One implementation, several surfaces, and what that costs
The mesh is operated from a command line and must be operable from a browser and from a model's tools, without becoming three systems. The pattern is already in the code and was unnamed: `board` serves HTTP by calling the same functions the CLI calls, holding nothing. Takes the decision 0034 said had to be taken deliberately rather than arrive with a feature: the HTTP surface is not read-only, so a browser login now carries authority over the mesh. Names the dependency by protocol — an OAuth2 identity provider — as the mesh does for AMQP, S3 and OCI. Keycloak is what fills the role; what the control plane knows is that it validates a token, and replacing the provider is a migration rather than a redesign. Says what this must not become, because it is the failure the project was started over: a kernel every module imports, 155 files of code from every context. Shared surfaces are not a shared library. Three adapters calling the same functions is not the same as logic leaving the context that owns it. And records the loop it creates. The networked surfaces depend on a module the control plane assigns, so when identity is down nobody can authenticate — including whoever is trying to fix it. The way out is the command line, which authenticates through nothing and is available to the account that owns the machine. Hence the rule: no capability exists only behind an authenticated surface, because that is a capability which disappears exactly when identity does.
This commit is contained in:
@@ -105,6 +105,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0024** — [Model access is a provision, and a licence is a thing with a name](0024-model-access-is-a-provision.md)
|
||||
- **0026** — [The mesh has a session of its own, and it is the node session's mechanism](0026-the-mesh-has-a-session-of-its-own.md)
|
||||
- **0027** — [A provision names what the consumer is coupled to, not the role it plays](0027-a-provision-names-what-the-consumer-is-coupled-to.md)
|
||||
- **0035** — [One implementation, several surfaces, and what that costs](0035-one-implementation-several-surfaces.md)
|
||||
|
||||
### How it is built
|
||||
|
||||
|
||||
Reference in New Issue
Block a user