The routing record is 0066, not 0056
0056 was already 'the authority is the control plane, not a database'. The routing record was renumbered where it lives; these citations pointed at the wrong decision, which is worse than pointing at none. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -66,7 +66,7 @@ const NODES = ["novox", "ace", "shanks", "g14"];
|
||||
const HOME_NODES = ["ace", "shanks", "g14"];
|
||||
|
||||
/**
|
||||
* ADR 0056 — the domain each public-facing node composes its routed names under.
|
||||
* ADR 0066 — the domain each public-facing node composes its routed names under.
|
||||
*
|
||||
* **The bed had none, so the ADR was untested by construction.** A module now contributes a `label`
|
||||
* to `route` and nothing else; the mesh joins it to the node's public domain and the join is the
|
||||
@@ -110,7 +110,7 @@ const NOVOX: Mod[] = [
|
||||
{ name: "mongodb", containers: ["mongo", "mesh-mongodb"] },
|
||||
{ name: "mssql", containers: ["mssql", "mesh-mssql"] },
|
||||
{ name: "lavinmq", containers: ["lavinmq", "mesh-lavinmq"] },
|
||||
// ADR 0056: the proxy now REQUIRES an `acme-ca`, so the bed must assign a provider of one or
|
||||
// ADR 0066: the proxy now REQUIRES an `acme-ca`, so the bed must assign a provider of one or
|
||||
// route-proxy is unresolvable and takes every routed module down with it. step-ca is that
|
||||
// provider, on the anchor, at mesh scope.
|
||||
{ name: "step-ca", containers: ["step-ca"] },
|
||||
@@ -148,7 +148,7 @@ const GAPS_NOVOX = new Set([
|
||||
"umami", "mailu", "firewall", "fail2ban", "only-office", "de-spiegel", "amqp-email-forwarder",
|
||||
// step-ca is reported, not gated: the internal-CA ISSUANCE path is still being fixed in
|
||||
// mesh-control, and this bed is not the place to discover that a fix has not landed yet. What is
|
||||
// gated is the half that is decided and cheap — see the ADR 0056 section at the end.
|
||||
// gated is the half that is decided and cheap — see the ADR 0066 section at the end.
|
||||
"step-ca",
|
||||
]);
|
||||
|
||||
@@ -339,7 +339,7 @@ async function psMapOf(node: string): Promise<Map<string, string>> {
|
||||
}
|
||||
|
||||
/**
|
||||
* ADR 0056: the internal CA is initialised FROM AN OPERATOR'S ROOT — it does not mint its own.
|
||||
* ADR 0066: the internal CA is initialised FROM AN OPERATOR'S ROOT — it does not mint its own.
|
||||
*
|
||||
* So the bed has to be an operator. The material is made on the anchor with openssl and handed to
|
||||
* the mesh through the real `secret accept` path, exactly as a person would: the mesh cannot invent
|
||||
@@ -464,7 +464,7 @@ before(async () => {
|
||||
// home→public works. novox enrols too: substrate host and service node at once.
|
||||
for (const machine of NODES) {
|
||||
await mesh(`node add ${machine}`);
|
||||
// ADR 0056: said as soon as the record exists, because everything routed is composed from it.
|
||||
// ADR 0066: said as soon as the record exists, because everything routed is composed from it.
|
||||
// A node that faces the outside has one; the workstations do not, and are given none.
|
||||
const domain = PUBLIC_DOMAIN[machine];
|
||||
if (domain) await mesh(`node public-domain ${machine} ${domain}`);
|
||||
@@ -612,9 +612,9 @@ test("the full mesh forms across the access point and both server sets converge"
|
||||
}
|
||||
}
|
||||
|
||||
// ADR 0056: the CA's root, before the push that would otherwise deliver a random 32 bytes for it.
|
||||
// ADR 0066: the CA's root, before the push that would otherwise deliver a random 32 bytes for it.
|
||||
const caRootDelivered = assigned["novox"]!.has("step-ca") ? await deliverCaRoot() : false;
|
||||
if (!caRootDelivered) console.log("ADR 0056: no operator root delivered; step-ca cannot initialise.");
|
||||
if (!caRootDelivered) console.log("ADR 0066: no operator root delivered; step-ca cannot initialise.");
|
||||
|
||||
// ONE push per node (workstations first — cheap — then the heavy service nodes).
|
||||
const pushError: Record<string, string> = {};
|
||||
@@ -706,7 +706,7 @@ test("the full mesh forms across the access point and both server sets converge"
|
||||
}
|
||||
|
||||
// ================================================================================================
|
||||
// ADR 0056 — ROUTE NAMES AND THE INTERNAL CA. Additive, and deliberately only the cheap half.
|
||||
// ADR 0066 — ROUTE NAMES AND THE INTERNAL CA. Additive, and deliberately only the cheap half.
|
||||
//
|
||||
// What is checked here is the part that is DECIDED and costs one file read: a module contributes a
|
||||
// LABEL, the node carries a PUBLIC DOMAIN, and the mesh joins them — `<label>.<public-domain>`,
|
||||
@@ -717,7 +717,7 @@ test("the full mesh forms across the access point and both server sets converge"
|
||||
// step-ca over ACME. That path is being fixed in mesh-control as this is written, and a bed that
|
||||
// gated on it would be reporting somebody else's in-flight work as this bed's failure.
|
||||
// ================================================================================================
|
||||
const adr: string[] = ["================ ADR 0056: LABELLED ROUTES ================"];
|
||||
const adr: string[] = ["================ ADR 0066: LABELLED ROUTES ================"];
|
||||
|
||||
const wanted: { node: string; module: string; label: string; name: string }[] = [];
|
||||
for (const { node, mods } of PLAN) {
|
||||
@@ -764,7 +764,7 @@ test("the full mesh forms across the access point and both server sets converge"
|
||||
`the overlay did NOT form across the access point — no home node could reach novox over the overlay:\n${overlaySummary}`);
|
||||
|
||||
if (!KEEP) {
|
||||
// ADR 0056, the cheap half. Reported on a KEEP run like everything else there.
|
||||
// ADR 0066, the cheap half. Reported on a KEEP run like everything else there.
|
||||
assert.deepEqual(missing, [],
|
||||
`these routed modules composed no name — a label with no public domain to join it to is a ` +
|
||||
`module nothing can reach, and it fails silently:\n${adr.join("\n")}\n\nroutes file:\n${routesFile}`);
|
||||
|
||||
Reference in New Issue
Block a user