Review of 0164-0166 and 190: the mesh's own setting words stay settable; changing runtime verbs are not the console's wildcard; migration steps 1-2 are one push; dnsmasq's dns key dates from 09-23

This commit is contained in:
2026-10-02 00:48:06 +02:00
parent 3d54fcbb86
commit 27c1db8a86
3 changed files with 28 additions and 12 deletions
@@ -81,14 +81,18 @@ it; a mesh-wide setting reaches every assignment of the module; a node's reaches
change names each assignment whose effective value moves. change names each assignment whose effective value moves.
**A declared setting is the only kind accepted.** Setting a key the module does not declare is refused **A declared setting is the only kind accepted.** Setting a key the module does not declare is refused
when it is set, naming the declared keys, rather than reported when the machine is planned. A module when it is set, naming the declared keys, rather than reported when the machine is planned. The mesh's
own words — where a port, a directory or an operator's data is placed, how far an endpoint reaches —
are the mesh's to validate as they are today, and no module declares them. A module
that declares no settings keeps today's behaviour until it does; a catalogue test lists those modules, that declares no settings keeps today's behaviour until it does; a catalogue test lists those modules,
and the list shrinks to empty before the implicit form is removed — design 27's rule for every retired and the list shrinks to empty before the implicit form is removed — design 27's rule for every retired
mechanism. mechanism.
**A setting says what it costs: nothing, a reload, or a restart.** When a file changes, the host **A setting says what it costs: nothing, a reload, or a restart.** When a file changes, the host
applies the strongest cost among the settings whose values moved in it, so a key the software reads applies the strongest cost among the settings whose values moved in it, so a key the software reads
only at start can no longer be written and never read. A service's `reload-on` and `restart-on` keep only at start can no longer be written and never read. A setting that reaches a container's environment
costs that container being recreated, which the host already does when a container's specification
changes; it needs no declaration. A service's `reload-on` and `restart-on` keep
naming the files that are not settings — a generated roster, a credential. naming the files that are not settings — a generated roster, a credential.
**The container runtime is the first module to declare its settings** and the model for the rest: **The container runtime is the first module to declare its settings** and the model for the rest:
@@ -66,7 +66,12 @@ it and is assigned to every machine. A podman module may claim it later; one mac
**The seat's verbs cover every container on the machine:** list, inspect, logs, stats, start, stop, **The seat's verbs cover every container on the machine:** list, inspect, logs, stats, start, stop,
restart, create and remove. A mesh-held container is marked by the host's label and says which restart, create and remove. A mesh-held container is marked by the host's label and says which
assignment holds it. **Creating or removing a mesh-held container is the host's alone.** Any other assignment holds it. **A container the runtime runs can be root on the machine** — privileged, a host
path mounted, the host's network or process namespace, the runtime's own socket — so a caller other
than the host may not create one that is any of these; only a declaration the mesh composed may ask
for them. And the verbs that change anything are granted by name, never by a wildcard: a grant of
every tool (the console's today) reaches the reading verbs only. Issue 193 is what a verb that trusts
its caller costs. **Creating or removing a mesh-held container is the host's alone.** Any other
caller is refused naming the assignment, because the host would undo it at its next apply. Starting, caller is refused naming the assignment, because the host would undo it at its next apply. Starting,
stopping or restarting one is allowed, and the answer says the host will restore what its stopping or restarting one is allowed, and the answer says the host will restore what its
declaration says. A container the mesh does not hold is the caller's to do anything with. declaration says. A container the mesh does not hold is the caller's to do anything with.
@@ -105,13 +110,13 @@ adopt theirs ([ADR 0078](0078-the-store-and-broker-are-modules.md)).
## Consequences ## Consequences
- **The migration on the running mesh has a fixed order:** - **The migration on the running mesh has a fixed order:**
1. The resolver module and the private network stop writing the runtime's file 1. Each machine's hand-written configuration is read, because the module's defaults replace what
([issue 190](../04-ISSUES/190-the-runtimes-configuration-is-written-by-modules-that-are-not-the-runtime/00-report.md)). differs.
The runtime module takes the same file in the same push. Otherwise the controller refuses two 2. In one push per machine: the resolver module and the private network stop writing the
modules declaring one path. runtime's file ([issue 190](../04-ISSUES/190-the-runtimes-configuration-is-written-by-modules-that-are-not-the-runtime/00-report.md)),
2. The runtime module is assigned to every machine and adopts the runtime there. Each machine's and the runtime module is assigned and adopts the runtime, its file and its service. Split in
hand-written configuration is read before the first push, because the module's defaults two, either the controller refuses two modules declaring one path, or a machine is left with
replace what differs. nothing setting `dns` and `live-restore`.
3. The controller seeds the seat and enforces the container requirement. 3. The controller seeds the seat and enforces the container requirement.
