Two fixes proven together by the built-store-cross-node bed:
One push leaves the mesh consistent (issue 057, ADR 0083). A provision is minted when a cross-node consumer is assigned or its account issued — before push runs — and the provider's grant list is a pure read of secrets already issued. So pushing the consumer left the provider blind until it was pushed again, with no signal to. A named push now flushes every machine whose declaration differs from what it was last sent (the same Waiting path --behind uses), by name, in the push's own output. Verified live on a kept two-node mesh: pushing the consumer populates the provider's grant and the vhost is minted.
The foundation's ports are forwarded, not only accepted on input (issue 063). The broker's amqps port is opened from anywhere so a node can enrol before it has an overlay address — but only on input. The broker is a published container port, so a cross-node dial is DNAT'd and forwarded, never reaching input; it survived on the first connection's conntrack entry, and adopting the foundation's own broker restarts it, dropping that entry, after which a joined node could never receive another declaration. The forward chain now carries the foundation ports too.
Unit suites green; the bed restarts the broker deliberately and asserts the joined node still reaches it. Resolves hq issues 057 and 063.
Two fixes proven together by the built-store-cross-node bed:
- **One push leaves the mesh consistent (issue 057, ADR 0083).** A provision is minted when a cross-node consumer is assigned or its account issued — before `push` runs — and the provider's grant list is a pure read of secrets already issued. So pushing the consumer left the provider blind until it was pushed again, with no signal to. A named push now flushes every machine whose declaration differs from what it was last sent (the same `Waiting` path `--behind` uses), by name, in the push's own output. Verified live on a kept two-node mesh: pushing the consumer populates the provider's grant and the vhost is minted.
- **The foundation's ports are forwarded, not only accepted on input (issue 063).** The broker's amqps port is opened from anywhere so a node can enrol before it has an overlay address — but only on input. The broker is a published container port, so a cross-node dial is DNAT'd and forwarded, never reaching input; it survived on the first connection's conntrack entry, and adopting the foundation's own broker restarts it, dropping that entry, after which a joined node could never receive another declaration. The forward chain now carries the foundation ports too.
Unit suites green; the bed restarts the broker deliberately and asserts the joined node still reaches it. Resolves hq issues 057 and 063.
A provision is minted while composing the consumer's node, and the
provider's grant list is a pure read of secrets already issued — so
pushing the consumer left the provider blind until somebody pushed it
again, with no signal to. A named push now captures what every machine
should be before composing, recomputes after, and sends the machines
whose declaration changed because of this push — by name, never
silently, converging over bounded rounds.
The broker's amqps port is opened from anywhere so a node can enrol
before it has an overlay address — but only in the input chain. The
broker is a published container port, so a cross-node dial is DNAT'd
and forwarded, never reaching input; it survived on the first
connection's conntrack entry and no more. Adopting the foundation's own
broker restarts it, dropping that entry, after which a joined node
could never receive another declaration. The forward chain now carries
the foundation ports too, from anywhere, matching their input rule.
Intermittent in the built-store-cross-node bed: it passed whenever the
broker did not happen to restart after the joined node first connected.
The first cut compared a before/after snapshot of the named push — but
the provision is minted at assign or module-issue, before push runs, so
by push time the provider is already behind with no delta to detect.
Fixed to flush machines whose declaration differs from what they were
last SENT (the same Waiting path --behind uses), which is the honest
meaning of 'one push leaves the mesh consistent' (ADR 0083). Verified
live on a kept two-node mesh: pushing the consumer populates the
provider's grant and the vhost is minted.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two fixes proven together by the built-store-cross-node bed:
pushruns — and the provider's grant list is a pure read of secrets already issued. So pushing the consumer left the provider blind until it was pushed again, with no signal to. A named push now flushes every machine whose declaration differs from what it was last sent (the sameWaitingpath--behinduses), by name, in the push's own output. Verified live on a kept two-node mesh: pushing the consumer populates the provider's grant and the vhost is minted.Unit suites green; the bed restarts the broker deliberately and asserts the joined node still reaches it. Resolves hq issues 057 and 063.