A machine says which ports it already holds

novox/hq ADR 0038 and 04-ISSUES/028. The substrate is not a module: a
node raises it from the bundle it carries before any mesh exists, so the
control plane has never heard of the store, the broker, or the control
plane's own container. A module assigned afterwards is handed a port one
of them holds, and finds out from a container runtime three layers down.

The host already recorded which resources it carried and which the mesh
sent — that distinction exists so the two never remove each other. It
now also records what each one binds, and reports the carried ones.

What the declaration binds, not what is open. A machine's open ports are
a moving target — something a person started, a connection the kernel
handed out — and assigning around those would mean a port that was free
when it was asked for and taken when it was used. What a resource
declares is stable, and it is the half the mesh can be responsible for.

Only the carried ones are reported. What the mesh put here it already
knows, and reporting it back would make the machine an authority on the
mesh's own bookkeeping.
This commit is contained in:
2026-09-01 18:29:39 +02:00
parent a7a2a48615
commit b91342a6bd
4 changed files with 81 additions and 1 deletions
+29 -1
View File
@@ -15,6 +15,7 @@ import (
"fmt"
"os"
"os/signal"
"sort"
"strings"
"syscall"
"text/tabwriter"
@@ -733,7 +734,7 @@ func applyAndKeep(ctx context.Context, opts options, raw []byte, signed *store.D
saveErr.Error()}
}
report := link.Report{}
report := link.Report{Carried: carriedPorts(updated)}
for _, change := range outcome.Outcomes {
report.Applied = append(report.Applied, change.ID)
}
@@ -798,3 +799,30 @@ func sealOpener(statePath string) apply.Unseal {
return key.Unseal(sealed)
}
}
// carriedPorts is every machine port held by what this host raised from its own bundle.
//
// **What the mesh must assign around** (novox/hq ADR 0038). The substrate is not a module: a node
// raises it before any mesh exists, so the control plane has never heard of the store or the
// broker. Told this, it can put a module somewhere else; not told, it hands out a port one of them
// holds and finds out from a container runtime.
//
// Only what was carried. What the mesh itself put here it already knows about, and reporting it
// back would make the machine an authority on the mesh's own bookkeeping.
func carriedPorts(state store.State) []int {
seen := map[int]bool{}
var out []int
for _, applied := range state.Resources {
if applied.Origin == store.OriginDeclared {
continue
}
for _, port := range applied.Holds {
if !seen[port] {
seen[port] = true
out = append(out, port)
}
}
}
sort.Ints(out)
return out
}