Record what four more pieces of the mesh became

Rotation and the provisioner contract; model access as a provision answered by
a record, with ADR 0024's other two gaps left as gaps; exposure, which closes
the open question about revoking a route; and the delivery loop, which closes
the gap ADR 0010 left when it replaced a pipeline with a comparison.
This commit is contained in:
2026-08-31 02:56:50 +02:00
parent 6b1c80b442
commit 0bc4b7774f
4 changed files with 258 additions and 2 deletions
@@ -151,6 +151,36 @@ the arrangement working: a build machine shares the runtime it was given rather
it sits on. **A module is cloned from the forge over a URL**, and "build this directory" is a
convenience for a builder somebody started by hand.
### And the loop is closed
*2026-08-31.* [ADR 0010](../../02-DECISIONS/0010-delivery.md) replaced a pipeline with a comparison
and named the risk: **losing the question "did my change go out?"**. The mesh could already answer
which modules were behind their source — and then a person read that list and retyped each
repository, which is a person being the loop, and the loop is the thing the pipeline was doing
before it was taken away.
`build --behind` is the other half, and it is the mirror of `push --behind`: the mesh knows what is
stale, so it builds it. The two forms are deliberately not combined — naming a repository and
asking which need building are different requests, and guessing which was meant would sometimes
build something nobody named.
**One failing does not stop the others**, for the same reason one broken module no longer blocks a
machine's whole declaration: a mesh where one bad repository holds back nine good ones is a mesh
where nobody dares add the tenth.
**Each is built from its own recorded ref**, not from the commit the mesh happened to notice.
Pinning to that would quietly turn a tracked branch into a pin — a change of meaning nobody asked
for, arrived at by an implementation detail.
**Building is not delivering, and the two stay separate.** A machine keeps running what it has
until it is told otherwise; the mesh changing its mind is not a machine acting on it, and
collapsing the two is how a mesh comes to report success for something that has not happened.
*Checked end to end: a commit, a build, a catalogue entry, and a machine that ends up running what
the source says — with both halves that make the answer trustworthy. It is still running the old
one until it is pushed, and it stops being reported as behind once it has caught up, because a
status that says "behind" for ever is one nobody reads.*
## What is kept
**Every result, including the failures.** A failed build that leaves no trace is indistinguishable