Reach asks for names on a routed endpoint, and its port stays the manifest's
A routed endpoint's port is how the proxy reaches it and nothing else (ADR 0045): a public service listens from the mesh, only the proxy reaches it, and it is exposed by name. So reach on a routed endpoint asks for names, and the port keeps what the manifest said; on an unrouted one — git over ssh, a mail port, the bus — it governs the port, because there is no name and the port is the only way in. Found by trying to express a real module rather than by review: routed name public because browsers post to it, machine-side port private because it serves a dashboard in cleartext. Under one value for both there was no way to say it, and 'public' would have reopened a port narrowed an hour earlier. novox/hq ADR 0138, corrected in place the same day.
This commit is contained in:
@@ -905,7 +905,18 @@ func (r Resolution) Rules(with Rendering) ([]Rule, error) {
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
// **Only for an endpoint the proxy does not serve.** A routed endpoint's port is how the
|
||||
// proxy reaches it and nothing else (ADR 0045), so `public` there asks for a public name and
|
||||
// says nothing about the port — opening it to the world as well would undo the arrangement
|
||||
// the proxy exists for, and would silently reopen a port an operator had narrowed.
|
||||
//
|
||||
// Found by trying to express a real module: one whose routed name must be public and whose
|
||||
// machine-side port must not be. Under one value for both, there was no way to say it.
|
||||
routed := RoutedPorts(m)
|
||||
for port, reach := range reaches {
|
||||
if routed[port] {
|
||||
continue
|
||||
}
|
||||
source, ok := FilterSource(reach)
|
||||
if !ok {
|
||||
return nil, fmt.Errorf("%s: %q is not a reach the filter can read", m.Module, reach)
|
||||
|
||||
Reference in New Issue
Block a user