The controller added a from-anywhere opening for the broker port on the broker's host (the foundation port), widening the nats module's own from: mesh, so a machine could enrol before having a tunnel. hq ADR 0169 (accepted) decides the bus is never public and machines join through the tunnel. This removes the widening; the bus port is now what nats declares, the mesh. Checked live before: all 60 bus connections came from 10.10.0.x or Docker's local bridge. Cost until ADR 0169's join-through-the-tunnel lands (branch feat/a-machine-joins-through-the-tunnel): a brand-new machine cannot enrol from outside the tunnel. No module changes. Test: the bus port renders for mesh addresses only. go test ./... passes.
The controller added a from-anywhere opening for the broker port on the broker's host (the foundation port), widening the nats module's own from: mesh, so a machine could enrol before having a tunnel. hq ADR 0169 (accepted) decides the bus is never public and machines join through the tunnel. This removes the widening; the bus port is now what nats declares, the mesh. Checked live before: all 60 bus connections came from 10.10.0.x or Docker's local bridge. Cost until ADR 0169's join-through-the-tunnel lands (branch feat/a-machine-joins-through-the-tunnel): a brand-new machine cannot enrol from outside the tunnel. No module changes. Test: the bus port renders for mesh addresses only. go test ./... passes.
The controller widened the bus's from-mesh port to from-anywhere on the
broker's host so a machine could enrol before it had a tunnel. ADR 0169
has machines join through the tunnel and decides the bus is never public;
every live bus connection already comes from the mesh.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The controller added a from-anywhere opening for the broker port on the broker's host (the foundation port), widening the nats module's own from: mesh, so a machine could enrol before having a tunnel. hq ADR 0169 (accepted) decides the bus is never public and machines join through the tunnel. This removes the widening; the bus port is now what nats declares, the mesh. Checked live before: all 60 bus connections came from 10.10.0.x or Docker's local bridge. Cost until ADR 0169's join-through-the-tunnel lands (branch feat/a-machine-joins-through-the-tunnel): a brand-new machine cannot enrol from outside the tunnel. No module changes. Test: the bus port renders for mesh addresses only. go test ./... passes.