An assignment says how far an endpoint reaches, and three things read it
novox/hq ADR 0138. Reachability was settled three times over: the filter read a listen's source with expose able to override it; the proxy composed a public name and an internal name for every route it was given, because it could; and the certificate authority followed from which names existed. Each was defensible and the combination was unstated, so "this endpoint must not be public" could not be written and was enforced by nothing — while a public certificate for that name was obtained anyway. Measured on the control node: an identity provider holding a 90-day public certificate and a 24-hour internal one, neither asked for. `reach` is one value per endpoint, per node — machine, internal, public or both — and the filter's source and the composed names both follow it. The authority needs no work: the proxy already asks the public authority for a route's own name and its internal authority for the internal one, so controlling the names controls the authority. Joined by the port, which a route already names: 35 of the catalogue's 36 route entries name a port the same module declares a listen on, and the one that does not is a path-level refusal — a rule about a name rather than an endpoint, left alone. Nothing said composes both names and follows the manifest's `from`, so every mesh already running is unchanged until an assignment speaks. A port that says both reach and expose is refused: they say the same thing in different words, and the filter would follow one while the names followed the other.
This commit is contained in:
@@ -186,6 +186,12 @@ func UnusedSettings(m Manifest, layers []Layer) []string {
|
||||
if key == PortsSetting {
|
||||
continue
|
||||
}
|
||||
// `reach` says how far one of this module's endpoints reaches (novox/hq ADR 0138) — the
|
||||
// filter's source, which names are composed, and therefore which authority certifies
|
||||
// them. Validated in Reaches, so not stray.
|
||||
if key == ReachSetting && len(m.Listens) > 0 {
|
||||
continue
|
||||
}
|
||||
unused = append(unused, fmt.Sprintf(
|
||||
"%s sets %q, and %s has no file or contribution to merge it into",
|
||||
layer.From, key, m.Module))
|
||||
|
||||
Reference in New Issue
Block a user