An address is read from the node's settings where it is used, never recorded with a port (hq issue 102) #50

Merged
jschoubben merged 2 commits from fix/addresses-follow-the-node into main 2026-09-23 21:55:03 +00:00
Owner

novox/hq 04-ISSUES/102. Three readers did not follow a moved foundation port; each is a reader of the node's settings now. Two commits, merged and rolled out in order — not squashed:

  • A e07b56c — all code: the NAME_PORT readers (store, broker, management, bus), the ${seat:…} placeholder and its filling, address-free build records and their routing, the trust file's port, tests. module.json unchanged.
  • B cdd3638 — module.json only (plus the tests pinning it): the six ${seat:…} env values. Build and push A's binary first, then B: a control plane running an older build passes the placeholder through as the literal value.

The control plane's own store and broker connections. Sealed at genesis with the port inside; the mesh cannot open them. Each setting gets a third twin, NAME_PORT, filled into the controller's container from the node's settings for whatever claims the mesh-store / mesh-broker seat — only a given or mesh-assigned port, never the manifest's own number; on an adopted node an assigned-but-not-taken holder counts only its given ports (F3). Empty when the mesh has nothing to add, so what genesis wrote stands. A value that is still ${…} is treated as nothing said, with a line on stderr (F1 insurance).

Every recorded build. Recorded by digest and path — artifact-store://<module>/<artifact>@sha256:… — and the store's address composed in where used: the declaration's image/source, the trust file, the bases handed to a builder, the replay to the catalogue. Over the network <node>.internal:<given port>; before any network exists, the store's own node reaches it by 127.0.0.1:<port> (F2 — genesis pushes store/broker/vault/catalogue before its network step). References recorded before this with an address are re-routed when the mesh built them. No schema change → no migration.

F4, not fixed here: the images genesis pinned — <registry>:<port>/mesh-controller@… and <registry>:<port>/mesh-builder@… — are single-segment repositories with no build row, so they stay literal until each is rebuilt through the mesh (build). Rebuild both before moving the store's port, or a recreate of either strands it. Said in a code comment on artifactsInto.

F5: WithPort finds the host from the last @, so a password holding / ? # @ no longer misroutes.

A running controller picks a moved port up only when its container is recreated with the new environment (issue 103); a push of the control-node composes it.

Do not merge as one commit. Do not merge without the report on hq issue 102.

novox/hq 04-ISSUES/102. Three readers did not follow a moved foundation port; each is a reader of the node's settings now. **Two commits, merged and rolled out in order — not squashed:** - **A `e07b56c`** — all code: the `NAME_PORT` readers (store, broker, management, bus), the `${seat:…}` placeholder and its filling, address-free build records and their routing, the trust file's port, tests. `module.json` unchanged. - **B `cdd3638`** — `module.json` only (plus the tests pinning it): the six `${seat:…}` env values. **Build and push A's binary first, then B**: a control plane running an older build passes the placeholder through as the literal value. **The control plane's own store and broker connections.** Sealed at genesis with the port inside; the mesh cannot open them. Each setting gets a third twin, `NAME_PORT`, filled into the controller's container from the node's settings for whatever claims the `mesh-store` / `mesh-broker` seat — only a *given* or *mesh-assigned* port, never the manifest's own number; on an adopted node an assigned-but-not-taken holder counts only its given ports (F3). Empty when the mesh has nothing to add, so what genesis wrote stands. A value that is still `${…}` is treated as nothing said, with a line on stderr (F1 insurance). **Every recorded build.** Recorded by digest and path — `artifact-store://<module>/<artifact>@sha256:…` — and the store's address composed in where used: the declaration's `image`/`source`, the trust file, the bases handed to a builder, the replay to the catalogue. Over the network `<node>.internal:<given port>`; before any network exists, the store's own node reaches it by `127.0.0.1:<port>` (F2 — genesis pushes store/broker/vault/catalogue before its network step). References recorded before this with an address are re-routed when the mesh built them. No schema change → no migration. **F4, not fixed here:** the images genesis pinned — `<registry>:<port>/mesh-controller@…` and `<registry>:<port>/mesh-builder@…` — are single-segment repositories with no build row, so they stay literal until each is rebuilt through the mesh (`build`). Rebuild both before moving the store's port, or a recreate of either strands it. Said in a code comment on `artifactsInto`. **F5:** `WithPort` finds the host from the last `@`, so a password holding `/ ? # @` no longer misroutes. A running controller picks a moved port up only when its container is recreated with the new environment (issue 103); a push of the control-node composes it. Do not merge as one commit. Do not merge without the report on hq issue 102.
jschoubben added 2 commits 2026-09-23 21:49:58 +00:00
Three readers did not follow a moved foundation port (novox/hq 04-ISSUES/102),
and each took the control-node down in its own way: the control plane's own
store and broker connections, sealed at genesis with the port inside; and every
build the mesh ever recorded, kept as `<registry>:<port>/<module>/<artifact>@…`.

The control plane cannot open its own sealed connections to move a port, and it
cannot bind the store as a consumer would — a binding mints a credential. So its
settings get a third twin, `NAME_PORT`, read on top of the sealed value by the
store, the broker, the management API and the bus connection, and filled into
its container by a placeholder that names a seat, `${seat:mesh-store:5432}`,
from the node's given or mesh-assigned ports — never the manifest's number, and
empty when the mesh has nothing to add, so what genesis wrote stands. A value
that is still a placeholder is nothing said, aloud: the manifest naming it lands
in the next commit, once every control plane that composes it knows it.

A build is now recorded by digest and path — `artifact-store://<module>/<artifact>@…`
— and the store's address is composed in where a reference is used: the
declaration, the trust file, the bases a build is handed, a replay to the
catalogue. Over the network as `<node>.internal:<port>`; on the store's own node
before any network exists — every genesis push before its "network" step — by
loopback. A reference recorded before this, with an address, is re-routed the
same way when the mesh built it. The trust file and every provider's address
come from one derivation: the node's given port, over the mesh's assignment,
over the manifest's number.

novox/hq 04-ISSUES/102
Beside each sealed connection genesis wrote, the port this machine put the
seat's holder at: `${seat:mesh-store:5432}` for the three stores,
`${seat:mesh-broker:…}` for the bus, the plain AMQP port and the management API.
Filled from the node's settings when the control plane composes its own
declaration; empty — the sealed value stands — when the mesh has nothing to add.

On its own, after the commit before it is built and running: a control plane
that does not know the placeholder passes it through as the value, and this
manifest is composed by whatever control plane is running when it is pushed.
The reader ignores an unfilled placeholder either way, and a test holds it to
ignoring exactly what this manifest says.

novox/hq 04-ISSUES/102
jschoubben force-pushed fix/addresses-follow-the-node from b7da02e370 to cdd3638312 2026-09-23 21:49:58 +00:00 Compare
jschoubben merged commit 7ef7669c0c into main 2026-09-23 21:55:03 +00:00
jschoubben deleted branch fix/addresses-follow-the-node 2026-09-23 21:55:04 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#50