Delete the lab's registry, and bootstrap the anchor through the installer #19

Merged
jschoubben merged 14 commits from feat/bed-bootstraps-through-the-installer into main 2026-09-11 19:57:05 +00:00
Showing only changes of commit a4c2a9b90b - Show all commits
+10 -10
View File
@@ -66,7 +66,7 @@ const NODES = ["novox", "ace", "shanks", "g14"];
const HOME_NODES = ["ace", "shanks", "g14"];
/**
* ADR 0056 — the domain each public-facing node composes its routed names under.
* ADR 0066 — the domain each public-facing node composes its routed names under.
*
* **The bed had none, so the ADR was untested by construction.** A module now contributes a `label`
* to `route` and nothing else; the mesh joins it to the node's public domain and the join is the
@@ -110,7 +110,7 @@ const NOVOX: Mod[] = [
{ name: "mongodb", containers: ["mongo", "mesh-mongodb"] },
{ name: "mssql", containers: ["mssql", "mesh-mssql"] },
{ name: "lavinmq", containers: ["lavinmq", "mesh-lavinmq"] },
// ADR 0056: the proxy now REQUIRES an `acme-ca`, so the bed must assign a provider of one or
// ADR 0066: the proxy now REQUIRES an `acme-ca`, so the bed must assign a provider of one or
// route-proxy is unresolvable and takes every routed module down with it. step-ca is that
// provider, on the anchor, at mesh scope.
{ name: "step-ca", containers: ["step-ca"] },
@@ -148,7 +148,7 @@ const GAPS_NOVOX = new Set([
"umami", "mailu", "firewall", "fail2ban", "only-office", "de-spiegel", "amqp-email-forwarder",
// step-ca is reported, not gated: the internal-CA ISSUANCE path is still being fixed in
// mesh-control, and this bed is not the place to discover that a fix has not landed yet. What is
// gated is the half that is decided and cheap — see the ADR 0056 section at the end.
// gated is the half that is decided and cheap — see the ADR 0066 section at the end.
"step-ca",
]);
@@ -339,7 +339,7 @@ async function psMapOf(node: string): Promise<Map<string, string>> {
}
/**
* ADR 0056: the internal CA is initialised FROM AN OPERATOR'S ROOT — it does not mint its own.
* ADR 0066: the internal CA is initialised FROM AN OPERATOR'S ROOT — it does not mint its own.
*
* So the bed has to be an operator. The material is made on the anchor with openssl and handed to
* the mesh through the real `secret accept` path, exactly as a person would: the mesh cannot invent
@@ -464,7 +464,7 @@ before(async () => {
// home→public works. novox enrols too: substrate host and service node at once.
for (const machine of NODES) {
await mesh(`node add ${machine}`);
// ADR 0056: said as soon as the record exists, because everything routed is composed from it.
// ADR 0066: said as soon as the record exists, because everything routed is composed from it.
// A node that faces the outside has one; the workstations do not, and are given none.
const domain = PUBLIC_DOMAIN[machine];
if (domain) await mesh(`node public-domain ${machine} ${domain}`);
@@ -612,9 +612,9 @@ test("the full mesh forms across the access point and both server sets converge"
}
}
// ADR 0056: the CA's root, before the push that would otherwise deliver a random 32 bytes for it.
// ADR 0066: the CA's root, before the push that would otherwise deliver a random 32 bytes for it.
const caRootDelivered = assigned["novox"]!.has("step-ca") ? await deliverCaRoot() : false;
if (!caRootDelivered) console.log("ADR 0056: no operator root delivered; step-ca cannot initialise.");
if (!caRootDelivered) console.log("ADR 0066: no operator root delivered; step-ca cannot initialise.");
// ONE push per node (workstations first — cheap — then the heavy service nodes).
const pushError: Record<string, string> = {};
@@ -706,7 +706,7 @@ test("the full mesh forms across the access point and both server sets converge"
}
// ================================================================================================
// ADR 0056 — ROUTE NAMES AND THE INTERNAL CA. Additive, and deliberately only the cheap half.
// ADR 0066 — ROUTE NAMES AND THE INTERNAL CA. Additive, and deliberately only the cheap half.
//
// What is checked here is the part that is DECIDED and costs one file read: a module contributes a
// LABEL, the node carries a PUBLIC DOMAIN, and the mesh joins them — `<label>.<public-domain>`,
@@ -717,7 +717,7 @@ test("the full mesh forms across the access point and both server sets converge"
// step-ca over ACME. That path is being fixed in mesh-control as this is written, and a bed that
// gated on it would be reporting somebody else's in-flight work as this bed's failure.
// ================================================================================================
const adr: string[] = ["================ ADR 0056: LABELLED ROUTES ================"];
const adr: string[] = ["================ ADR 0066: LABELLED ROUTES ================"];
const wanted: { node: string; module: string; label: string; name: string }[] = [];
for (const { node, mods } of PLAN) {
@@ -764,7 +764,7 @@ test("the full mesh forms across the access point and both server sets converge"
`the overlay did NOT form across the access point — no home node could reach novox over the overlay:\n${overlaySummary}`);
if (!KEEP) {
// ADR 0056, the cheap half. Reported on a KEEP run like everything else there.
// ADR 0066, the cheap half. Reported on a KEEP run like everything else there.
assert.deepEqual(missing, [],
`these routed modules composed no name — a label with no public domain to join it to is a ` +
`module nothing can reach, and it fails silently:\n${adr.join("\n")}\n\nroutes file:\n${routesFile}`);