Fixes novox/hq issue 191, as decided in hq ADR 0167.
1. A route with only an internal name is served (first commit). Since ADR 0138, an endpoint that reaches only the private network gets an internal-name and no name. The proxy used to skip it.
2. Memberships carry what a module receives, and who the mesh is.Compose reports each module's received contributions: the same list its received file is written from, same-node port fix included. Push issues them in the membership as receives, together with mesh, every machine's private-network address. That's the list the filter's "from the mesh" is rendered from.
3. The proxy follows its membership. It connects with its bus account, reads mesh.assignment.<node>.route-proxy by direct get, and follows it live.
Routes come from receives.route.
Internal names are served only to the addresses in mesh and to loopback. Anyone else gets the same answer as for an unrouted name: in the request, in the TLS handshake, and in the 404's list of served names.
Until a membership with routes arrives, it serves the file, and internal names to its own machine alone.
Release order: mesh-catalog 211, issue the proxy's credential on each machine, then this PR, then push.
Tests:
received_on_the_bus_test.go: bus and file carry identical routes.
reach_test.go: who is served what, the handshake, membership application, and unreadable input.
Every access test fails with the check disabled.
go test -race ./... passes.
Fixes novox/hq issue 191, as decided in hq ADR 0167.
**1. A route with only an internal name is served** (first commit). Since ADR 0138, an endpoint that reaches only the private network gets an `internal-name` and no `name`. The proxy used to skip it.
**2. Memberships carry what a module receives, and who the mesh is.** `Compose` reports each module's received contributions: the same list its received file is written from, same-node port fix included. Push issues them in the membership as `receives`, together with `mesh`, every machine's private-network address. That's the list the filter's "from the mesh" is rendered from.
**3. The proxy follows its membership.** It connects with its bus account, reads `mesh.assignment.<node>.route-proxy` by direct get, and follows it live.
- Routes come from `receives.route`.
- Internal names are served only to the addresses in `mesh` and to loopback. Anyone else gets the same answer as for an unrouted name: in the request, in the TLS handshake, and in the 404's list of served names.
- Until a membership with routes arrives, it serves the file, and internal names to its own machine alone.
**Release order:** mesh-catalog 211, issue the proxy's credential on each machine, then this PR, then push.
Tests:
- `received_on_the_bus_test.go`: bus and file carry identical routes.
- `reach_test.go`: who is served what, the handshake, membership application, and unreadable input.
- Every access test fails with the check disabled.
- `go test -race ./...` passes.
Since ADR 0138 an endpoint that reaches only the private network gets an
internal-name and no name, and the proxy skipped it as naming nothing, so
every internal-only module was unreachable by name (novox/hq issue 191).
The proxy answered every routed name to any request carrying it, so an
internal-only route would have been public under its internal name. Each
membership now carries what its module receives, from the same
composition as its received file, and every machine's private-network
address, the list the packet filter's "from the mesh" is. The proxy
follows its membership, serves internal names only to those machines and
itself, and keeps the file until the bus has spoken (novox/hq ADR 0167,
issue 191).
mesh-admin
changed title from route-proxy: serve a route that names only its internal host (hq issue 191) to The proxy is told its routes and the mesh on the bus, and serves internal names to the mesh only (hq issue 191, ADR 0167)2026-10-01 23:48:38 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes novox/hq issue 191, as decided in hq ADR 0167.
1. A route with only an internal name is served (first commit). Since ADR 0138, an endpoint that reaches only the private network gets an
internal-nameand noname. The proxy used to skip it.2. Memberships carry what a module receives, and who the mesh is.
Composereports each module's received contributions: the same list its received file is written from, same-node port fix included. Push issues them in the membership asreceives, together withmesh, every machine's private-network address. That's the list the filter's "from the mesh" is rendered from.3. The proxy follows its membership. It connects with its bus account, reads
mesh.assignment.<node>.route-proxyby direct get, and follows it live.receives.route.meshand to loopback. Anyone else gets the same answer as for an unrouted name: in the request, in the TLS handshake, and in the 404's list of served names.Release order: mesh-catalog 211, issue the proxy's credential on each machine, then this PR, then push.
Tests:
received_on_the_bus_test.go: bus and file carry identical routes.reach_test.go: who is served what, the handshake, membership application, and unreadable input.go test -race ./...passes.0fcea460dato24f024dd74route-proxy: serve a route that names only its internal host (hq issue 191)to The proxy is told its routes and the mesh on the bus, and serves internal names to the mesh only (hq issue 191, ADR 0167)