docs(handoff): app direct ports are IPv4-only over the mesh — node-side task #112

Closed
lfg2025 wants to merge 1 commits from docs/mesh-app-ports-handoff into main

View File

@ -142,3 +142,29 @@ Chain of findings, each verified live:
slow, it's failing outright. The private-tree option (detach fleet from slow, it's failing outright. The private-tree option (detach fleet from
the public v0l mesh, root at vps2) looks like the real fix; app-side the public v0l mesh, root at vps2) looks like the real fix; app-side
patience only helps once discovery succeeds at all. patience only helps once discovery succeeds at all.
## NEXT (00:00, Mac agent → dev-box agent): app ports are IPv4-only over the mesh
The kiosk now loads over the ULA — but opening any APP dies with
`ERR_CONNECTION_REFUSED` on `http://[<ULA>]:<port>/` (user-verified with
:8334, and it will be every app). Cause is the same class as the :80 nginx
bug you fixed: the web UI builds app URLs from the current host + the app's
DIRECT port (Direct Port Rule), so over the mesh that's `[ULA]:8334` — but
container-published ports only bind 0.0.0.0 (verified: `192.168.63.249:8334`
→ HTTP 200, ULA:8334 → refused).
Fix needs to cover EVERY catalog app port and survive app install/remove.
Two shapes; pick what fits the container layer best:
1. **IPv6 publish at the container layer** — publish ports on `[::]` too
(pasta/rootless podman support address-specific `-p` entries), wired into
the container manager so new apps get it automatically; or
2. **Host-side v6→v4 forwarders** — generated nginx `stream {}` (or
systemd-socket) blocks: `listen [::]:<port>``127.0.0.1:<port>`, one
per catalog app port, regenerated on app install/remove, self-healed at
boot like your :80 fix. Keeps the Direct Port Rule URL contract intact
without touching containers.
Whichever you choose, please also extend your bootstrap self-heal to cover
it, and verify from the mesh side (curl the ULA on 23 app ports from vps2
or the phone) — not just from the LAN.