-- The tunnel a node found on its machine, and the peers it carried (novox/hq ADR 0105). -- -- On an adopted node that is the hub, the private network takes over the tunnel it finds: its -- key, its port, its address and range, and every peer. The node presents what it found when it -- enrols -- the same moment it presents its keys, because the found tunnel's key IS its key on the -- private network from then on -- and the mesh composes every address from it. -- What the node presented: interface, unit and configuration path, port, address and range, and -- the tunnel's public key. The private key never travels; the node keeps it as its own overlay -- key. Null on a node that found no tunnel, which is every converged one. alter table node add column tunnel jsonb; -- The node's last account of carrying it: the found interface down and disabled, the mesh's up -- in its place. Null until the node says so. alter table node add column tunnel_carried jsonb; -- The peers the found tunnel had: a public key and the address the tunnel routed to it. Peers of -- the tunnel, not nodes of the mesh, until they enrol -- a machine the mesh has no record of, whose -- identity precedes its enrolment. One row per key, and one address per key on one tunnel. create table tunnel_peer ( node uuid not null references node(id) on delete cascade, public_key text not null, address inet not null, since timestamptz not null default now(), primary key (node, public_key), unique (node, address) );