ADR 0163: taking a module over is a comparison — what it compares, refuses and carries; designs 05 and 09; group 6's issues located, 093 resolved

This commit is contained in:
2026-10-01 21:12:36 +02:00
parent b277f3b4ba
commit 2904c359b8
14 changed files with 234 additions and 21 deletions
+11 -1
View File
@@ -2,8 +2,9 @@
layer: to-be
status: in-progress
code: [mesh-host]
updated: 2026-09-29
updated: 2026-10-01
decisions:
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
- 02-DECISIONS/0141-the-host-delivers-its-own-successor.md
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md
@@ -153,6 +154,15 @@ checked:* unit tests hold the host to keeping a found file and container, conver
taken, never removing a held file and reporting one that changed; the adoption bed asserts a found
file byte for byte unchanged until its module is taken.
**What the host says of a found container, and what it removes** — revision, 2026-10-01
([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md)). Its report of a held
container carries the image and the image's creation date, the networks it is on and the other
containers on each, its mounts and its published ports — the facts a take compares. The host compares
every field it writes before calling a container current, volumes and paths included; its record keeps
a resource's former targets, removes a container or file it wrote under a name the declaration no
longer names, never removes what was found, and reports what runs on the machine that it neither
wrote nor holds. *How it is checked:* ADR 0163's table.
**Found reaches every kind that can touch what the machine has**
([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)). For a module not yet taken, a directory present with no record
keeps its mode and owner, a unit present with no record keeps its state and boot setting, a
+13 -1
View File
@@ -8,8 +8,9 @@ code:
- mesh-host packaging/nox-mesh-host-network.sh
- mesh-controller internal/token
- mesh-controller internal/inventory/nodes.go
updated: 2026-09-23
updated: 2026-10-01
decisions:
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
- 02-DECISIONS/0005-the-node-host.md
@@ -311,6 +312,17 @@ found firewall again and converges the openings through it; what was taken stays
a predecessor leaves one and asserts nothing that serves changes until a module is taken or the
node is converged, and that the flip closes exactly what the preview said.
**Taking a module is previewed, and the preview is a comparison** — revision, 2026-10-01
([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md)). For every held thing a
module would replace, `take` puts what runs beside what the module declares: a container's image and
its age, name, networks and their other members, published ports and their reach, mounts; a file's
kept original against the declared content, as a difference; a secret the mesh minted for a service
that already has one; the module's settings composed against its definition. An older image, a
differing file and a minted secret for found data refuse unless named; a narrowed port and a shared
network are said. `take --yes <digest>` cuts over what was previewed, as the flip does. A taken
container may keep a found network by a per-machine setting while its neighbours are not yet taken.
*How it is checked:* ADR 0163's table.
A candidate machine is not empty. It has a package manager, probably a container runtime,
configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md)
says the host never touches what it did not create — adoption is the deliberate act of taking