A route says the largest body its proxy may carry, and both proxies honour it #48

Closed
jschoubben wants to merge 2 commits from feat/registry-public-route into main
Owner

The registry's hand-over (hq ADR 0082/0104). Pairs with novox/mesh-catalog PR #47.

What changes

  • internal/catalogue/route.go: the route contribution has an agreed vocabulary — label (or legacy name), port, and the new max-request-body (a whole positive number of bytes). The parser refuses a key no proxy reads (naming the known ones), a route with no port, and a limit that is not a number of bytes — a JSON null included. Every existing catalogue manifest passes.
  • examples/route-proxy: reads max-request-body as written; a declared body past it is refused before a byte is read, an undeclared one at the byte past the limit — as 413, not the 502 the transport would have produced. A route whose limit it cannot read is skipped and named, like a port that is not one. Review fix: presence of the key is checked before the value is read, so null is skipped exactly as the adapter skips it and the catalogue refuses it — an absent key alone means no limit.
  • internal/catalogue/registry_gate_test.go: reads distribution, distribution-gate and route-adapter from the catalogue beside the checkout. Holds: the store still resolves with no proxy (genesis' set); the three resolve together with route from the adapter; a gate assigned to a machine without the store is refused by name (the-artifact-store … one per mesh) rather than raising a second, empty store there — the review found the first version asserted that pull-in as the feature; the store's seat is mesh-scoped in #47 for this. The gate contributes registry-api.<domain> on the port the node's ports setting gave it, with the twenty-gigabyte limit; only the gate mounts the htpasswd, locks the door and enables delete; the store carries no auth and no delete.

Tests: go build ./... && go vet ./... && go test -count=1 ./... green with MESH_TEST_POSTGRES set. gofmt -l . flags cmd/mesh-builder/stdout_test.go, which is unformatted on main already and untouched here.

Note for CI: the two registry_gate_test.go tests skip (catalogueManifest skips when the module is absent beside the checkout) until #47 lands in mesh-catalog — the controller's CI will not exercise them before that merge. They ran green locally against the #47 branch.

Not merged on purpose — awaiting the catalogue PR beside it.

The registry's hand-over (hq ADR 0082/0104). Pairs with novox/mesh-catalog PR #47. **What changes** - `internal/catalogue/route.go`: the route contribution has an agreed vocabulary — `label` (or legacy `name`), `port`, and the new `max-request-body` (a whole positive number of bytes). The parser refuses a key no proxy reads (naming the known ones), a route with no port, and a limit that is not a number of bytes — a JSON `null` included. Every existing catalogue manifest passes. - `examples/route-proxy`: reads `max-request-body` as written; a declared body past it is refused before a byte is read, an undeclared one at the byte past the limit — as 413, not the 502 the transport would have produced. A route whose limit it cannot read is skipped and named, like a port that is not one. **Review fix**: presence of the key is checked before the value is read, so `null` is skipped exactly as the adapter skips it and the catalogue refuses it — an absent key alone means no limit. - `internal/catalogue/registry_gate_test.go`: reads `distribution`, `distribution-gate` and `route-adapter` from the catalogue beside the checkout. Holds: the store still resolves with no proxy (genesis' set); the three resolve together with `route` from the adapter; **a gate assigned to a machine without the store is refused by name** (`the-artifact-store … one per mesh`) rather than raising a second, empty store there — the review found the first version asserted that pull-in as the feature; the store's seat is mesh-scoped in #47 for this. The gate contributes `registry-api.<domain>` on the port the node's `ports` setting gave it, with the twenty-gigabyte limit; only the gate mounts the htpasswd, locks the door and enables delete; the store carries no auth and no delete. **Tests**: `go build ./... && go vet ./... && go test -count=1 ./...` green with `MESH_TEST_POSTGRES` set. `gofmt -l .` flags `cmd/mesh-builder/stdout_test.go`, which is unformatted on main already and untouched here. **Note for CI**: the two `registry_gate_test.go` tests skip (`catalogueManifest` skips when the module is absent beside the checkout) until #47 lands in mesh-catalog — the controller's CI will not exercise them before that merge. They ran green locally against the #47 branch. **Not merged on purpose** — awaiting the catalogue PR beside it.
jschoubben added 1 commit 2026-09-23 21:19:42 +00:00
The registry's public name is served by the predecessor with a twenty-gigabyte buffering
middleware, because a registry takes image layers in single requests of gigabytes and a
proxy's default turns every push into a 413 the registry never sees. A route contribution
had no way to say so, so the mesh could not take the name over without losing what made it
usable.

The contribution now carries `max-request-body`, a whole positive number of bytes, and the
catalogue holds every route to an agreed vocabulary — label or name, port, and the limit —
refusing a key no proxy reads (a field that parses cleanly and does nothing is a promise
nobody keeps) and a route with no port (unreachable by the proxy it just asked for, found at
parse time rather than in a proxy's log). The mesh's own proxy reads the limit as written,
refuses a body past it as 413 rather than the 502 the transport would have reported, and
skips a route whose limit it cannot read rather than carrying what the module said not to.

The registry's hand-over itself is read from the catalogue beside this checkout: the store
still resolves with no proxy, the gate beside it pulls the store in, contributes the
predecessor's name on the port the node gave it, and locks only the door that faces the
world.

hq ADR 0082/0104, the registry hand-over.
jschoubben added 1 commit 2026-09-23 21:35:32 +00:00
Review of the registry hand-over. The proxy's bodyLimit treated an absent key and a JSON
null alike, so a `max-request-body: null` was served unlimited here while the adapter
skipped it and the catalogue refused it — one provider carrying what the others refuse.
Presence is now checked before the value is read.

The catalogue-backed test asserted the gate pulling the store in beside it as the feature.
It was the fault: a node-scoped requirement with one candidate installs that candidate, so
a gate assigned to a machine without the store raised a second, empty one there behind the
real credentials and the public name. The store's seat is one per mesh now (mesh-catalog),
and the test asserts the refusal by name. Delete is asserted only behind the lock.

hq ADR 0082/0104, the registry hand-over.
Author
Owner

Closed without merging: the operator decided the mesh will not take over the predecessor's registry name — that registry holds only the predecessor's images and simply retires when the last of its apps has become a mesh-built module, so the body-limit vocabulary and the gate are not needed. The one real fix the review found (the store's seat is one per mesh) is re-submitted on its own as fix/the-artifact-store-is-one-per-mesh.

Closed without merging: the operator decided the mesh will not take over the predecessor's registry name — that registry holds only the predecessor's images and simply retires when the last of its apps has become a mesh-built module, so the body-limit vocabulary and the gate are not needed. The one real fix the review found (the store's seat is one per mesh) is re-submitted on its own as `fix/the-artifact-store-is-one-per-mesh`.
jschoubben closed this pull request 2026-09-23 21:38:50 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#48