Skip to content

Isolated applications are admitted when no SNI route can reach them (no host, or a host shared by urlPath) #2757

Description

@kriszyp

Problem

An isolated application (feat(threads): run an isolated application in a dedicated worker thread) is reachable only through its own UDS mirror, sockets/app-<name>-<port>.sock. Its dedicated worker binds no shared port, and pool workers never load it. A fronting proxy (symphony) routes to that socket by TLS SNI, using the applicationHosts list the worker publishes in app-<name>-<port>.yaml. That list comes from the app's root-config host (isolatedApplicationRoute(), server/threads/isolatedApplications.ts:150).

Admission (isolatedApplicationRefusal(), isolatedApplications.ts:123) checks thread count, http.securePort, tls.unixDomainSockets and socket path length, but not whether the app can be routed to. Two configurations are admitted and then fail silently:

# Config Result
a isolated: true with no host (with or without urlPath) Publishes applicationHosts: []. No SNI routes to the socket, so the app loads and reports healthy while no request can reach it.
b isolated: true with a host another application also mounts, the two split only by urlPath SNI cannot separate the two apps. If the other app is also isolated, the proxy has no correct target: host-manager falls back to the shared pool, where neither app is loaded. If the other app is not isolated, the proxy sends the whole host to the isolated worker, and the other app becomes unreachable on that host.

Neither case logs anything on the Harper side.

Expected

Refuse these at admission, the same way isolatedApplicationRefusal() already fails closed for an unreachable worker:

  • isolated: true requires a host.
  • An isolated app's host must not be mounted by any other application, isolated or not. A urlPath split cannot be routed by SNI.

Alternative for (b): relax the rule once the proxy can route by path, e.g. an HTTP-aware hop. That is not planned; refusal is the correct behavior until then.

Context

Activity

  1. added theissue type on Sep 22, 2026
  2. added this to the v5.3 milestone on Sep 22, 2026
  3. modified the milestones: v5.3, v5.4 on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    P2

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions