diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs
new file mode 100644
index 00000000..91aad7c7
--- /dev/null
+++ b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Configuration/ConfigServeAuthInterceptor.cs
@@ -0,0 +1,157 @@
+using System.Security.Cryptography;
+using System.Text;
+using Grpc.Core;
+using Grpc.Core.Interceptors;
+using Microsoft.Extensions.Logging;
+using Microsoft.Extensions.Options;
+using ZB.MOM.WW.OtOpcUa.Cluster;
+
+namespace ZB.MOM.WW.OtOpcUa.Host.Configuration;
+
+///
+/// Gates the central config-serve artifact endpoint (per-cluster mesh Phase 3). The
+/// DeploymentArtifactService streams a driver node the exact configuration it will boot
+/// on; anything able to reach central's serve port could otherwise pull the whole deployed config
+/// out-of-band. This interceptor is the ONLY inbound auth on that endpoint.
+///
+///
+///
+/// Scoped by method path. Only calls under
+/// /deployment_artifact.v1.DeploymentArtifactService/ are gated; every other method on
+/// the shared gRPC pipeline (notably the LocalDb sync service) passes through untouched, so
+/// this can share one AddGrpc registration with .
+///
+///
+/// Fail-closed. With no ConfigServe:ApiKey configured, NO fetch is accepted,
+/// authenticated or not. Treating "no key" as "no auth required" would expose the deployed
+/// configuration on exactly the default shape most nodes ship with. The node dialing in must
+/// present the same ConfigSource:ApiKey (the shared node key), so a key typo stops
+/// config delivery outright rather than degrading to unauthenticated.
+///
+///
+/// Comparison is over UTF-8 bytes, so a
+/// wrong key cannot be recovered byte-by-byte from response timing. Length differences are
+/// unavoidably observable and are not sensitive.
+///
+///
+public sealed class ConfigServeAuthInterceptor : Interceptor
+{
+ private const string ServicePrefix = "/deployment_artifact.v1.DeploymentArtifactService/";
+ private const string AuthorizationHeader = "authorization";
+ private const string BearerPrefix = "Bearer ";
+
+ private readonly IOptions _options;
+ private readonly ILogger _logger;
+
+ /// Creates the interceptor.
+ /// Config-serve options; ApiKey is the expected bearer token.
+ /// Logger for denial diagnostics.
+ public ConfigServeAuthInterceptor(
+ IOptions options,
+ ILogger logger)
+ {
+ ArgumentNullException.ThrowIfNull(options);
+ ArgumentNullException.ThrowIfNull(logger);
+
+ _options = options;
+ _logger = logger;
+ }
+
+ ///
+ public override Task UnaryServerHandler(
+ TRequest request,
+ ServerCallContext context,
+ UnaryServerMethod continuation)
+ {
+ Authorize(context);
+ return continuation(request, context);
+ }
+
+ ///
+ public override Task DuplexStreamingServerHandler(
+ IAsyncStreamReader requestStream,
+ IServerStreamWriter responseStream,
+ ServerCallContext context,
+ DuplexStreamingServerMethod continuation)
+ {
+ Authorize(context);
+ return continuation(requestStream, responseStream, context);
+ }
+
+ ///
+ public override Task ClientStreamingServerHandler(
+ IAsyncStreamReader requestStream,
+ ServerCallContext context,
+ ClientStreamingServerMethod continuation)
+ {
+ Authorize(context);
+ return continuation(requestStream, context);
+ }
+
+ ///
+ public override Task ServerStreamingServerHandler(
+ TRequest request,
+ IServerStreamWriter responseStream,
+ ServerCallContext context,
+ ServerStreamingServerMethod continuation)
+ {
+ Authorize(context);
+ return continuation(request, responseStream, context);
+ }
+
+ ///
+ /// Throws with if this is
+ /// a config-serve call that does not carry the configured bearer token. Non-serve calls return
+ /// immediately.
