Corrects the change merged an hour ago in #136, and ADR 0138 with it (hq#178).
A routed endpoint's port is how the proxy reaches it and nothing else. ADR 0045 decided that before
0138 was written: a public service is exposed through the proxy, not by opening its own port — it
listens from: mesh, only the proxy reaches it, and it is exposed by name. So 0138's claim that public means "the filter opens the port to anywhere" is wrong wherever a proxy serves the endpoint.
Found by trying to express one real module rather than by review. Its routed name must be public,
because browsers post to its collection endpoint; its machine-side port must not be, because that port
serves its dashboard in cleartext over plain HTTP. Under one value driving both, saying public would
have reopened a port that had been narrowed an hour earlier for exactly that reason. Measured the same
evening: that module's routed name answered from the internet over TLS while its machine-side port was
refused from the same place. The port is not the path.
So:
routed endpoint — reach asks for names; the port keeps what the manifest said.
unrouted endpoint — git over ssh, a mail port, the bus — reach governs the port, because there is
no name and the port is the only way in.
That is the split 0138 already drew in "an endpoint that is not routed is reached but never named";
what it got wrong was carrying the filter across it.
Two tests replace the one that encoded the error: an unrouted endpoint's port follows its reach through
all four values, and a public reach on a routed endpoint leaves the port as the manifest said while
still composing the public name and dropping the internal one — so the reach is honoured rather than
ignored. Proved by making the routed-port set empty once: exactly that assertion fails.
Corrects the change merged an hour ago in #136, and ADR 0138 with it (hq#178).
A routed endpoint's port is how the proxy reaches it and nothing else. ADR 0045 decided that before
0138 was written: *a public service is exposed through the proxy, not by opening its own port* — it
listens `from: mesh`, only the proxy reaches it, and it is exposed by name. So 0138's claim that
`public` means "the filter opens the port to anywhere" is wrong wherever a proxy serves the endpoint.
Found by trying to express one real module rather than by review. Its routed name must be public,
because browsers post to its collection endpoint; its machine-side port must not be, because that port
serves its dashboard in cleartext over plain HTTP. Under one value driving both, saying `public` would
have reopened a port that had been narrowed an hour earlier for exactly that reason. Measured the same
evening: that module's routed name answered from the internet over TLS while its machine-side port was
refused from the same place. The port is not the path.
So:
- **routed endpoint** — reach asks for names; the port keeps what the manifest said.
- **unrouted endpoint** — git over ssh, a mail port, the bus — reach governs the port, because there is
no name and the port is the only way in.
That is the split 0138 already drew in "an endpoint that is not routed is reached but never named";
what it got wrong was carrying the filter across it.
Two tests replace the one that encoded the error: an unrouted endpoint's port follows its reach through
all four values, and a public reach on a routed endpoint leaves the port as the manifest said while
still composing the public name and dropping the internal one — so the reach is honoured rather than
ignored. Proved by making the routed-port set empty once: exactly that assertion fails.
A routed endpoint's port is how the proxy reaches it and nothing else (ADR 0045):
a public service listens from the mesh, only the proxy reaches it, and it is
exposed by name. So reach on a routed endpoint asks for names, and the port keeps
what the manifest said; on an unrouted one — git over ssh, a mail port, the bus —
it governs the port, because there is no name and the port is the only way in.
Found by trying to express a real module rather than by review: routed name public
because browsers post to it, machine-side port private because it serves a
dashboard in cleartext. Under one value for both there was no way to say it, and
'public' would have reopened a port narrowed an hour earlier.
novox/hq ADR 0138, corrected in place the same day.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Corrects the change merged an hour ago in #136, and ADR 0138 with it (hq#178).
A routed endpoint's port is how the proxy reaches it and nothing else. ADR 0045 decided that before
0138 was written: a public service is exposed through the proxy, not by opening its own port — it
listens
from: mesh, only the proxy reaches it, and it is exposed by name. So 0138's claim thatpublicmeans "the filter opens the port to anywhere" is wrong wherever a proxy serves the endpoint.Found by trying to express one real module rather than by review. Its routed name must be public,
because browsers post to its collection endpoint; its machine-side port must not be, because that port
serves its dashboard in cleartext over plain HTTP. Under one value driving both, saying
publicwouldhave reopened a port that had been narrowed an hour earlier for exactly that reason. Measured the same
evening: that module's routed name answered from the internet over TLS while its machine-side port was
refused from the same place. The port is not the path.
So:
no name and the port is the only way in.
That is the split 0138 already drew in "an endpoint that is not routed is reached but never named";
what it got wrong was carrying the filter across it.
Two tests replace the one that encoded the error: an unrouted endpoint's port follows its reach through
all four values, and a public reach on a routed endpoint leaves the port as the manifest said while
still composing the public name and dropping the internal one — so the reach is honoured rather than
ignored. Proved by making the routed-port set empty once: exactly that assertion fails.