novox/hq 08-connectivity §3, built. The mirror of a database grant: there the consumer supplies a name and receives credentials; here it supplies a target and receives a name. Nothing new in the vocabulary — a route is a provision like any other. One field was missing and it is the one that matters for anything reaching back: a contribution now carries where the mesh says that machine is. A reverse proxy is told to send traffic to a consumer and has to open a connection, so without it every provider implementing a provision would have to know how the mesh names machines — a convention leaking into every module. The proxy itself is an example, not part of the control plane: the contract is the file, not this program. It replaces its table whole rather than merging, because the file is the whole truth about who has a route and merging would keep serving a name whose module was unassigned — the stale-route fault 08-connectivity lists as open, reintroduced one level down. A name it does not serve is refused by saying which it does: a route withdrawn and a name that never existed are different things.
15 lines
534 B
Docker
15 lines
534 B
Docker
# The route proxy, as a module ships one.
|
|
#
|
|
# Static and FROM scratch like the control plane's image, and for the same reason: it is fetched
|
|
# by digest and run on a machine, so everything in it is something a person would have to audit.
|
|
FROM golang:1.25-alpine AS build
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' -o /mesh-route-proxy ./examples/route-proxy
|
|
|
|
FROM scratch
|
|
COPY --from=build /mesh-route-proxy /mesh-route-proxy
|
|
ENTRYPOINT ["/mesh-route-proxy"]
|