The lab's row of novox/hq ADR 0169's table: a new machine joins from outside the hub's network with the bus closed to it. Merge third, after novox/mesh-controller#132 and novox/mesh-host#52 (same branch name, one group).
New bed joins-through-the-tunnel (anchor + joiner): the anchor raises the foundation from the NATS bundle, joins on loopback, is placed as hub and given mesh-wireguard; the joiner makes its key, is issued a token for it (the test reads the token: issued for that key, hub endpoint, bus not at a public address), enrols, and shakes hands with the hub — with the bus's published port 5671 dropped from the joiner's own address at prerouting. The hub's udp port is opened by hand (scenery; the derived filter is the two-node walk's).
The earlier commits' extra test in mesh.test.ts moved into this bed; it dropped port 4222, which the bundle does not publish, so it closed nothing.
MESH_LAB_UPLINK_V4 names the uplink's range: behind a VPN client that routes 10/8 and 172.16/12, incus could pick none and no scenario could be raised.
Rebased onto main (17 behind, clean).
Run 2026-10-08 with the branches' controller image and host: both tests pass (MESH_LAB_UPLINK_V4=192.168.231.1/24). Instance destroyed after.
Not run: the two-node walk (mesh.test.ts) these older commits adapt. It stocks mesh-runtime-nftables:development, which scripts/build-module-runtime.sh can no longer build (mesh-tools has no npm package any more), and its builder step still dials an AMQP broker. The two failing unit tests (listing instances/networks fails rather than reporting none) fail on main the same way on this machine.
The lab's row of novox/hq ADR 0169's table: *a new machine joins from outside the hub's network with the bus closed to it*. **Merge third**, after novox/mesh-controller#132 and novox/mesh-host#52 (same branch name, one group).
- New bed `joins-through-the-tunnel` (anchor + joiner): the anchor raises the foundation from the NATS bundle, joins on loopback, is placed as hub and given `mesh-wireguard`; the joiner makes its key, is issued a token for it (the test reads the token: issued for that key, hub endpoint, bus **not** at a public address), enrols, and shakes hands with the hub — with the bus's published port **5671** dropped from the joiner's own address at prerouting. The hub's udp port is opened by hand (scenery; the derived filter is the two-node walk's).
- The earlier commits' extra test in `mesh.test.ts` moved into this bed; it dropped port 4222, which the bundle does not publish, so it closed nothing.
- `MESH_LAB_UPLINK_V4` names the uplink's range: behind a VPN client that routes 10/8 and 172.16/12, incus could pick none and no scenario could be raised.
Rebased onto main (17 behind, clean).
**Run 2026-10-08** with the branches' controller image and host: both tests pass (`MESH_LAB_UPLINK_V4=192.168.231.1/24`). Instance destroyed after.
**Not run:** the two-node walk (`mesh.test.ts`) these older commits adapt. It stocks `mesh-runtime-nftables:development`, which `scripts/build-module-runtime.sh` can no longer build (mesh-tools has no npm package any more), and its builder step still dials an AMQP broker. The two failing unit tests (`listing instances/networks fails rather than reporting none`) fail on main the same way on this machine.
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
A token carries the bus's address, and at genesis that is the anchor's
loopback, which no other machine reaches. The anchor joins locally and
becomes the hub; the laptop makes its tunnel key, is issued a token for
it and joins over the tunnel (novox/hq ADR 0169, issue 146).
The filter module now serves its verbs from a runtime the mesh builds
(novox/hq ADR 0170), and a bed registered its raw manifest, which the
mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the
filter helper registers the module through the stocked image.
Two machines: the anchor raises the foundation, joins over its own
loopback and becomes the hub; the joiner makes its tunnel key, is issued
a token for it and enrols with the bus's port closed to its own address,
so the enrolment can arrive only over the tunnel (novox/hq ADR 0169). The
check that had been added to the two-node walk moves here, closing the
port the bundle publishes the bus on rather than the bus's own.
And the uplink's range may be named: behind a VPN client that routes
every private range, incus had none left to pick and no scenario could
be raised.
2026-10-07 23:57 (new) → proposed (announced): novox/mesh-lab#61's head announced
2026-10-07 23:58 proposed → checked (checked): the verdict names this commit
2026-10-07 23:58 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
2026-10-08 08:24 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
2026-10-08 08:24 published → delivered (done): nothing for a walk to move
The commit's note under refs/notes/mesh-plan keeps every transition: git log --notes=mesh-plan.
<!-- mesh-delivery:view -->
**Delivery** `novox/mesh-lab@e80a4b1642bf` — **delivered** since 2026-10-08T08:24:53Z
**Delivery plan** — builds nothing: the change touches no module of the mesh's graph
**Group** `feat/a-machine-joins-through-the-tunnel`, in order: novox/mesh-lab@e80a4b1642bf
- novox/mesh-controller@8bbfdb53db2b before novox/mesh-host@86cbebd10f8a: built by
- novox/mesh-host@86cbebd10f8a before novox/mesh-controller@8bbfdb53db2b: engine before controller
**Transitions**
- 2026-10-07 23:57 (new) → proposed (announced): novox/mesh-lab#61's head announced
- 2026-10-07 23:58 proposed → checked (checked): the verdict names this commit
- 2026-10-07 23:58 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
- 2026-10-08 08:24 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
- 2026-10-08 08:24 published → delivered (done): nothing for a walk to move
The commit's note under `refs/notes/mesh-plan` keeps every transition: `git log --notes=mesh-plan`.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The lab's row of novox/hq ADR 0169's table: a new machine joins from outside the hub's network with the bus closed to it. Merge third, after novox/mesh-controller#132 and novox/mesh-host#52 (same branch name, one group).
joins-through-the-tunnel(anchor + joiner): the anchor raises the foundation from the NATS bundle, joins on loopback, is placed as hub and givenmesh-wireguard; the joiner makes its key, is issued a token for it (the test reads the token: issued for that key, hub endpoint, bus not at a public address), enrols, and shakes hands with the hub — with the bus's published port 5671 dropped from the joiner's own address at prerouting. The hub's udp port is opened by hand (scenery; the derived filter is the two-node walk's).mesh.test.tsmoved into this bed; it dropped port 4222, which the bundle does not publish, so it closed nothing.MESH_LAB_UPLINK_V4names the uplink's range: behind a VPN client that routes 10/8 and 172.16/12, incus could pick none and no scenario could be raised.Rebased onto main (17 behind, clean).
Run 2026-10-08 with the branches' controller image and host: both tests pass (
MESH_LAB_UPLINK_V4=192.168.231.1/24). Instance destroyed after.Not run: the two-node walk (
mesh.test.ts) these older commits adapt. It stocksmesh-runtime-nftables:development, whichscripts/build-module-runtime.shcan no longer build (mesh-tools has no npm package any more), and its builder step still dials an AMQP broker. The two failing unit tests (listing instances/networks fails rather than reporting none) fail on main the same way on this machine.Delivery
novox/mesh-lab@e80a4b1642bf— delivered since 2026-10-08T08:24:53ZDelivery plan — builds nothing: the change touches no module of the mesh's graph
Group
feat/a-machine-joins-through-the-tunnel, in order: novox/mesh-lab@e80a4b1642Transitions
The commit's note under
refs/notes/mesh-plankeeps every transition:git log --notes=mesh-plan.