Reach asks for names on a routed endpoint #137

Merged
mesh-admin merged 1 commits from fix/reach-names-a-route-not-a-port into main 2026-09-29 00:53:28 +00:00
Contributor

Corrects the change merged an hour ago in #136, and ADR 0138 with it (hq#178).

A routed endpoint's port is how the proxy reaches it and nothing else. ADR 0045 decided that before
0138 was written: a public service is exposed through the proxy, not by opening its own port — it
listens from: mesh, only the proxy reaches it, and it is exposed by name. So 0138's claim that
public means "the filter opens the port to anywhere" is wrong wherever a proxy serves the endpoint.

Found by trying to express one real module rather than by review. Its routed name must be public,
because browsers post to its collection endpoint; its machine-side port must not be, because that port
serves its dashboard in cleartext over plain HTTP. Under one value driving both, saying public would
have reopened a port that had been narrowed an hour earlier for exactly that reason. Measured the same
evening: that module's routed name answered from the internet over TLS while its machine-side port was
refused from the same place. The port is not the path.

So:

  • routed endpoint — reach asks for names; the port keeps what the manifest said.
  • unrouted endpoint — git over ssh, a mail port, the bus — reach governs the port, because there is
    no name and the port is the only way in.

That is the split 0138 already drew in "an endpoint that is not routed is reached but never named";
what it got wrong was carrying the filter across it.

Two tests replace the one that encoded the error: an unrouted endpoint's port follows its reach through
all four values, and a public reach on a routed endpoint leaves the port as the manifest said while
still composing the public name and dropping the internal one — so the reach is honoured rather than
ignored. Proved by making the routed-port set empty once: exactly that assertion fails.

Corrects the change merged an hour ago in #136, and ADR 0138 with it (hq#178). A routed endpoint's port is how the proxy reaches it and nothing else. ADR 0045 decided that before 0138 was written: *a public service is exposed through the proxy, not by opening its own port* — it listens `from: mesh`, only the proxy reaches it, and it is exposed by name. So 0138's claim that `public` means "the filter opens the port to anywhere" is wrong wherever a proxy serves the endpoint. Found by trying to express one real module rather than by review. Its routed name must be public, because browsers post to its collection endpoint; its machine-side port must not be, because that port serves its dashboard in cleartext over plain HTTP. Under one value driving both, saying `public` would have reopened a port that had been narrowed an hour earlier for exactly that reason. Measured the same evening: that module's routed name answered from the internet over TLS while its machine-side port was refused from the same place. The port is not the path. So: - **routed endpoint** — reach asks for names; the port keeps what the manifest said. - **unrouted endpoint** — git over ssh, a mail port, the bus — reach governs the port, because there is no name and the port is the only way in. That is the split 0138 already drew in "an endpoint that is not routed is reached but never named"; what it got wrong was carrying the filter across it. Two tests replace the one that encoded the error: an unrouted endpoint's port follows its reach through all four values, and a public reach on a routed endpoint leaves the port as the manifest said while still composing the public name and dropping the internal one — so the reach is honoured rather than ignored. Proved by making the routed-port set empty once: exactly that assertion fails.
mesh-admin added 1 commit 2026-09-29 00:53:27 +00:00
A routed endpoint's port is how the proxy reaches it and nothing else (ADR 0045):
a public service listens from the mesh, only the proxy reaches it, and it is
exposed by name. So reach on a routed endpoint asks for names, and the port keeps
what the manifest said; on an unrouted one — git over ssh, a mail port, the bus —
it governs the port, because there is no name and the port is the only way in.

Found by trying to express a real module rather than by review: routed name public
because browsers post to it, machine-side port private because it serves a
dashboard in cleartext. Under one value for both there was no way to say it, and
'public' would have reopened a port narrowed an hour earlier.

novox/hq ADR 0138, corrected in place the same day.
mesh-admin merged commit b4da20ecc0 into main 2026-09-29 00:53:28 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#137