A first node gets as far as its own bus: three faults on the way #50

Merged
jschoubben merged 1 commits from fix/one-foundation-on-the-bus-the-mesh-runs-on into main 2026-09-29 14:06:34 +00:00
Owner

novox/hq issue 146. Found by trying to raise a first node in order to check something else. Four faults stacked, each hidden behind the one before it; three of them are here, and every one was right while the mesh ran on the previous broker. Nothing has raised a foundation since it changed, so nothing said so.

The bus's certificate is made by the program that needs it. The step ran openssl inside the broker's image; the bus's image is Alpine with a shell and no openssl, so it exited 127 and no mesh could be raised — and no other image the bundle names has it either. mesh-controller broker certificate writes it instead (companion PR in mesh-controller). Self-signed as before and on purpose: a host pins this server's exact certificate (ADR 0004), and at that moment there is no authority to ask. --user 0:0 because the volume is root's and the control plane's image runs as nobody.

Enrolment no longer dials TLS at a bus that speaks first. NATS sends its greeting and upgrades afterwards, so the raw pre-check met a plaintext line: first record does not look like a TLS handshake. The pin was never the problem — the client that presents the token carries the same pinned configuration and verifies inside its own handshake, so the one-time secret still leaves only after the certificate has been checked. The raw dial stays as what its tests always proved and is no longer a path anything takes.

And the token says which bus it is for. Empty meant whatever the mesh runs today, true while two buses existed and a refusal the moment one did.

A first node now gets as far as asking to join, and is refused by the bus's user list — the fourth fault, which is genesis work and not a patch. It is written up in the issue's diagnosis.

novox/hq [issue 146](https://git.novox.be/novox/hq). Found by trying to raise a first node in order to check something else. Four faults stacked, each hidden behind the one before it; three of them are here, and every one was right while the mesh ran on the previous broker. Nothing has raised a foundation since it changed, so nothing said so. **The bus's certificate is made by the program that needs it.** The step ran `openssl` inside the broker's image; the bus's image is Alpine with a shell and no `openssl`, so it exited 127 and no mesh could be raised — and no other image the bundle names has it either. `mesh-controller broker certificate` writes it instead (companion PR in mesh-controller). Self-signed as before and on purpose: a host pins this server's exact certificate (ADR 0004), and at that moment there is no authority to ask. `--user 0:0` because the volume is root's and the control plane's image runs as nobody. **Enrolment no longer dials TLS at a bus that speaks first.** NATS sends its greeting and upgrades afterwards, so the raw pre-check met a plaintext line: *first record does not look like a TLS handshake*. The pin was never the problem — the client that presents the token carries the same pinned configuration and verifies inside its own handshake, so the one-time secret still leaves only after the certificate has been checked. The raw dial stays as what its tests always proved and is no longer a path anything takes. **And the token says which bus it is for.** Empty meant *whatever the mesh runs today*, true while two buses existed and a refusal the moment one did. A first node now gets as far as asking to join, and is refused by the bus's user list — the fourth fault, which is genesis work and not a patch. It is written up in the issue's diagnosis.
jschoubben added 1 commit 2026-09-29 13:43:13 +00:00
novox/hq 04-ISSUES/146. Each was right while the mesh ran on the previous
broker, and nothing has raised a foundation since it changed.

The bus's certificate is made by the program that needs it rather than by
openssl inside the broker's image — the bus's image is Alpine with a shell and
no openssl, so the step exited 127 and no mesh could be raised. Self-signed as
before and on purpose; --user 0:0 because the volume is root's and the control
plane's image runs as nobody.

Enrolment no longer opens a raw TLS connection to check the pin: NATS speaks
its own protocol and upgrades afterwards, so the handshake met a plaintext
greeting. The client that presents the token carries the same pinned config
and verifies inside its own handshake, so the secret still leaves only after
the certificate is checked. The raw dial stays as what its tests prove, and is
no longer a path anything takes.

And the token says which bus it is for. Empty meant 'whatever the mesh runs
today' while two buses existed and became a refusal the moment one did.

It now stops at the bus's user list, which is the genesis half of 146.
jschoubben merged commit a3b810f1f0 into main 2026-09-29 14:06:34 +00:00
jschoubben deleted branch fix/one-foundation-on-the-bus-the-mesh-runs-on 2026-09-29 14:06:34 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#50