Adopt the glossary's vocabulary in the mutable design docs
"control plane" -> controller and "substrate" -> foundation throughout 03-DESIGN, 00-META and the README, with 06-the-control-plane.md and 07-the-substrate.md renamed to 06-the-controller.md and 07-the-foundation.md. The immutable 02-DECISIONS records keep their original wording (and links to them are unchanged) — a term retired here may still appear there, which the glossary explains how to read. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -59,7 +59,7 @@ names neither the licence nor the mesh.
|
||||
|
||||
**A key is read from a file or standard input, never an argument.** A key on a command line is a
|
||||
key in shell history and in every process listing taken while it ran. It is never echoed back:
|
||||
what is stored is unreadable by whoever holds it, the control plane included, and printing it
|
||||
what is stored is unreadable by whoever holds it, the controller included, and printing it
|
||||
would put the one copy that matters on a terminal.
|
||||
|
||||
## Refusing is felt, and that is the design working
|
||||
@@ -83,7 +83,7 @@ per machine, which is a step toward it and is not it.
|
||||
|
||||
*2026-08-31: this gap now has named consumers rather than hypothetical ones.*
|
||||
[ADR 0026](../../02-DECISIONS/0026-the-mesh-has-a-session-of-its-own.md) puts two sessions on the
|
||||
control-plane node — the node's own and the mesh's — each bound in its own right. See
|
||||
controller node — the node's own and the mesh's — each bound in its own right. See
|
||||
[`15-the-agent-session.md`](15-the-agent-session.md).
|
||||
|
||||
**And for sessions the gap is already closed, which was not obvious.** A binding is per module per
|
||||
@@ -172,12 +172,12 @@ it; the metric is vendor-defined, so no false common unit is forced. Anthropic b
|
||||
In the lab, on real machines, in the order a person would meet it: a consumer is refused with both
|
||||
candidates named; put on one and still refused because no key exists; the key is given on standard
|
||||
input and not echoed; the public half arrives saying it came from a record rather than a machine;
|
||||
the key arrives readable only by that machine — and it is **nowhere in the control plane's own
|
||||
the key arrives readable only by that machine — and it is **nowhere in the controller's own
|
||||
database**, nor in anything that crossed the broker.
|
||||
|
||||
For the generalisation ([ADR 0050](../../02-DECISIONS/0050-model-access-is-vendor-agnostic.md)): a
|
||||
second vendor — `anthropic-api-key`, static-key — is bound to a consumer and exercises the whole path
|
||||
with the carve-out switched off, its key sealed per node and absent from the control plane's database.
|
||||
with the carve-out switched off, its key sealed per node and absent from the controller's database.
|
||||
For a `refreshable-grant` licence, the refresh token is asserted to exist (encrypted) **only on the
|
||||
manager node**, to be **absent from every holder's delivery**, and the delivered credential to be
|
||||
access-token-only; a `static-key` licence stores no refresh token anywhere. A scenario with two
|
||||
|
||||
Reference in New Issue
Block a user