filtering: a per-node expose setting overrides a listen's source (ADR 0051) #4

Closed
jschoubben wants to merge 1 commits from config/exposure-setting into events/module-broker-account
Owner

Implements the listens.from-as-a-setting half of ADR 0051 — the code behind your postgres case.

listens.from was a manifest constant, one value for every node a module runs on. Now a per-node setting overrides it:

settings set postgres --node novox   →   {"expose": {"5432": "anywhere"}}

makes postgres public on novox while it stays from: mesh on ace (and everywhere the setting isn't). The firewall (ADR 0050) is computed from the effective source, so the packet filter follows the setting — no manifest edit, no rebuild.

  • Exposure(m, layers) extracts and validates the override: a port the module doesn't listen on, or a source that isn't mesh/anywhere/machine, is refused rather than silently reaching nothing (the ADR 0048/0050 discipline).
  • Filtering applies it per listen (keyed on the declared port, so it travels with the mesh-assigned port).
  • UnusedSettings knows expose is a real destination for a module that listens, so a valid exposure isn't flagged stray.
  • Tests: default is mesh; the setting opens the port to anywhere; a bad port/source is refused.

Postgres already declares listens: [{5432, from: mesh}], so nothing changes there — the exposure is purely the assignment's.

Stacked on events/module-broker-account. Depends on ADR 0051 (HQ PR #19).

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Implements the `listens.from`-as-a-setting half of ADR 0051 — the code behind your postgres case. `listens.from` was a manifest constant, one value for every node a module runs on. Now a **per-node setting** overrides it: ``` settings set postgres --node novox → {"expose": {"5432": "anywhere"}} ``` makes postgres public on novox while it stays `from: mesh` on ace (and everywhere the setting isn't). The firewall (ADR 0050) is computed from the **effective** source, so the packet filter follows the setting — no manifest edit, no rebuild. - `Exposure(m, layers)` extracts and **validates** the override: a port the module doesn't listen on, or a source that isn't `mesh`/`anywhere`/`machine`, is **refused** rather than silently reaching nothing (the ADR 0048/0050 discipline). - `Filtering` applies it per listen (keyed on the declared port, so it travels with the mesh-assigned port). - `UnusedSettings` knows `expose` is a real destination for a module that listens, so a valid exposure isn't flagged stray. - Tests: default is `mesh`; the setting opens the port to `anywhere`; a bad port/source is refused. Postgres already declares `listens: [{5432, from: mesh}]`, so nothing changes there — the exposure is purely the assignment's. Stacked on `events/module-broker-account`. Depends on ADR 0051 (HQ PR #19). https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-04 19:12:48 +00:00
listens.from was a manifest constant — one value for every node a module runs
on. Now a per-node setting overrides it: {"expose": {"5432": "anywhere"}} makes
postgres public on the machine it is set for while it stays from:mesh elsewhere,
and the firewall (ADR 0050) is computed from the effective source. Exposure()
validates it — a port the module does not listen on, or a source that is not
mesh/anywhere/machine, is refused rather than reaching nothing; UnusedSettings
knows 'expose' is a real destination. Tested: default mesh, setting opens it to
anywhere, bad settings refused.
jschoubben closed this pull request 2026-09-05 01:19:53 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#4