ADR 0103: what an adopted node holds and what its guard refuses; the node host and connectivity designs name 0102 and 0103
This commit is contained in:
@@ -5,6 +5,8 @@ code: [mesh-host]
|
||||
updated: 2026-09-22
|
||||
decisions:
|
||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||
- 02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md
|
||||
- 02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md
|
||||
- 02-DECISIONS/0019-how-this-repository-works.md
|
||||
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
|
||||
- 02-DECISIONS/0005-the-node-host.md
|
||||
@@ -150,6 +152,18 @@ checked:* unit tests hold the host to keeping a found file and container, conver
|
||||
taken, never removing a held file and reporting one that changed; the adoption bed asserts a found
|
||||
file byte for byte unchanged until its module is taken.
|
||||
|
||||
**Found reaches every kind that can touch what the machine has**
|
||||
([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)). For a module not yet taken, a directory present with no record
|
||||
keeps its mode and owner, a unit present with no record keeps its state and boot setting, a
|
||||
container that would mount found data is not created, and an action run in a held container
|
||||
waits for the cutover. **A file the machine shares is written into, never over**
|
||||
([ADR 0102](../../02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md)): the host sets the mesh's keys in the object already there,
|
||||
keeps every other key, records what each of its keys held before and gives them back when the
|
||||
file is undeclared. Such a file replaces nothing, so it is never held. A service that re-reads
|
||||
its configuration is **reloaded** for what it names in `reload-on`, never restarted. *How it is
|
||||
checked:* unit tests hold the host to each of these, and the adoption bed asserts the runtime's
|
||||
own settings survive adoption and a container without a restart policy keeps running.
|
||||
|
||||
## Where a declaration comes from
|
||||
|
||||
One behaviour, two sources
|
||||
|
||||
@@ -9,6 +9,7 @@ code:
|
||||
- mesh-host internal/apply (the service that reflects a rule set)
|
||||
updated: 2026-09-22
|
||||
decisions:
|
||||
- 02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md
|
||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||
- 02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md
|
||||
- 02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md
|
||||
@@ -550,9 +551,13 @@ the found firewall in that firewall's own terms, marks it as the mesh's, removes
|
||||
marked, and re-checks every opening on each reconcile so a reload or a reboot does not lose it for
|
||||
longer than one reconcile. An opening is state, not a command, so it travels over the link like any
|
||||
other resource. **The mesh guards its own ports in a table of its own that only refuses** —
|
||||
passing everything by default and holding nothing but refusals of the foundation's own two ports,
|
||||
checked free at genesis, so it cannot close what the machine serves, and the found firewall's
|
||||
reload does not touch it. It refuses the store's port and the broker's management port except from
|
||||
passing everything by default and holding nothing but refusals, and the found firewall's reload
|
||||
does not touch it. Its ports are derived ([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)): every machine port a
|
||||
*taken* module publishes that the filter admits from the private network only, with the store's
|
||||
port and the broker's management port. A port of a module not yet taken may still be the
|
||||
predecessor's, so it is not guarded; and only packets addressed to this machine are matched, so
|
||||
traffic it routes for others passes. An opening a found rule already answers is not added, so
|
||||
removing it never removes the operator's rule. It refuses those ports except from
|
||||
the private network and the machine itself — loopback and the container runtime's networks, known by the interface a packet arrives on, never by
|
||||
its source address alone — at
|
||||
the prerouting hook, before the container runtime redirects the packet, so it matches the port the
|
||||
|
||||
Reference in New Issue
Block a user