ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended

This commit is contained in:
2026-09-21 17:50:41 +02:00
parent ffb7fa52ec
commit 16442ecd23
9 changed files with 183 additions and 8 deletions
@@ -7,6 +7,7 @@ code:
- mesh-catalog modules/builder
updated: 2026-09-21
decisions:
- 02-DECISIONS/0091-a-mount-is-declared-three-ways.md
- 02-DECISIONS/0087-a-seeded-file-is-created-once.md
- 02-DECISIONS/0040-what-a-module-is.md
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
@@ -182,6 +183,16 @@ disagrees with it.
| `computed` | marks a module the controller generates rather than an author writing |
| `build.artifacts` | what it produces |
**A container mounts only what the manifest declares**
([ADR 0091](../../02-DECISIONS/0091-a-mount-is-declared-three-ways.md)). A bind mount the module
never declared is created by the container runtime as root, so the module's owner and mode never
reach its data and the rule that keeps data when a module goes away does not cover it. A path is
declared in one of three ways, for the three things a path can be: the module's own (a directory
or file resource, or where a secret, grant or contribution lands), the operator's (an `accesses`
entry), or the machine's (a facility a declared capability grants — `container-runtime` grants its
socket). *How it is checked:* the parser refuses an undeclared mount naming the path and the three
remedies, and a test parses every manifest in the catalogue beside the checkout.
### What it builds
| kind | is |