A public route used to carry its whole hostname as a literal in the module manifest, so running the same catalogue against a different domain meant overriding that literal on every routed module, per node. The mesh was, in effect, holding a map of names to services: the one thing it should never hold, because the subdomain is the operator's choice and the domain is the node's. Compose instead. A route contribution carries a `label` (the subdomain); a node carries its `public_domain` as node-level configuration; the mesh joins `<label>.<public-domain>` and grants exactly that, interpreting neither half. Held as a node property beside the node's other node-level facts (endpoint, site, overlay address), not in a module's settings — the ADR calls it node-level, and the settings table is keyed per module. Additive, so an unmigrated catalogue keeps working: a contribution that still carries a full `name` and no `label` passes through unchanged, and the catalogue can migrate module by module. A labelled contribution on a node with no public domain composes nothing, reading downstream as a route that named no host. And propagate: each granted route name is published into internal resolution mesh-wide, mapped to the node that serves it, alongside the `<node>.internal` names every container already gets. So a container — and an internal ACME validator, which cannot complete a challenge for a name it cannot reach — resolves a routed name to the proxy that serves it. Name-agnostic throughout: the mesh propagates whatever names it was told to serve and knows nothing about what they mean. novox/hq 02-DECISIONS/0056 Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
17 lines
1.1 KiB
SQL
17 lines
1.1 KiB
SQL
-- The public domain a node's routed names are composed under.
|
|
--
|
|
-- novox/hq ADR 0056. A public route used to carry its whole hostname in the module manifest, so
|
|
-- running the same catalogue against a different domain — a lab standing in for production, a
|
|
-- second operator's mesh — meant overriding that literal on every routed module. That made the
|
|
-- mesh hold a map of names to services: the one thing it must not, because the subdomain is the
|
|
-- operator's choice and the domain is the node's.
|
|
--
|
|
-- So the domain becomes a fact about the node, held here beside the node's other node-level
|
|
-- configuration (its endpoint, its site, its overlay address). A module contributes only the label
|
|
-- (the subdomain); the mesh composes <label>.<public-domain> and never interprets what it means.
|
|
--
|
|
-- Null for a node with no public domain, which is the ordinary case: most machines serve nothing
|
|
-- to the outside. A routed module on such a node composes no name and the proxy simply has nothing
|
|
-- to serve for it — additive, so an unmigrated catalogue carrying full hostnames is untouched.
|
|
alter table node add column public_domain text;
|