Prove a machine joins through the tunnel with the bus closed to it (hq ADR 0169) #61

Merged
mesh-admin merged 6 commits from feat/a-machine-joins-through-the-tunnel into main 2026-10-08 08:24:17 +00:00
Contributor

The lab's row of novox/hq ADR 0169's table: a new machine joins from outside the hub's network with the bus closed to it. Merge third, after novox/mesh-controller#132 and novox/mesh-host#52 (same branch name, one group).

  • New bed joins-through-the-tunnel (anchor + joiner): the anchor raises the foundation from the NATS bundle, joins on loopback, is placed as hub and given mesh-wireguard; the joiner makes its key, is issued a token for it (the test reads the token: issued for that key, hub endpoint, bus not at a public address), enrols, and shakes hands with the hub — with the bus's published port 5671 dropped from the joiner's own address at prerouting. The hub's udp port is opened by hand (scenery; the derived filter is the two-node walk's).
  • The earlier commits' extra test in mesh.test.ts moved into this bed; it dropped port 4222, which the bundle does not publish, so it closed nothing.
  • MESH_LAB_UPLINK_V4 names the uplink's range: behind a VPN client that routes 10/8 and 172.16/12, incus could pick none and no scenario could be raised.

Rebased onto main (17 behind, clean).

Run 2026-10-08 with the branches' controller image and host: both tests pass (MESH_LAB_UPLINK_V4=192.168.231.1/24). Instance destroyed after.

Not run: the two-node walk (mesh.test.ts) these older commits adapt. It stocks mesh-runtime-nftables:development, which scripts/build-module-runtime.sh can no longer build (mesh-tools has no npm package any more), and its builder step still dials an AMQP broker. The two failing unit tests (listing instances/networks fails rather than reporting none) fail on main the same way on this machine.

The lab's row of novox/hq ADR 0169's table: *a new machine joins from outside the hub's network with the bus closed to it*. **Merge third**, after novox/mesh-controller#132 and novox/mesh-host#52 (same branch name, one group). - New bed `joins-through-the-tunnel` (anchor + joiner): the anchor raises the foundation from the NATS bundle, joins on loopback, is placed as hub and given `mesh-wireguard`; the joiner makes its key, is issued a token for it (the test reads the token: issued for that key, hub endpoint, bus **not** at a public address), enrols, and shakes hands with the hub — with the bus's published port **5671** dropped from the joiner's own address at prerouting. The hub's udp port is opened by hand (scenery; the derived filter is the two-node walk's). - The earlier commits' extra test in `mesh.test.ts` moved into this bed; it dropped port 4222, which the bundle does not publish, so it closed nothing. - `MESH_LAB_UPLINK_V4` names the uplink's range: behind a VPN client that routes 10/8 and 172.16/12, incus could pick none and no scenario could be raised. Rebased onto main (17 behind, clean). **Run 2026-10-08** with the branches' controller image and host: both tests pass (`MESH_LAB_UPLINK_V4=192.168.231.1/24`). Instance destroyed after. **Not run:** the two-node walk (`mesh.test.ts`) these older commits adapt. It stocks `mesh-runtime-nftables:development`, which `scripts/build-module-runtime.sh` can no longer build (mesh-tools has no npm package any more), and its builder step still dials an AMQP broker. The two failing unit tests (`listing instances/networks fails rather than reporting none`) fail on main the same way on this machine.
mesh-admin added 6 commits 2026-10-07 23:56:55 +00:00
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
A token carries the bus's address, and at genesis that is the anchor's
loopback, which no other machine reaches. The anchor joins locally and
becomes the hub; the laptop makes its tunnel key, is issued a token for
it and joins over the tunnel (novox/hq ADR 0169, issue 146).
The filter module now serves its verbs from a runtime the mesh builds
(novox/hq ADR 0170), and a bed registered its raw manifest, which the
mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the
filter helper registers the module through the stocked image.
Prove a machine joins through the tunnel in a bed of its own
mesh/delivery delivered
mesh/delivery-group group feat/a-machine-joins-through-the-tunnel delivered: every member is delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
e80a4b1642
Two machines: the anchor raises the foundation, joins over its own
loopback and becomes the hub; the joiner makes its tunnel key, is issued
a token for it and enrols with the bus's port closed to its own address,
so the enrolment can arrive only over the tunnel (novox/hq ADR 0169). The
check that had been added to the two-node walk moves here, closing the
port the bundle publishes the bus on rather than the bus's own.

And the uplink's range may be named: behind a VPN client that routes
every private range, incus had none left to pick and no scenario could
be raised.
Author
Contributor

Delivery novox/mesh-lab@e80a4b1642bf — delivered since 2026-10-08T08:24:53Z

Delivery plan — builds nothing: the change touches no module of the mesh's graph

Group feat/a-machine-joins-through-the-tunnel, in order: novox/mesh-lab@e80a4b1642

Transitions

  • 2026-10-07 23:57 (new) → proposed (announced): novox/mesh-lab#61's head announced
  • 2026-10-07 23:58 proposed → checked (checked): the verdict names this commit
  • 2026-10-07 23:58 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
  • 2026-10-08 08:24 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
  • 2026-10-08 08:24 published → delivered (done): nothing for a walk to move

The commit's note under refs/notes/mesh-plan keeps every transition: git log --notes=mesh-plan.

<!-- mesh-delivery:view --> **Delivery** `novox/mesh-lab@e80a4b1642bf` — **delivered** since 2026-10-08T08:24:53Z **Delivery plan** — builds nothing: the change touches no module of the mesh's graph **Group** `feat/a-machine-joins-through-the-tunnel`, in order: novox/mesh-lab@e80a4b1642bf - novox/mesh-controller@8bbfdb53db2b before novox/mesh-host@86cbebd10f8a: built by - novox/mesh-host@86cbebd10f8a before novox/mesh-controller@8bbfdb53db2b: engine before controller **Transitions** - 2026-10-07 23:57 (new) → proposed (announced): novox/mesh-lab#61's head announced - 2026-10-07 23:58 proposed → checked (checked): the verdict names this commit - 2026-10-07 23:58 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail - 2026-10-08 08:24 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move - 2026-10-08 08:24 published → delivered (done): nothing for a walk to move The commit's note under `refs/notes/mesh-plan` keeps every transition: `git log --notes=mesh-plan`.
mesh-admin merged commit 20bdf96b31 into main 2026-10-08 08:24:17 +00:00
mesh-admin deleted branch feat/a-machine-joins-through-the-tunnel 2026-10-08 08:24:18 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-lab#61