The broker credential handed to a module named the genesis MESH_BROKER_ADDRESS (the broker's public endpoint), which a joined node's firewall does not admit — a cross-node consumer timed out fetching the broker's certificate. brokerReachableAt now returns the broker as the target node can reach it: a node on the overlay gets the hub's .internal name (fingerprint pinning makes the host swap safe for TLS); a node not yet on the overlay keeps the genesis address, so bring-up is unchanged. Both credential paths (module issue, builder issue) use it.
Reachability half of hq issue 055. Proven green by the two-node bed in mesh-lab.
The broker credential handed to a module named the genesis MESH_BROKER_ADDRESS (the broker's public endpoint), which a joined node's firewall does not admit — a cross-node consumer timed out fetching the broker's certificate. `brokerReachableAt` now returns the broker as the target node can reach it: a node on the overlay gets the hub's `.internal` name (fingerprint pinning makes the host swap safe for TLS); a node not yet on the overlay keeps the genesis address, so bring-up is unchanged. Both credential paths (module issue, builder issue) use it.
Reachability half of hq issue 055. Proven green by the two-node bed in mesh-lab.
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
The broker credential handed to a module named the genesis MESH_BROKER_ADDRESS — the
broker's public endpoint. That is reachable from the control-node itself but not routed
to another node, whose firewall admits only the overlay (from:mesh); a consumer on a
joined node timed out fetching the broker's certificate and never connected.
brokerReachableAt returns the broker's address as the given node can reach it: a node on
the overlay gets the hub's `.internal` name (which every node resolves and the firewall
admits, the fingerprint pin making the host swap safe for TLS); a node not yet on the
overlay — at genesis, before any `overlay place`, when the builder's account is issued —
keeps the genesis address, so bring-up is unchanged. Both credential paths (module issue
and builder issue) use it. This is the reachability half of novox/hq issue 055.
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The broker credential handed to a module named the genesis MESH_BROKER_ADDRESS (the broker's public endpoint), which a joined node's firewall does not admit — a cross-node consumer timed out fetching the broker's certificate.
brokerReachableAtnow returns the broker as the target node can reach it: a node on the overlay gets the hub's.internalname (fingerprint pinning makes the host swap safe for TLS); a node not yet on the overlay keeps the genesis address, so bring-up is unchanged. Both credential paths (module issue, builder issue) use it.Reachability half of hq issue 055. Proven green by the two-node bed in mesh-lab.
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx