A cross-node module reaches the broker by the hub's overlay name, not the public address
The broker credential handed to a module named the genesis MESH_BROKER_ADDRESS — the broker's public endpoint. That is reachable from the control-node itself but not routed to another node, whose firewall admits only the overlay (from:mesh); a consumer on a joined node timed out fetching the broker's certificate and never connected. brokerReachableAt returns the broker's address as the given node can reach it: a node on the overlay gets the hub's `.internal` name (which every node resolves and the firewall admits, the fingerprint pin making the host swap safe for TLS); a node not yet on the overlay — at genesis, before any `overlay place`, when the builder's account is issued — keeps the genesis address, so bring-up is unchanged. Both credential paths (module issue and builder issue) use it. This is the reachability half of novox/hq issue 055. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -216,6 +216,11 @@ func builderCommand(ctx context.Context, args []string) error {
|
||||
}
|
||||
defer inv.Close()
|
||||
|
||||
brokerAddr, err := brokerReachableAt(ctx, inv, known, *forNode)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// The URL and what verifies the broker, together. A mesh's broker presents a certificate
|
||||
// of the mesh's own, which is in no public trust store — so a URL on its own reaches only
|
||||
// a broker somebody else vouches for, and the connection fails at TLS with an error about
|
||||
@@ -228,7 +233,7 @@ func builderCommand(ctx context.Context, args []string) error {
|
||||
URL string `json:"url"`
|
||||
Fingerprint string `json:"fingerprint,omitempty"`
|
||||
}{
|
||||
URL: fmt.Sprintf("amqps://%s:%s@%s/", name, password, known.Address),
|
||||
URL: fmt.Sprintf("amqps://%s:%s@%s/", name, password, brokerAddr),
|
||||
Fingerprint: known.Fingerprint,
|
||||
})
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user