filtering: a per-node expose setting overrides a listen's source (ADR 0051)
#4
Closed
jschoubben
wants to merge 1 commits from
config/exposure-setting into events/module-broker-account
pull from: config/exposure-setting
merge into: :events/module-broker-account
:main
:fix/an-older-merge-does-not-move-a-source
:fix/a-mirrored-base-is-not-pulled-twice
:fix/a-module-hears-what-it-consumes
:fix/the-controller-may-ask-a-tool
:fix/a-module-serves-its-own-namespace
:fix/the-check-dials-as-the-mesh-does
:fix/an-edge-is-recorded-by-path
:feat/build-edges-are-recorded
:feat/one-bus
:fix/the-controller-follows-what-it-decodes
:feat/a-merge-on-the-forge-builds-what-it-moved
:feat/rollout-hand
:fix/store-seats-keep-their-protocol
:feat/the-build-machine-takes-work-on-nats
:fix/a-principal-may-hear-its-consumer
:fix/the-bus-account-has-jetstream
:fix/the-controller-pins-the-bus-certificate
:feat/the-controller-serves-on-nats
:fix/a-node-may-bind-its-consumer
:fix/mint-leaves-the-control-planes-old-secret-alone
:fix/the-controller-mounts-its-bus-secret
:fix/the-network-map-knows-the-holders
:fix/mint-bare-host-and-again
:fix/mint-finds-the-bus-on-the-hub
:switch/the-controller-speaks-nats
:feat/the-move-mints-and-delivers
:fix/seat-usage-lines
:fix/record-the-standing-holder
:feat/amqp-is-not-a-provision
:feat/seat-handover
:fix/rollout-retires-the-old-broker
:fix/the-store-owns-the-seat-set
:fix/go-126-base
:feat/nats-genesis
:fix/a-taken-tunnel-brings-its-port
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements the
listens.from-as-a-setting half of ADR 0051 — the code behind your postgres case.listens.fromwas a manifest constant, one value for every node a module runs on. Now a per-node setting overrides it:makes postgres public on novox while it stays
from: meshon ace (and everywhere the setting isn't). The firewall (ADR 0050) is computed from the effective source, so the packet filter follows the setting — no manifest edit, no rebuild.Exposure(m, layers)extracts and validates the override: a port the module doesn't listen on, or a source that isn'tmesh/anywhere/machine, is refused rather than silently reaching nothing (the ADR 0048/0050 discipline).Filteringapplies it per listen (keyed on the declared port, so it travels with the mesh-assigned port).UnusedSettingsknowsexposeis a real destination for a module that listens, so a valid exposure isn't flagged stray.mesh; the setting opens the port toanywhere; a bad port/source is refused.Postgres already declares
listens: [{5432, from: mesh}], so nothing changes there — the exposure is purely the assignment's.Stacked on
events/module-broker-account. Depends on ADR 0051 (HQ PR #19).https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
listens.from was a manifest constant — one value for every node a module runs on. Now a per-node setting overrides it: {"expose": {"5432": "anywhere"}} makes postgres public on the machine it is set for while it stays from:mesh elsewhere, and the firewall (ADR 0050) is computed from the effective source. Exposure() validates it — a port the module does not listen on, or a source that is not mesh/anywhere/machine, is refused rather than reaching nothing; UnusedSettings knows 'expose' is a real destination. Tested: default mesh, setting opens it to anywhere, bad settings refused.Pull request closed