+ ///
+ private void Authorize(ServerCallContext context)
+ {
+ if (!context.Method.StartsWith(ServicePrefix, StringComparison.Ordinal))
+ return;
+
+ var expected = _options.Value.ApiKey;
+ if (string.IsNullOrEmpty(expected))
+ {
+ _logger.LogWarning(
+ "Rejected a config-serve call to {Method}: no ConfigServe:ApiKey is configured, so the " +
+ "artifact endpoint is closed. Configure the shared node key on central and every node.",
+ context.Method);
+ throw new RpcException(new Status(
+ StatusCode.Unauthenticated,
+ "Config-serve is not accepting connections: no API key is configured on this node."));
+ }
+
+ var presented = ExtractBearerToken(context.RequestHeaders);
+ if (presented is null || !FixedTimeEquals(presented, expected))
+ {
+ _logger.LogWarning(
+ "Rejected a config-serve call to {Method}: {Reason}.",
+ context.Method,
+ presented is null ? "no bearer token presented" : "bearer token did not match");
+ throw new RpcException(new Status(
+ StatusCode.Unauthenticated,
+ "Config-serve authentication failed."));
+ }
+ }
+
+ private static string? ExtractBearerToken(Metadata headers)
+ {
+ // gRPC lowercases header keys on the wire; compare case-insensitively anyway so a hand-built
+ // Metadata in a test behaves the same as a real request.
+ foreach (var entry in headers)
+ {
+ if (!string.Equals(entry.Key, AuthorizationHeader, StringComparison.OrdinalIgnoreCase))
+ continue;
+
+ var value = entry.Value;
+ if (value is not null && value.StartsWith(BearerPrefix, StringComparison.OrdinalIgnoreCase))
+ return value[BearerPrefix.Length..];
+ }
+
+ return null;
+ }
+
+ private static bool FixedTimeEquals(string presented, string expected)
+ => CryptographicOperations.FixedTimeEquals(
+ Encoding.UTF8.GetBytes(presented), Encoding.UTF8.GetBytes(expected));
+}
diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs
index ef193f04..5dee7c3b 100644
--- a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs
+++ b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Program.cs
@@ -8,6 +8,7 @@ using Serilog.Events;
using ZB.MOM.WW.OtOpcUa.AdminUI;
using ZB.MOM.WW.OtOpcUa.AdminUI.Clients;
using ZB.MOM.WW.OtOpcUa.AdminUI.Components;
+using ZB.MOM.WW.OtOpcUa.AdminUI.Grpc;
using ZB.MOM.WW.OtOpcUa.AdminUI.Hubs;
using ZB.MOM.WW.OtOpcUa.AdminUI.ScriptAnalysis;
using ZB.MOM.WW.OtOpcUa.Cluster;
@@ -185,11 +186,9 @@ if (hasDriver)
// (initiator) / LocalDb:SyncListenPort (listener) are set. See LocalDbRegistration.
builder.Services.AddOtOpcUaLocalDb(builder.Configuration);
- // gRPC server plumbing for the passive sync endpoint mapped below. Registered only under
- // hasDriver so admin-only nodes expose no sync surface at all. The interceptor is the ONLY
- // inbound auth on that endpoint — the replication library's LocalDbSyncService verifies
- // nothing — and it fail-closes when no ApiKey is configured.
- builder.Services.AddGrpc(o => o.Interceptors.Add());
+ // gRPC server plumbing (AddGrpc + the two path-scoped auth interceptors) is registered once,
+ // below, for hasDriver || hasAdmin — the LocalDb passive sync endpoint (driver) and the
+ // ConfigServe artifact endpoint (admin) share one pipeline.