4. The host releases the version that uses the holder. 4. The host releases the version that uses the holder.
5. The host's command-line path is removed in the release after every machine's holder answers. 5. The host's command-line path is removed in the release after every machine's holder answers.
@@ -124,6 +129,10 @@ adopt theirs ([ADR 0078](0078-the-store-and-broker-are-modules.md)).
tools cannot fall back to a container. tools cannot fall back to a container.
- A user interface subscribing to events directly does not exist. Today a reader of events is a module - A user interface subscribing to events directly does not exist. Today a reader of events is a module
that consumes them. The mesh's container view is a module, or waits for that path. that consumes them. The mesh's container view is a module, or waits for that path.
- [ADR 0005](0005-the-node-host.md) ("a container runtime is detected, not chosen") and
[ADR 0006](0006-the-substrate-and-the-control-plane.md)'s matching line describe the mechanism this replaces: on
acceptance, each gets a dated note saying the runtime is now a seat's holder, as the decision
records' rule for a moved mechanism requires. Design 05 and design 26 are amended after acceptance.
- The operator's decision to remove the third-party interface by hand needs no mechanism. No - The operator's decision to remove the third-party interface by hand needs no mechanism. No
module-retires-module rule is introduced. module-retires-module rule is introduced.
- **What got harder:** the host gains a dependency it did not have, and a first machine's bundle gains - **What got harder:** the host gains a dependency it did not have, and a first machine's bundle gains
@@ -136,6 +145,7 @@ adopt theirs ([ADR 0078](0078-the-store-and-broker-are-modules.md)).
|---|---| |---|---|
| The seat is the mesh's own, node-scoped, with its verbs and events | A catalogue test on the default seats; registration refuses a claimant that does not serve every verb (design 33's existing check) | | The seat is the mesh's own, node-scoped, with its verbs and events | A catalogue test on the default seats; registration refuses a claimant that does not serve every verb (design 33's existing check) |
| Creating or removing a mesh-held container is the host's alone | A test of the runtime module's verbs: create or remove of a container carrying the host's label, from any caller but the host's socket, is refused naming the assignment; the same verbs on an unlabelled container succeed | | Creating or removing a mesh-held container is the host's alone | A test of the runtime module's verbs: create or remove of a container carrying the host's label, from any caller but the host's socket, is refused naming the assignment; the same verbs on an unlabelled container succeed |
| No caller but the host creates a container that is root on the machine | A test of `create` from the bus: privileged, a host path, the host's namespaces and the runtime's socket are each refused; the same request on the host's socket is accepted. A broker test: a grant of every tool does not reach a changing verb |
| The host uses the holder and never the command line | A host test with a fake holder on the local socket: every container operation goes to it, and with the holder absent the apply creates nothing and reports the seat; after step 5, the host carries no command-line runtime code (checked by build: the package is gone) | | The host uses the holder and never the command line | A host test with a fake holder on the local socket: every container operation goes to it, and with the holder absent the apply creates nothing and reports the seat; after step 5, the host carries no command-line runtime code (checked by build: the package is gone) |
| A container needs the seat held | A resolution test refusing a containerised assignment on a machine with the seat unheld, naming the seat | | A container needs the seat held | A resolution test refusing a containerised assignment on a machine with the seat unheld, naming the seat |
| Socket mounts are granted by the seat | A catalogue test: a module mounting the runtime's socket on a machine whose holder states a different path is refused | | Socket mounts are granted by the seat | A catalogue test: a module mounting the runtime's socket on a machine whose holder states a different path is refused |
@@ -16,8 +16,10 @@ the runtime:
- **The resolver module** writes the runtime's `dns` key (the machine's private address) and - **The resolver module** writes the runtime's `dns` key (the machine's private address) and
`live-restore` into the runtime's file, written into rather than over `live-restore` into the runtime's file, written into rather than over
([ADR 0102](../../02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md)). It also ([ADR 0102](../../02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md)). It also
declares the runtime's service, reloaded when that file changes. It was added on 2026-09-30 to declares the runtime's service, reloaded when that file changes. The `dns` key has been written
fix [issue 110](../110-a-container-on-the-runtimes-own-network-cannot-reach-the-resolver/00-report.md), since the resolver module was converted from its predecessor on 2026-09-23; `live-restore` and the
service were added on 2026-09-30 while fixing
[issue 110](../110-a-container-on-the-runtimes-own-network-cannot-reach-the-resolver/00-report.md),
where containers silently resolved through a public resolver. where containers silently resolved through a public resolver.
- **The private network** writes the runtime's `insecure-registries` into the same file, and declares - **The private network** writes the runtime's `insecure-registries` into the same file, and declares
the same service reloaded on it, as [ADR 0082](../../02-DECISIONS/0082-the-registry-is-reached-by-name-and-trusted-by-the-overlay.md) the same service reloaded on it, as [ADR 0082](../../02-DECISIONS/0082-the-registry-is-reached-by-name-and-trusted-by-the-overlay.md)