A route composes its internal-network alias too, not only its public name #60

Merged
jschoubben merged 1 commits from feat/route-carries-internal-alias into main 2026-09-25 15:24:02 +00:00
Owner

Every cutover done on novox tonight (drive, files, files-api, git, keycloak, umami) dropped the <label>.<node>.internal alias HAL always paired with the public hostname — found only when the operator tested it by hand.

Not a security boundary (a predecessor proxy served both as a convenience, reaching a service over the VPN without a public TLS round trip, not as access control), so restoring it is composing the same convenience the same way the public name already is: <label> joined to the node's own private address (r.At), independently of whether a public domain exists to join the other half to.

composeName's signature changes (publicDomain, internalDomain) but its shape does not — additive, label-gated, apex-aware, exactly mirroring the public half it already did. Writing both names is the entire fix; consumers (route-adapter, route-proxy) pick up internal-name whenever they're updated to serve it, not before.

Full test suite passes except the three pre-existing TestTheBuildersCarriedPackageBinding* failures (hq issue 117, unrelated, left failing on purpose).

Every cutover done on novox tonight (drive, files, files-api, git, keycloak, umami) dropped the `<label>.<node>.internal` alias HAL always paired with the public hostname — found only when the operator tested it by hand. Not a security boundary (a predecessor proxy served both as a convenience, reaching a service over the VPN without a public TLS round trip, not as access control), so restoring it is composing the same convenience the same way the public name already is: `<label>` joined to the node's own private address (`r.At`), independently of whether a public domain exists to join the other half to. `composeName`'s signature changes (`publicDomain, internalDomain`) but its shape does not — additive, label-gated, apex-aware, exactly mirroring the public half it already did. Writing both names is the entire fix; consumers (route-adapter, route-proxy) pick up `internal-name` whenever they're updated to serve it, not before. Full test suite passes except the three pre-existing `TestTheBuildersCarriedPackageBinding*` failures (hq issue 117, unrelated, left failing on purpose).
jschoubben added 1 commit 2026-09-25 15:23:57 +00:00
Every cutover done on novox tonight (drive, files, files-api, git,
keycloak, umami) dropped the <label>.<node>.internal alias HAL always
paired with the public hostname — found only when the operator tested it
by hand. Not a security boundary (a predecessor proxy served both as a
convenience, reaching a service over the VPN without a public TLS round
trip, not as access control), so restoring it is composing the same
convenience the same way the public name already is: <label> joined to
the node's own private address (r.At), independently of whether a public
domain exists to join the other half to.

composeName's signature changes (publicDomain, internalDomain) but its
shape does not — additive, label-gated, apex-aware, exactly mirroring the
public half it already did. A contribution the mesh writes both names
into is the entire fix; route-adapter and route-proxy pick up internal-
name whenever they're updated to serve it, not before, so this alone
changes nothing about what is live on any node yet.
jschoubben merged commit 752abaa81d into main 2026-09-25 15:24:02 +00:00
jschoubben deleted branch feat/route-carries-internal-alias 2026-09-25 15:24:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#60