// Config-gated server-side HistoryRead backend. When the ServerHistorian section is enabled this
// overrides the NullHistorianDataSource default from AddOtOpcUaRuntime (last registration wins) with
@@ -389,23 +388,46 @@ builder.Services.AddOtOpcUaSecrets(builder.Configuration);
builder.Services.AddOtOpcUaHealth();
builder.Services.AddOtOpcUaObservability(builder.Configuration);
+// gRPC server plumbing shared by two endpoints: the LocalDb passive sync endpoint (driver-role,
+// mapped below on hasDriver && syncListenPort > 0) and the ConfigServe artifact endpoint
+// (admin-role, mapped on hasAdmin && configServeGrpcPort > 0). Each interceptor is scoped strictly
+// to its own service path, so both can share one pipeline and each is a harmless pass-through when
+// its service is unmapped. Both fail-closed with no ApiKey configured — the interceptor is the ONLY
+// inbound auth on either endpoint (the libraries verify nothing). Registered whenever either role is
+// present so an admin-only node still serves config and a driver-only node still gates sync.
+if (hasDriver || hasAdmin)
+{
+ builder.Services.AddGrpc(o =>
+ {
+ if (hasDriver)
+ o.Interceptors.Add();
+ if (hasAdmin)
+ o.Interceptors.Add();
+ });
+}
+
// ---------------------------------------------------------------------------------------------
-// LocalDb sync listener (default-OFF).
+// Dedicated h2c listeners (both default-OFF): the LocalDb sync endpoint (driver) and the
+// ConfigServe artifact endpoint (admin, per-cluster mesh Phase 3).
//
// DANGER: any explicit Kestrel Listen* call makes Kestrel IGNORE ASPNETCORE_URLS/urls ENTIRELY
// (it logs "Overriding address(es)"). The host has no ConfigureKestrel today and binds solely via
// that configuration, so adding a listener naively would silently unbind the AdminUI + deploy API
// behind Traefik. Everything the host was already asked to serve is therefore re-bound explicitly
-// in the same block.
+// in the same block — and, critically, EXACTLY ONCE: a fused admin+driver node can have BOTH
+// dedicated ports set, and re-applying the existing surface per-port would double-bind it and throw
+// "address already in use". So the existing surface is computed and applied once, then whichever of
+// the two dedicated ports are configured are added on top.
//
-// The listener is HTTP/2-ONLY on purpose: the sync client speaks prior-knowledge h2c, which a
-// cleartext Http1AndHttp2 endpoint cannot negotiate (there is no ALPN without TLS). Hence a
-// dedicated port rather than multiplexing onto the main one.
+// Each listener is HTTP/2-ONLY on purpose: both clients speak prior-knowledge h2c, which a cleartext
+// Http1AndHttp2 endpoint cannot negotiate (there is no ALPN without TLS). Hence dedicated ports
+// rather than multiplexing onto the main one.
//
-// When LocalDb:SyncListenPort is 0 (the default) none of this runs and URL binding is untouched.
+// When both ports are 0 (the default) none of this runs and URL binding is untouched.
// ---------------------------------------------------------------------------------------------
-var syncListenPort = LocalDbRegistration.SyncListenPort(builder.Configuration);
-if (hasDriver && syncListenPort > 0)
+var syncListenPort = hasDriver ? LocalDbRegistration.SyncListenPort(builder.Configuration) : 0;
+var configServeGrpcPort = hasAdmin ? builder.Configuration.GetValue("ConfigServe:GrpcListenPort") : 0;
+if (syncListenPort > 0 || configServeGrpcPort > 0)
{
// Mirror Kestrel's own source precedence: URLS wins; else the HTTP_PORTS/HTTPS_PORTS bare-port
// vars; else Kestrel's localhost:5000 default. Missing the HTTP_PORTS leg is not academic — the
@@ -428,8 +450,8 @@ if (hasDriver && syncListenPort > 0)
];
if (existingBindings.Count > 0)
Log.Information(
- "LocalDb sync listener enabled; re-binding the HTTP_PORTS surface ({HttpPorts}/{HttpsPorts}) " +
- "alongside the sync port.", httpPorts, httpsPorts);
+ "Dedicated h2c listener(s) enabled; re-binding the HTTP_PORTS surface ({HttpPorts}/{HttpsPorts}) " +
+ "alongside the dedicated port(s).", httpPorts, httpsPorts);
}
// A driver-only Windows-service node gets NO URLS and NO *_PORTS (Install-Services.ps1 sets URLS
@@ -440,38 +462,48 @@ if (hasDriver && syncListenPort > 0)
{
existingBindings = [new KestrelHttpBinding("localhost", 5000, IsSecure: false)];
Log.Information(
- "LocalDb sync listener enabled with no URLs configured; re-binding Kestrel's default " +
- "http://localhost:5000 alongside the sync port.");
+ "Dedicated h2c listener(s) enabled with no URLs configured; re-binding Kestrel's default " +
+ "http://localhost:5000 alongside the dedicated port(s).");
}
// Re-binding an https endpoint would need its certificate configuration replayed too, which
// this host does not model (TLS is terminated at Traefik). Rather than silently serve it
// without TLS — or drop it — refuse to take over Kestrel at all and leave the existing
// surface exactly as it was. The operator gets a loud, actionable error instead of an
- // AdminUI that stopped answering.
