ADR 0100 accepted; the node host, connectivity, the node lifecycle and raising a mesh amended for a node adopted before it is converged

This commit is contained in:
2026-09-22 16:20:27 +02:00
parent 5fc3cbde4c
commit 111456abb5
7 changed files with 70 additions and 10 deletions
+19 -3
View File
@@ -8,8 +8,9 @@ code:
- mesh-host packaging/nox-mesh-host-network.sh
- mesh-controller internal/token
- mesh-controller internal/inventory/nodes.go
updated: 2026-08-31
updated: 2026-09-22
decisions:
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
- 02-DECISIONS/0005-the-node-host.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
@@ -282,8 +283,23 @@ runs. Building the start mechanism before deciding that would be building it for
## Adoption: what happens to what is already there
Adoption is not a state. It is what the **first apply** does when it is told to own something a
machine already has ([research 012](../../01-RESEARCH/012-the-minimum-viable-node/00-overview.md)).
**An enrolled node is adopted or converged, and the mesh records which** ([ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md)).
This was once said the other way — adoption as only what the first apply does — and a machine
being migrated from a mesh already running on it made the middle state last: while its services
move one at a time, what it already has must stay in force. So *adopted* is a second axis of an
enrolled node, not a step on the path above: a machine in use is enrolled adopted, and stays so
until its migration is done and the operator converges it. A machine that was empty is enrolled
converged, as before
([research 012](../../01-RESEARCH/012-the-minimum-viable-node/00-overview.md)).
On an adopted node the firewall found there stays in force and the mesh opens what it needs
through it ([08-connectivity](08-connectivity.md)); a file found at a path the mesh declares is
kept until the module declaring it migrates ([05-the-node-host](05-the-node-host.md)).
**Converging is one act per node, previewed**: it lists every port the found firewall allows and
whether an assigned module declares it or it will close, then loads the mesh's own filter, retires
the found one and converges what was kept. *How it is checked:* a lab bed prepares a machine the
way a predecessor leaves one and asserts nothing on it changes until the flip, and that the flip
closes exactly what the preview said.
A candidate machine is not empty. It has a package manager, probably a container runtime,
configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md)