Prove a route reaches the workload, and does not outlive it

The request goes to the name, across the private network, and returns the
workload's own answer. Then the module is unassigned and the same request must
stop working — a stale public name pointing at nothing fails more visibly than
a stale grant.

The workload declares its port as well as its route, because they are different
questions and the earlier test leaves this machine filtering: a module that
asked for a route and not for the port would be unreachable by the proxy it
just asked for.
This commit is contained in:
2026-08-31 02:43:19 +02:00
parent 21a1e85d32
commit 47d990b33a
2 changed files with 88 additions and 0 deletions
+2
View File
@@ -34,6 +34,8 @@ images:
# And the provisioner, which is what makes a sealed credential true on a machine — the mesh
# discarded the plaintext and cannot tell a database to start accepting it.
- mesh-provision-postgres:development
# And the proxy, which is what turns a route grant into traffic actually arriving.
- mesh-route-proxy:development
place:
all: [host, runtime]