+ // AdminUI that stopped answering. Disables BOTH dedicated ports (either would force the same
+ // Kestrel takeover).
if (existingBindings.Any(b => b.IsSecure))
{
Log.Error(
- "LocalDb:SyncListenPort is set to {Port} but this host serves HTTPS endpoint(s) ({Urls}). " +
- "Binding the sync listener requires re-binding every existing endpoint explicitly, and the " +
- "HTTPS certificate configuration cannot be replayed safely. The sync listener is DISABLED; " +
- "terminate TLS upstream (as the docker-dev rig does) or leave replication off on this node.",
- syncListenPort, configuredUrls);
+ "A dedicated h2c listener is requested (LocalDb:SyncListenPort={SyncPort}, " +
+ "ConfigServe:GrpcListenPort={ConfigServePort}) but this host serves HTTPS endpoint(s) ({Urls}). " +
+ "Binding a dedicated listener requires re-binding every existing endpoint explicitly, and the " +
+ "HTTPS certificate configuration cannot be replayed safely. BOTH dedicated listeners are DISABLED; " +
+ "terminate TLS upstream (as the docker-dev rig does) or leave these features off on this node.",
+ syncListenPort, configServeGrpcPort, configuredUrls);
syncListenPort = 0;
+ configServeGrpcPort = 0;
}
else
{
+ // Capture locals so the ConfigureKestrel closure does not observe later reassignment.
+ var syncPortToBind = syncListenPort;
+ var configServePortToBind = configServeGrpcPort;
builder.WebHost.ConfigureKestrel(kestrel =>
{
foreach (var binding in existingBindings)
binding.Apply(kestrel);
- kestrel.ListenAnyIP(syncListenPort, o => o.Protocols = HttpProtocols.Http2);
+ if (syncPortToBind > 0)
+ kestrel.ListenAnyIP(syncPortToBind, o => o.Protocols = HttpProtocols.Http2);
+ if (configServePortToBind > 0)
+ kestrel.ListenAnyIP(configServePortToBind, o => o.Protocols = HttpProtocols.Http2);
});
Log.Information(
- "LocalDb sync listener bound on :{SyncPort} (h2c); re-bound existing endpoint(s) {Urls}.",
- syncListenPort, configuredUrls ?? "http://localhost:5000 (Kestrel default)");
+ "Dedicated h2c listener(s) bound (sync=:{SyncPort}, config-serve=:{ConfigServePort}); " +
+ "re-bound existing endpoint(s) {Urls}.",
+ syncListenPort, configServeGrpcPort, configuredUrls ?? "http://localhost:5000 (Kestrel default)");
}
}
@@ -514,6 +546,14 @@ if (hasDriver && syncListenPort > 0)
app.MapZbLocalDbSync();
}
+// Central config-serve artifact endpoint (per-cluster mesh Phase 3). Mapped only on admin-role
+// nodes (which hold the central SQL connection) and only when a dedicated h2c port is bound. The
+// ConfigServeAuthInterceptor is the ONLY inbound auth and fail-closes with no ConfigServe:ApiKey.
