From 079c488d5e4a122c63ded1e57399135b165f2603 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 29 Aug 2026 14:06:33 +0200 Subject: [PATCH] Provisioned and immutable beats exempt Replacing the framing I wrote an hour ago. I had the node's own agent sitting outside the lifecycle as an exemption, which is a rule somebody has to remember. Provisioned the ordinary way and constrained is a rule the system enforces, and it is one row like any other rather than a category every query listing agents has to special-case. It also reads the original sentence more carefully. "Exempt from the hiring lifecycle" is exempt from hiring, not from having a lifecycle. Its lifecycle is the node's -- provisioned at enrolment, retired when the node is retired. Same states, a different thing driving them, and no exemption needed. The constraints are now the four nonsense states written as things that cannot happen rather than as an argument: not retirable, reassignable or deletable while its node exists; exactly one per node. And a distinction that was missing -- its existence is immutable, its engram is not. Freezing the personality would remove the way a node is configured. Disabling is the better half of this. A node with no agent is a silence somebody has to diagnose; a node whose agent is disabled answers saying so, immediately, with no model invoked -- the queue is still consumed and the state is the reply. That is the host's own rule about a service that does not exist, applied one tier up: absence must never be indistinguishable from a failure to answer. --- .../0003-agents-are-persistent-employees.md | 29 +++++++++++++++---- 1 file changed, 24 insertions(+), 5 deletions(-) diff --git a/02-DECISIONS/0003-agents-are-persistent-employees.md b/02-DECISIONS/0003-agents-are-persistent-employees.md index 3f9945c..3f26127 100644 --- a/02-DECISIONS/0003-agents-are-persistent-employees.md +++ b/02-DECISIONS/0003-agents-are-persistent-employees.md @@ -75,15 +75,34 @@ distinction is the answer to a question asked repeatedly and worth settling here twice is real duplication and the concern was right; collapsing the lifecycles is the other mistake and it is worse. -**The exemption is not bureaucracy — it removes four states that make no sense.** If a node's own -voice were an ordinary hired agent it could be **retired**, leaving a node nothing can talk to; -**reassigned**, moving one machine's mind onto another; hired **twice**, with no answer to which -replies when the node is addressed; or hired **not at all**, leaving a node with no voice. The -exemption is what makes those unreachable. +**It is provisioned the ordinary way and made immutable — not held outside the system.** The +sentence above says *exempt from the hiring lifecycle*, and the precision matters: it is exempt +from **hiring**, not from having a lifecycle. Its lifecycle is the **node's** — provisioned when +the node enrols, retired when the node is retired. Same states, a different thing driving them. + +That distinction is what keeps it inside the model. A thing genuinely held outside would have to be +special-cased by everything that lists agents; a thing provisioned normally and constrained is one +row like any other, and the constraints are **checkable** rather than remembered: + +| | | +|---|---| +| **cannot be retired, reassigned, or deleted while its node exists** | it *is* that machine's voice — retiring it leaves a node nothing can talk to, moving it puts one machine's mind on another | +| **exactly one per node** | with two, nothing decides which replies when the node is addressed; with none, the node is mute | +| **may be disabled and re-enabled** | ordinary, and see below | +| **its engram may be changed** | its existence is immutable, its personality is not — that is how a node is configured | [ADR 0001](0001-mesh-brokers-nodes-host-agents-think.md)'s *the two agent rows per node merge* is the same fact from the other side: **one per node** — not zero, and not two. +**Disabled is a state that answers.** A node prompted while its agent is disabled replies saying +so, immediately, without a model being invoked. It does not time out and it is not silence — the +queue is still consumed, and the answer is the state. + +That is the whole reason disabling is better than not provisioning. A node with no agent is a +silence somebody has to diagnose; a node whose agent is disabled tells you what is wrong in the +reply. It is the same rule the host follows about a service that does not exist, applied here: +**absence must never be indistinguishable from a failure to answer.** + ### What is scoped, and what is not **Its tool list is its own and narrower than a session a person drives.** The same scoping any