catalogue: give host-network containers the mesh's names too

A container with `network: host` was skipped when the mesh injects its
`<node>.internal` names, on the belief it "shares the machine's hosts file
already". It does not: `docker run --network host` still gives the container
its own /etc/hosts (localhost and its own id only), so every internal name the
mesh wrote is invisible inside it, and a client that dials one gets EAI_AGAIN.

This surfaced with the first host-network consumer to dial a provider by the
`.internal` address the mesh hands it as `${bound:...:at}` (the model-usage
store reaching its postgres). The remedy is the same `--add-host` every other
container already gets — the runtime accepts it with `--network host`
(verified against Docker) and mesh-host emits it for any network mode.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-07 03:44:28 +02:00
parent d9c4818e6d
commit 958bef56c7
2 changed files with 18 additions and 13 deletions
+8 -7
View File
@@ -693,6 +693,14 @@ func here(r Resolution, requirement string) *Needed {
//
// Copied rather than edited in place: these maps come from a module's manifest, and mutating one
// would change what the catalogue holds for every other machine running that module.
//
// A host-network container gets the names too. It was once skipped, on the belief that it "shares
// the machine's hosts file already" — but it does not: `docker run --network host` still gives the
// container its own /etc/hosts (localhost and its own id only), so every `<node>.internal` name the
// mesh wrote for the machine is invisible inside it, and a client that dials one gets EAI_AGAIN. The
// remedy is the same `--add-host` every other container gets — the runtime accepts it with
// `--network host` (verified), and without it a host-network consumer cannot reach a provider by the
// `.internal` address the mesh hands it as `${bound:...:at}`.
func withMeshNames(resources []map[string]any, names map[string]string) []map[string]any {
out := make([]map[string]any, 0, len(resources))
for _, r := range resources {
@@ -700,13 +708,6 @@ func withMeshNames(resources []map[string]any, names map[string]string) []map[st
out = append(out, r)
continue
}
// A container on the machine's own network shares its hosts file already, and a runtime
// refuses to write one for it. Adding names there would be an argument the runtime
// rejects, which fails the whole container for something it did not need.
if network, on := r["network"].(string); on && network == "host" {
out = append(out, r)
continue
}
copied := map[string]any{}
for k, v := range r {