+if (hasAdmin && configServeGrpcPort > 0)
+{
+ app.MapGrpcService();
+}
+
app.MapOtOpcUaHealth();
app.MapOtOpcUaMetrics();
diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs
new file mode 100644
index 00000000..333772d4
--- /dev/null
+++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeAuthInterceptorTests.cs
@@ -0,0 +1,152 @@
+using Grpc.Core;
+using Microsoft.Extensions.Logging.Abstractions;
+using Microsoft.Extensions.Options;
+using Shouldly;
+using Xunit;
+using ZB.MOM.WW.OtOpcUa.Cluster;
+using ZB.MOM.WW.OtOpcUa.Host.Configuration;
+
+namespace ZB.MOM.WW.OtOpcUa.Host.IntegrationTests;
+
+///
+/// Per-cluster mesh Phase 3 (Task 3) — the config-serve artifact endpoint's inbound gate.
+///
+///
+/// The DeploymentArtifactService streams a driver node the exact configuration it will
+/// boot on. Anything able to reach central's serve port could otherwise pull the whole deployed
+/// config, so the endpoint is gated by a shared bearer key, fail-closed, constant-time — the
+/// same contract as , scoped to a different service path.
+///
+public sealed class ConfigServeAuthInterceptorTests
+{
+ private const string FetchMethod = "/deployment_artifact.v1.DeploymentArtifactService/Fetch";
+ private const string OtherMethod = "/localdb_sync.v1.LocalDbSync/Sync";
+
+ private static ConfigServeAuthInterceptor CreateInterceptor(string? apiKey)
+ => new(
+ Options.Create(new ConfigServeOptions { ApiKey = apiKey ?? string.Empty }),
+ NullLogger.Instance);
+
+ private static ServerCallContext CreateContext(string method, string? authorizationHeader)
+ {
+ var headers = new Metadata();
+ if (authorizationHeader is not null)
+ headers.Add("authorization", authorizationHeader);
+
+ return new FakeServerCallContext(method, headers);
+ }
+
+ /// Invokes the interceptor's server-streaming path (how Fetch actually runs).
+ private static Task Invoke(ConfigServeAuthInterceptor interceptor, ServerCallContext context)
+ => interceptor.ServerStreamingServerHandler(
+ "request", responseStream: null!, context, (_, _, _) => Task.CompletedTask);
+
+ [Fact]
+ public async Task NonServeMethod_PassesThrough_EvenWithNoKeyConfigured()
+ {
+ // The interceptor shares the AddGrpc pipeline with the LocalDb sync interceptor, so it sees
+ // every call. It must be scoped strictly to the artifact service — a sync call is not its
+ // business.
+ var interceptor = CreateInterceptor(apiKey: null);
+ var context = CreateContext(OtherMethod, authorizationHeader: null);
+
+ await Invoke(interceptor, context); // no throw
+ }
+
+ [Fact]
+ public async Task FetchMethod_WithNoKeyConfigured_IsDenied_EvenWithABearerToken()
+ {
+ // Fail-closed. "No key configured" is the DEFAULT — treating it as "no auth required" would
+ // expose the deployed config on exactly the shape most nodes ship with. A token must not help.
