docs(handoff): app direct ports are IPv4-only over the mesh — node-side task #112
@ -142,3 +142,29 @@ Chain of findings, each verified live:
|
|||||||
slow, it's failing outright. The private-tree option (detach fleet from
|
slow, it's failing outright. The private-tree option (detach fleet from
|
||||||
the public v0l mesh, root at vps2) looks like the real fix; app-side
|
the public v0l mesh, root at vps2) looks like the real fix; app-side
|
||||||
patience only helps once discovery succeeds at all.
|
patience only helps once discovery succeeds at all.
|
||||||
|
|
||||||
|
## NEXT (00:00, Mac agent → dev-box agent): app ports are IPv4-only over the mesh
|
||||||
|
|
||||||
|
The kiosk now loads over the ULA — but opening any APP dies with
|
||||||
|
`ERR_CONNECTION_REFUSED` on `http://[<ULA>]:<port>/` (user-verified with
|
||||||
|
:8334, and it will be every app). Cause is the same class as the :80 nginx
|
||||||
|
bug you fixed: the web UI builds app URLs from the current host + the app's
|
||||||
|
DIRECT port (Direct Port Rule), so over the mesh that's `[ULA]:8334` — but
|
||||||
|
container-published ports only bind 0.0.0.0 (verified: `192.168.63.249:8334`
|
||||||
|
→ HTTP 200, ULA:8334 → refused).
|
||||||
|
|
||||||
|
Fix needs to cover EVERY catalog app port and survive app install/remove.
|
||||||
|
Two shapes; pick what fits the container layer best:
|
||||||
|
|
||||||
|
1. **IPv6 publish at the container layer** — publish ports on `[::]` too
|
||||||
|
(pasta/rootless podman support address-specific `-p` entries), wired into
|
||||||
|
the container manager so new apps get it automatically; or
|
||||||
|
2. **Host-side v6→v4 forwarders** — generated nginx `stream {}` (or
|
||||||
|
systemd-socket) blocks: `listen [::]:<port>` → `127.0.0.1:<port>`, one
|
||||||
|
per catalog app port, regenerated on app install/remove, self-healed at
|
||||||
|
boot like your :80 fix. Keeps the Direct Port Rule URL contract intact
|
||||||
|
without touching containers.
|
||||||
|
|
||||||
|
Whichever you choose, please also extend your bootstrap self-heal to cover
|
||||||
|
it, and verify from the mesh side (curl the ULA on 2–3 app ports from vps2
|
||||||
|
or the phone) — not just from the LAN.
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user