Files
mesh-lab/scenarios/two-nodes.yml
T
jschoubben 47d990b33a Prove a route reaches the workload, and does not outlive it
The request goes to the name, across the private network, and returns the
workload's own answer. Then the module is unassigned and the same request must
stop working — a stale public name pointing at nothing fails more visibly than
a stale grant.

The workload declares its port as well as its route, because they are different
questions and the earlier test leaves this machine filtering: a module that
asked for a route and not for the port would be unreachable by the proxy it
just asked for.
2026-08-31 02:43:19 +02:00

42 lines
1.5 KiB
YAML

# Two machines, one mesh.
#
# The first raises everything from the bundle its host carries and joins the mesh it made. The
# second is an ordinary node: it has a host and nothing else, and a person carries it a token.
#
# This is the first scenario where the mesh is a mesh. Everything before it proved a machine could
# talk to a control plane on its own loopback, which proves less than it looks.
scenario: two-nodes
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
inbound: allow
laptop:
at: { segment: hosting, address: [192.0.2.20] }
inbound: allow
images:
- postgres:17-alpine
- cloudamqp/lavinmq:latest
- mesh-control:development
# So a module can mirror one into a registry of the mesh's own. The scenario's registry serves
# what the mesh's registry is built from — the same chicken-and-egg the bootstrap has, resolved
# the same way.
- registry:2
# And the builder, because it is a module the mesh assigns rather than a program somebody
# starts by hand — which is the only way its credential can be one the mesh delivered.
- mesh-builder:development
# And the provisioner, which is what makes a sealed credential true on a machine — the mesh
# discarded the plaintext and cannot tell a database to start accepting it.
- mesh-provision-postgres:development
# And the proxy, which is what turns a route grant into traffic actually arriving.
- mesh-route-proxy:development
place:
all: [host, runtime]