route-forwarding: prove the native ingress routes + withdraws (drop traefik) #12

Merged
jschoubben merged 2 commits from feat/route-proxy-bed into main 2026-09-06 13:17:24 +00:00
Owner

The route-grant lab proof: the mesh assigns the route-proxy provider and a hello-web consumer; a request with the consumer's Host header, sent to the proxy, is forwarded to the backend; an unrouted name gets the named refusal; and on unassign the route is withdrawn (the request stops working). This is 08-connectivity §3's "checked in the lab" pair. SUITE_EXIT=0. Public-ACME TLS is covered separately by the existing certificates.test.ts. Adds scripts/build-route-proxy-image.sh.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

The route-grant lab proof: the mesh assigns the `route-proxy` provider and a `hello-web` consumer; a request with the consumer's Host header, sent to the proxy, is forwarded to the backend; an unrouted name gets the named refusal; and on `unassign` the route is withdrawn (the request stops working). This is 08-connectivity §3's "checked in the lab" pair. **SUITE_EXIT=0.** Public-ACME TLS is covered separately by the existing `certificates.test.ts`. Adds `scripts/build-route-proxy-image.sh`. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 2 commits 2026-09-06 13:17:15 +00:00
A scenario and integration test assign route-proxy (provider) and hello-web
(consumer) on one node, then assert a request to the consumer's name -- sent to
the proxy -- is forwarded to the workload and returns its answer, and that
unassigning the consumer withdraws the route so the same request stops working
(the proxy replaces its table rather than merging). Modeled on
mesh-grant-end-to-end and schedule-tick: module add, assign, one push, settled,
with no module issue (route-proxy needs no scoped account).

build-route-proxy-image.sh compiles the Go proxy from
mesh-control/examples/route-proxy into mesh-route-proxy:development for the
scenario to stock. This bed proves route-forwarding over plain HTTP;
public-ACME TLS is proven separately by certificates.test.ts against a real
ACME server.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit b22a1716d6 into main 2026-09-06 13:17:24 +00:00
jschoubben deleted branch feat/route-proxy-bed 2026-09-06 13:17:25 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-lab#12