which is the one fact the check is there to report. --- cmd/mesh-controller/rollout.go | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/cmd/mesh-controller/rollout.go b/cmd/mesh-controller/rollout.go index d2e9f2f..f314642 100644 --- a/cmd/mesh-controller/rollout.go +++ b/cmd/mesh-controller/rollout.go @@ -127,9 +127,13 @@ func readinessOf(ctx context.Context, inv *inventory.Inventory) (broker.Readines if address != "" { // One dial, briefly. "Is it answering" is the one fact records cannot hold, and a mesh about // to move onto a server that is not there should hear it here rather than afterwards. - if conn, err := nats.Connect(broker.BareAddress(address), nats.Timeout(5*time.Second)); err == nil { + // + // **Dialled the way the mesh dials it** — credential and pin — because a bare connect to a + // bus that requires TLS and a user fails at the handshake, and the check then reported a + // standing server as absent (seen live, 2026-09-28). + if js, err := broker.Dial(address, nats.Timeout(5*time.Second)); err == nil { state.ServerStanding = true - conn.Close() + js.Close() } }