ADR 0052 (proposed) — an init step is a container run once to completion
A module can declare state but not a step that runs. mosquitto must seed its dynsec admin into dynamic-security.json before the broker starts, or the plugin aborts; the database providers need the same for first-boot migrations and health gates (04-ISSUES/037). The old event-hook engine that did this was powerful and flaky; this is the narrowest sound mechanism instead. A run-once step is an ordinary container marked `run-once: true`: the host runs it to completion, requires exit 0, and gates the apply on it — so what the declaration places after it (the broker) starts only once it has finished. Gating is by declaration order, not a resolved dependency (ADR 0005); the completion marker is the recorded declaration digest (ADR 0018), so a re-apply does not re-run it unless the declaration changed. No new host shape and no arbitrary host command: strictly less powerful than an `action`. Points 04-ISSUES/037 fixed-by/amended-design at the record; index regenerated; records.py and index.py pass. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -120,6 +120,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0049** — [A consumer's identity is bounded by the tightest backend that must accept it](0049-a-consumers-identity-fits-the-tightest-backend.md)
|
||||
- **0050** — [Model access is vendor-agnostic, and a vendor is an adapter](0050-model-access-is-vendor-agnostic.md)
|
||||
- **0051** — [Shared data is the operator's, and a module is granted access to it](0051-shared-data-is-the-operators.md)
|
||||
- **0052** — [An init step is a container run once to completion, gating what follows](0052-a-step-that-runs-once-before-a-container.md) *(proposed)*
|
||||
|
||||
### How it is built
|
||||
|
||||
|
||||
Reference in New Issue
Block a user