Problem
An isolated application (feat(threads): run an isolated application in a dedicated worker thread) is reachable only through its own UDS mirror, sockets/app-<name>-<port>.sock. Its dedicated worker binds no shared port, and pool workers never load it. A fronting proxy (symphony) routes to that socket by TLS SNI, using the applicationHosts list the worker publishes in app-<name>-<port>.yaml. That list comes from the app's root-config host (isolatedApplicationRoute(), server/threads/isolatedApplications.ts:150).
Admission (isolatedApplicationRefusal(), isolatedApplications.ts:123) checks thread count, http.securePort, tls.unixDomainSockets and socket path length, but not whether the app can be routed to. Two configurations are admitted and then fail silently:
| # |
Config |
Result |
| a |
isolated: true with no host (with or without urlPath) |
Publishes applicationHosts: []. No SNI routes to the socket, so the app loads and reports healthy while no request can reach it. |
| b |
isolated: true with a host another application also mounts, the two split only by urlPath |
SNI cannot separate the two apps. If the other app is also isolated, the proxy has no correct target: host-manager falls back to the shared pool, where neither app is loaded. If the other app is not isolated, the proxy sends the whole host to the isolated worker, and the other app becomes unreachable on that host. |
Neither case logs anything on the Harper side.
Expected
Refuse these at admission, the same way isolatedApplicationRefusal() already fails closed for an unreachable worker:
isolated: true requires a host.
- An isolated app's
host must not be mounted by any other application, isolated or not. A urlPath split cannot be routed by SNI.
Alternative for (b): relax the rule once the proxy can route by path, e.g. an HTTP-aware hop. That is not planned; refusal is the correct behavior until then.
Context
Problem
An isolated application (feat(threads): run an isolated application in a dedicated worker thread) is reachable only through its own UDS mirror,
sockets/app-<name>-<port>.sock. Its dedicated worker binds no shared port, and pool workers never load it. A fronting proxy (symphony) routes to that socket by TLS SNI, using theapplicationHostslist the worker publishes inapp-<name>-<port>.yaml. That list comes from the app's root-confighost(isolatedApplicationRoute(),server/threads/isolatedApplications.ts:150).Admission (
isolatedApplicationRefusal(),isolatedApplications.ts:123) checks thread count,http.securePort,tls.unixDomainSocketsand socket path length, but not whether the app can be routed to. Two configurations are admitted and then fail silently:isolated: truewith nohost(with or withouturlPath)applicationHosts: []. No SNI routes to the socket, so the app loads and reports healthy while no request can reach it.isolated: truewith ahostanother application also mounts, the two split only byurlPathNeither case logs anything on the Harper side.
Expected
Refuse these at admission, the same way
isolatedApplicationRefusal()already fails closed for an unreachable worker:isolated: truerequires ahost.hostmust not be mounted by any other application, isolated or not. AurlPathsplit cannot be routed by SNI.Alternative for (b): relax the rule once the proxy can route by path, e.g. an HTTP-aware hop. That is not planned; refusal is the correct behavior until then.
Context
applicationHoststo the dedicated socket, falls back to the pool on a host two apps list): Route an isolated Harper application's host to its dedicated worker socket.v5.3.0-beta.1; not in any GA release.