Add route-forwarding lab bed proving the route grant end to end

A scenario and integration test assign route-proxy (provider) and hello-web
(consumer) on one node, then assert a request to the consumer's name -- sent to
the proxy -- is forwarded to the workload and returns its answer, and that
unassigning the consumer withdraws the route so the same request stops working
(the proxy replaces its table rather than merging). Modeled on
mesh-grant-end-to-end and schedule-tick: module add, assign, one push, settled,
with no module issue (route-proxy needs no scoped account).

build-route-proxy-image.sh compiles the Go proxy from
mesh-control/examples/route-proxy into mesh-route-proxy:development for the
scenario to stock. This bed proves route-forwarding over plain HTTP;
public-ACME TLS is proven separately by certificates.test.ts against a real
ACME server.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-06 15:07:23 +02:00
parent b75ec7782d
commit f03647d605
3 changed files with 362 additions and 0 deletions
+28
View File
@@ -0,0 +1,28 @@
#!/usr/bin/env bash
# Build the route-proxy module's runtime image: the reference reverse proxy (novox/hq
# 08-connectivity §3), compiled from its canonical Go source in mesh-control into a container the
# lab can stock and serve by digest.
#
# Unlike the TypeScript modules (built by build-module-runtime.sh into a node tool runtime), the
# proxy is a Go program. The module ships only the packaging — a Dockerfile in mesh-catalog whose
# build context is the mesh-control repository root — and this script runs that build into the local
# docker daemon, which a scenario's registry then stocks and serves by digest.
#
# build-route-proxy-image.sh
# -> tags mesh-route-proxy:development in the local daemon
set -euo pipefail
HERE="$(cd "$(dirname "$0")/.." && pwd)"; ROOT="$(cd "$HERE/.." && pwd)"
MESH_CONTROL="${MESH_CONTROL:-$ROOT/mesh-control}"
MESH_CATALOG="${MESH_CATALOG:-$ROOT/mesh-catalog}"
TAG="${ROUTE_PROXY_TAG:-mesh-route-proxy:development}"
DOCKERFILE="$MESH_CATALOG/modules/route-proxy/Dockerfile"
[ -f "$DOCKERFILE" ] || { echo "no Dockerfile at $DOCKERFILE" >&2; exit 1; }
[ -f "$MESH_CONTROL/examples/route-proxy/main.go" ] || {
echo "no proxy source at $MESH_CONTROL/examples/route-proxy" >&2; exit 1; }
# Context is the mesh-control repository root: the proxy compiles against that module's go.mod and
# its examples/route-proxy package.
docker build -f "$DOCKERFILE" -t "$TAG" "$MESH_CONTROL"
echo "built $TAG (from $MESH_CONTROL/examples/route-proxy)"