Brandon Schneider
|
4cce98115c
|
feat(infra): migrate external service registry to aiven mysql with ssl
- Migrated service_registry.py defaults from InfinityFree to Aiven MySQL.
- Enforced REQUIRED SSL mode on connections (ssl_mode for mysql-connector, ssl dict for pymysql).
- Added helper _get_dict_cursor to resolve pymysql compatibility issues.
- Configured registry password and encryption key in decrypted/encrypted .env via SOPS.
Build: 3313 jobs, 0 errors (lake build)
|
2026-05-31 02:10:10 -05:00 |
|
Brandon Schneider
|
a308afeb03
|
fix(infra): service registry is backup/fallback, not primary
Primary: Tailscale mesh + internal PostgreSQL/SQLite
Backup: InfinityFree MySQL (this file)
Use cases for backup path:
- Edge nodes that cant reach mesh (ESP32, Cloudflare Workers)
- Mesh-down fallback (Tailscale outage)
- Cross-mesh discovery (different tailnets)
- Low-impact config distribution
|
2026-05-30 21:19:24 -05:00 |
|
Brandon Schneider
|
a84709fe7f
|
feat(infra): external service registry via InfinityFree MySQL
service_registry.py — mesh-independent node discovery and credential store.
Tables:
nodes — registered devices with capabilities, tier, IPs
credentials — encrypted blobs (ChaCha20) with TTL auto-expiry
config — distributed key-value configuration
Features:
- auto_register() — uses device_capability_probe to register
- discover_nodes() — find nodes by tier, with max-age filter
- store/get_credential() — encrypted at rest, short TTL
- heartbeat() — keepalive for node registry
- CLI: init, register, discover, store, get, cleanup, config-set/get
Any node with internet can reach it (no Tailscale required).
Credentials encrypted with ChaCha20, key from REGISTRY_ENCRYPT_KEY env.
|
2026-05-30 21:14:51 -05:00 |
|