The bus is never public: the broker port is no longer a foundation opening (hq ADR 0169) #229

Merged
mesh-admin merged 1 commits from jschoubben/the-bus-is-never-public AGit into main 2026-10-02 20:52:29 +00:00
Owner

The controller added a from-anywhere opening for the broker port on the broker's host (the foundation port), widening the nats module's own from: mesh, so a machine could enrol before having a tunnel. hq ADR 0169 (accepted) decides the bus is never public and machines join through the tunnel. This removes the widening; the bus port is now what nats declares, the mesh. Checked live before: all 60 bus connections came from 10.10.0.x or Docker's local bridge. Cost until ADR 0169's join-through-the-tunnel lands (branch feat/a-machine-joins-through-the-tunnel): a brand-new machine cannot enrol from outside the tunnel. No module changes. Test: the bus port renders for mesh addresses only. go test ./... passes.

The controller added a from-anywhere opening for the broker port on the broker's host (the foundation port), widening the nats module's own from: mesh, so a machine could enrol before having a tunnel. hq ADR 0169 (accepted) decides the bus is never public and machines join through the tunnel. This removes the widening; the bus port is now what nats declares, the mesh. Checked live before: all 60 bus connections came from 10.10.0.x or Docker's local bridge. Cost until ADR 0169's join-through-the-tunnel lands (branch feat/a-machine-joins-through-the-tunnel): a brand-new machine cannot enrol from outside the tunnel. No module changes. Test: the bus port renders for mesh addresses only. go test ./... passes.
jschoubben added 1 commit 2026-10-02 20:52:22 +00:00
The controller widened the bus's from-mesh port to from-anywhere on the
broker's host so a machine could enrol before it had a tunnel. ADR 0169
has machines join through the tunnel and decides the bus is never public;
every live bus connection already comes from the mesh.
mesh-admin merged commit 93a0c6202e into main 2026-10-02 20:52:29 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#229