ADR 0100 after review: found means unrecorded; assigning prepares, taking cuts over; openings through the found firewall on both paths; the mesh guards its own ports; ports kept as node settings; a converged genesis refuses a machine in use; designs 05, 07, 08, 09 and 17 in step
This commit is contained in:
@@ -292,14 +292,18 @@ until its migration is done and the operator converges it. A machine that was em
|
||||
converged, as before
|
||||
([research 012](../../01-RESEARCH/012-the-minimum-viable-node/00-overview.md)).
|
||||
|
||||
On an adopted node the firewall found there stays in force and the mesh opens what it needs
|
||||
through it ([08-connectivity](08-connectivity.md)); a file found at a path the mesh declares is
|
||||
kept until the module declaring it migrates ([05-the-node-host](05-the-node-host.md)).
|
||||
**Converging is one act per node, previewed**: it lists every port the found firewall allows and
|
||||
whether an assigned module declares it or it will close, then loads the mesh's own filter, retires
|
||||
the found one and converges what was kept. *How it is checked:* a lab bed prepares a machine the
|
||||
way a predecessor leaves one and asserts nothing on it changes until the flip, and that the flip
|
||||
closes exactly what the preview said.
|
||||
The operator says a node is adopted — at genesis for the control-node, in the enrolment token for
|
||||
the others — and the controller records it and says so in every declaration, with the modules
|
||||
**taken** on that node. On an adopted node what is found is held until its module is taken
|
||||
([05-the-node-host](05-the-node-host.md)): assigning a module prepares it, taking it is its
|
||||
cutover. The firewall found there stays in force and the mesh opens what it needs through it
|
||||
([08-connectivity](08-connectivity.md)). **Converging is one act per node, previewed**: it lists
|
||||
what is reachable on the machine now — listening sockets and published ports — and whether an
|
||||
assigned module declares each or it will close, then takes every module not yet taken, loads the
|
||||
mesh's own filter and disables the found one without flushing it. Returning a converged node to
|
||||
adopted enables the found firewall again. *How it is checked:* a lab bed prepares a machine the way
|
||||
a predecessor leaves one and asserts nothing that serves changes until a module is taken or the
|
||||
node is converged, and that the flip closes exactly what the preview said.
|
||||
|
||||
A candidate machine is not empty. It has a package manager, probably a container runtime,
|
||||
configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md)
|
||||
@@ -316,11 +320,16 @@ an installation. This is a *never* rule, and it earns that from the worst loss i
|
||||
a tool acting on a path it did not own.
|
||||
|
||||
**On conflict, the machine's configuration wins.** Adoption always completes; the conflict is
|
||||
flagged and reconciled afterwards. A machine in use keeps working exactly as it did.
|
||||
flagged and reconciled afterwards. A machine in use keeps working exactly as it did. Two things are
|
||||
not conflicts in this sense ([ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md)):
|
||||
a module the operator has *taken* replaces what it found, because that is its cutover; and genesis
|
||||
refuses a port the foundation needs that something else holds, because a foundation that cannot
|
||||
bind is not adopted but broken.
|
||||
|
||||
**Adoption produces a briefing**, not just a result: what it found, what it took over, and what
|
||||
it could not resolve — with each line marked `ok`, `kept`, `unknown` or `failed`, and the overall
|
||||
outcome **derived** from the worst line rather than stated alongside it.
|
||||
outcome **derived** from the worst line rather than stated alongside it. A file or container the
|
||||
host is holding on an adopted node is a `kept` line for as long as it is held.
|
||||
|
||||
---
|
||||
|
||||
@@ -384,6 +393,11 @@ runtime because a declaration changed would stop every container on the node.
|
||||
|
||||
---
|
||||
|
||||
|
||||
*On an adopted node* ([ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md)),
|
||||
what the host is holding was found, not made, so nothing held is ever removed: a held file whose
|
||||
module is unassigned stays where it is.
|
||||
|
||||
## enrolled ⇄ disconnected
|
||||
|
||||
Not a failure. Not degraded. A situation
|
||||
|
||||
Reference in New Issue
Block a user