The proxy is told its routes and the mesh on the bus, and serves internal names to the mesh only

The proxy answered every routed name to any request carrying it, so an
internal-only route would have been public under its internal name. Each
membership now carries what its module receives, from the same
composition as its received file, and every machine's private-network
address, the list the packet filter's "from the mesh" is. The proxy
follows its membership, serves internal names only to those machines and
itself, and keeps the file until the bus has spoken (novox/hq ADR 0167,
issue 191).
This commit is contained in:
2026-10-02 01:46:30 +02:00
parent 9acb5f1292
commit 24f024dd74
9 changed files with 610 additions and 32 deletions
+2 -1
View File
@@ -404,7 +404,8 @@ func declarationWith(ctx context.Context, open *stores, node string,
if err != nil {
return sendable{}, err
}
return sendable{Resources: composed.Resources, Adoption: adoption}, nil
return sendable{Resources: composed.Resources, Adoption: adoption,
Received: composed.Received, Mesh: with.Mesh}, nil
}
// renderingFor is everything a node's declaration is composed with, and the node's record.