-- Which of a machine's links face outside it, replacing the networks it was told to say it routes. -- -- novox/hq ADR 0140, superseding 0137 and 0139. The derived filter blocked everything passing -- through a machine and then allowed the machine's own containers back by naming the address ranges -- they sit on: two ranges fixed in the controller's source, the rest recorded by 0043's column. -- -- Every route to a correct list fails. A constant describes one machine. A recorded range goes stale -- in silence, and cannot tell a network the mesh made from one a predecessor left behind — measured -- on the control-node, where six ranges fall outside the constants and two of the six belong to -- services the mesh does not run. Generating the list from the modules put half the rule set on the -- machine. -- -- The list should not exist, because the mesh has no position on a container reaching outward: that -- is not a port opened to anybody. The filter constrains what arrives from OUTSIDE the machine and -- says nothing about what did not, which needs one fact instead of a list — which links "outside" -- arrives on. -- -- Reported by the machine on every apply, never recorded by hand, so it cannot go stale. Null for a -- machine that has not reported yet; the mesh composes no filter for such a machine and leaves the -- one it has, because a rule written around a link with no name is a rule set that does not load. alter table node add column outward_links jsonb; -- What 0043 recorded is not migrated into it. The ranges answered a question that no longer exists, -- and every machine that named one keeps working without it: the traffic those ranges allowed is now -- allowed by not having arrived from outside. alter table node drop column routed_networks;