+ var interceptor = CreateInterceptor(apiKey: null);
+ var context = CreateContext(FetchMethod, "Bearer anything-at-all");
+
+ var ex = await Should.ThrowAsync(() => Invoke(interceptor, context));
+ ex.StatusCode.ShouldBe(StatusCode.Unauthenticated);
+ }
+
+ [Fact]
+ public async Task FetchMethod_WithNoBearerToken_IsDenied()
+ {
+ var interceptor = CreateInterceptor("the-shared-key");
+ var context = CreateContext(FetchMethod, authorizationHeader: null);
+
+ var ex = await Should.ThrowAsync(() => Invoke(interceptor, context));
+ ex.StatusCode.ShouldBe(StatusCode.Unauthenticated);
+ }
+
+ [Fact]
+ public async Task FetchMethod_WithWrongBearerToken_IsDenied()
+ {
+ var interceptor = CreateInterceptor("the-shared-key");
+ var context = CreateContext(FetchMethod, "Bearer the-wrong-key");
+
+ var ex = await Should.ThrowAsync(() => Invoke(interceptor, context));
+ ex.StatusCode.ShouldBe(StatusCode.Unauthenticated);
+ }
+
+ [Fact]
+ public async Task FetchMethod_WithCorrectBearerToken_PassesThrough()
+ {
+ var interceptor = CreateInterceptor("the-shared-key");
+ var context = CreateContext(FetchMethod, "Bearer the-shared-key");
+
+ await Invoke(interceptor, context); // no throw
+ }
+
+ [Fact]
+ public async Task FetchMethod_TokenComparison_IsNotAPrefixMatch()
+ {
+ // A prefix/StartsWith comparison would accept a truncated key and make the secret
+ // recoverable one character at a time.
+ var interceptor = CreateInterceptor("the-shared-key");
+ var context = CreateContext(FetchMethod, "Bearer the-shared-ke");
+
+ var ex = await Should.ThrowAsync(() => Invoke(interceptor, context));
+ ex.StatusCode.ShouldBe(StatusCode.Unauthenticated);
+ }
+
+ [Fact]
+ public async Task UnaryPath_IsAlsoGated()
+ {
+ // Fetch is server-streaming today, but gating only that path would leave any future unary
+ // method on the same service open. Gate every handler shape.
+ var interceptor = CreateInterceptor("the-shared-key");
+ var context = CreateContext(FetchMethod, "Bearer the-wrong-key");
+
+ var ex = await Should.ThrowAsync(() =>
+ interceptor.UnaryServerHandler(
+ "request", context, (_, _) => Task.FromResult("ok")));
+
+ ex.StatusCode.ShouldBe(StatusCode.Unauthenticated);
+ }
+
+ ///
+ /// Minimal carrying just a method name and request headers —
+ /// the only two things the interceptor reads. Hand-rolled because
+ /// Grpc.Core.Testing.TestServerCallContext ships only in the retired native package.
+ ///
+ private sealed class FakeServerCallContext(string method, Metadata requestHeaders)
+ : ServerCallContext
+ {
+ protected override string MethodCore => method;
+ protected override string HostCore => "localhost";
+ protected override string PeerCore => "ipv4:127.0.0.1:12345";
+ protected override DateTime DeadlineCore => DateTime.UtcNow.AddMinutes(1);
+ protected override Metadata RequestHeadersCore => requestHeaders;
+ protected override CancellationToken CancellationTokenCore => CancellationToken.None;
+ protected override Metadata ResponseTrailersCore { get; } = [];
+ protected override Status StatusCore { get; set; }
+ protected override WriteOptions? WriteOptionsCore { get; set; }
+
+ protected override AuthContext AuthContextCore { get; } =
+ new(null, new Dictionary>());
+
+ protected override ContextPropagationToken CreatePropagationTokenCore(
+ ContextPropagationOptions? options)
+ => throw new NotSupportedException();
+
+ protected override Task WriteResponseHeadersAsyncCore(Metadata responseHeaders)
+ => Task.CompletedTask;
+ }
+}
diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs
new file mode 100644
index 00000000..0349f328
--- /dev/null
+++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.IntegrationTests/ConfigServeListenerTests.cs
@@ -0,0 +1,99 @@
+using System.Net;
+using Microsoft.AspNetCore.Builder;
+using Microsoft.AspNetCore.Server.Kestrel.Core;
+using Microsoft.Extensions.DependencyInjection;
+using Microsoft.Extensions.Hosting;
+using Shouldly;
+using Xunit;
+using ZB.MOM.WW.OtOpcUa.Host.Configuration;
+
+namespace ZB.MOM.WW.OtOpcUa.Host.IntegrationTests;
+
+///
+/// Per-cluster mesh Phase 3 (Task 3) — the coexistence of the ConfigServe artifact h2c listener
+/// with the LocalDb-sync h2c listener on a fused admin+driver node.
