The roster is the machines: each node's internal domain covers its routes (hq ADR 0191) #238

Merged
jschoubben merged 2 commits from fix/the-mesh-publishes-the-names-it-composed into main 2026-10-03 19:12:24 +00:00
Owner

Replaces #235's suffix filter, and goes further: the roster no longer carries routed names at all.

A node has one internal domain (<node>.internal); every route on it is a name under that domain (ADR 0151) and the resolver answers it with the per-node wildcard dnsmasq already has (address=/<node>.internal/<addr>). A node's public domains (one or more) are answered by public DNS. So routeNamesInTheMesh and catalogue.NamesServed (+ helpers, tests) are removed; .Names and .Machines stay as two fields for template compatibility and are now equal.

Verified live before the change: git.novox.internal, photos-api.novox.internal, plex.ace.internal, anything.shanks.internal all resolve via the wildcard on every node; all nodes resolve through local dnsmasq.

Tests, run with MESH_TEST_POSTGRES (throwaway postgres, as make check): new TestTheRosterNamesOnlyTheMachines passes; go vet clean. One failure — TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves (dnsmasq has no bus credential, issue 203) — fails identically on unmodified main.

Replaces #235's suffix filter, and goes further: the roster no longer carries routed names at all. A node has one internal domain (`<node>.internal`); every route on it is a name under that domain (ADR 0151) and the resolver answers it with the per-node wildcard dnsmasq already has (`address=/<node>.internal/<addr>`). A node's public domains (one or more) are answered by public DNS. So `routeNamesInTheMesh` and `catalogue.NamesServed` (+ helpers, tests) are removed; `.Names` and `.Machines` stay as two fields for template compatibility and are now equal. Verified live before the change: `git.novox.internal`, `photos-api.novox.internal`, `plex.ace.internal`, `anything.shanks.internal` all resolve via the wildcard on every node; all nodes resolve through local dnsmasq. Tests, run with `MESH_TEST_POSTGRES` (throwaway postgres, as `make check`): new `TestTheRosterNamesOnlyTheMachines` passes; `go vet` clean. One failure — `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves` (dnsmasq has no bus credential, issue 203) — fails identically on unmodified main.
jschoubben added 1 commit 2026-10-03 13:39:09 +00:00
NamesServed read a route's public `name` and plan.go then filtered by suffix — telling the mesh's
names from public ones by their spelling, when the mesh composed both itself. It now publishes the
`internal-name` it composed under the serving node (ADR 0151); the suffix filter is gone.
jschoubben changed title from The roster publishes a route's internal name, never its public one (hq ADR 0191) to The roster is the machines: each node's internal domain covers its routes (hq ADR 0191) 2026-10-03 14:10:17 +00:00
jschoubben added 1 commit 2026-10-03 14:10:17 +00:00
The roster published routed names — public ones first, then (in this PR's first take) internal ones
told apart by suffix. Neither is needed: a node has one internal domain and every route on it is a
name under it, answered by the resolver's per-node wildcard; a node's public domains are public
DNS's. routeNamesInTheMesh and NamesServed are removed, and a test pins .Names to the machines.
jschoubben merged commit 06ea2168d8 into main 2026-10-03 19:12:24 +00:00
jschoubben deleted branch fix/the-mesh-publishes-the-names-it-composed 2026-10-03 19:12:25 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#238