+///
+///
+///
+/// Why this is the load-bearing test. A fused central node can carry BOTH dedicated
+/// h2c ports (LocalDb sync + ConfigServe). Any explicit Kestrel Listen* makes Kestrel
+/// discard ASPNETCORE_URLS wholesale, so the existing HTTP surface must be re-bound
+/// exactly ONCE alongside the two dedicated ports. Re-binding it twice (one block per h2c
+/// port) throws "address already in use"; re-binding it zero times silently unbinds the
+/// AdminUI behind Traefik. This test pins that all three answer simultaneously.
+///
+///
+/// Like , this drives a minimal WebApplication
+/// shaped exactly like Program.cs's merged listener block rather than booting the real
+/// host (which needs SQL, an Akka mesh and LDAP). What is under test is the Kestrel binding
+/// contract, fully reproduced here; the real end-to-end fetch is the Task 8 boundary test.
+///
+///
+public sealed class ConfigServeListenerTests
+{
+ [Fact]
+ public async Task BothDedicatedH2cPorts_AndTheHttpSurface_AnswerSimultaneously()
+ {
+ var httpPort = GetFreePort();
+ var syncPort = GetFreePort();
+ var configServePort = GetFreePort();
+
+ var builder = WebApplication.CreateBuilder();
+ builder.Environment.ApplicationName = typeof(ConfigServeListenerTests).Assembly.GetName().Name!;
+ builder.Services.AddGrpc();
+
+ // Exactly the shape Program.cs's merged block applies: compute the existing surface ONCE,
+ // apply it ONCE, then add each configured dedicated h2c port.
+ var existingBindings = KestrelHttpBinding.Parse($"http://localhost:{httpPort}");
+ builder.WebHost.ConfigureKestrel(kestrel =>
+ {
+ foreach (var binding in existingBindings)
+ binding.Apply(kestrel);
+
+ kestrel.ListenAnyIP(syncPort, o => o.Protocols = HttpProtocols.Http2);
+ kestrel.ListenAnyIP(configServePort, o => o.Protocols = HttpProtocols.Http2);
+ });
+
+ await using var app = builder.Build();
+ app.MapGet("/healthz", () => "ok");
+ await app.StartAsync(TestContext.Current.CancellationToken);
+
+ try
+ {
+ // The re-bound HTTP/1.1 surface still answers (the AdminUI/Traefik guarantee).
+ using var http1 = new HttpClient();
+ (await http1.GetStringAsync(
+ $"http://localhost:{httpPort}/healthz", TestContext.Current.CancellationToken))
+ .ShouldBe("ok");
+
+ // Both dedicated ports negotiate prior-knowledge h2c. A 404 is a fine result — it proves
+ // the HTTP/2 connection was established and routed, which is all that is in question.
+ using var http2 = new HttpClient
+ {
+ DefaultRequestVersion = HttpVersion.Version20,
+ DefaultVersionPolicy = HttpVersionPolicy.RequestVersionExact,
+ };
+
+ using var syncResponse = await http2.GetAsync(
+ $"http://localhost:{syncPort}/", TestContext.Current.CancellationToken);
+ syncResponse.Version.ShouldBe(HttpVersion.Version20);
+
+ using var configServeResponse = await http2.GetAsync(
+ $"http://localhost:{configServePort}/", TestContext.Current.CancellationToken);
+ configServeResponse.Version.ShouldBe(HttpVersion.Version20);
+ }
+ finally
+ {
+ await app.StopAsync(TestContext.Current.CancellationToken);
+ }
+ }
+
+ private static int GetFreePort()
+ {
+ using var listener = new System.Net.Sockets.TcpListener(IPAddress.Loopback, 0);
+ listener.Start();
+ var port = ((IPEndPoint)listener.LocalEndpoint).Port;
+ listener.Stop();
+ return port;
+ }
+}