ADR 0192: a tools bundle declares what it is given, and the runtime hands it to that bundle alone; research 020 graduated; design 38 WP4b
This commit is contained in:
@@ -12,6 +12,7 @@ decisions:
|
||||
- 02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md
|
||||
- 02-DECISIONS/0149-the-live-mesh-is-the-test-bed.md
|
||||
- 02-DECISIONS/0188-a-modules-own-code-is-bundles-in-any-language-and-a-tools-bundle-speaks-mcp-to-the-runtime.md
|
||||
- 02-DECISIONS/0192-a-tools-bundle-declares-what-it-is-given-and-the-runtime-hands-it-to-that-bundle-alone.md
|
||||
---
|
||||
|
||||
# 38. Building the operator's machine
|
||||
@@ -222,8 +223,27 @@ proven on all four machines — `status`, `banned` and the module's own `fail2ba
|
||||
the runtime, no `mesh-fail2ban` container, the runtime serving both bundles. Two holders moved; of the
|
||||
thirty-three tool containers the catalogue held, thirty-one remain, and all but these two carried their
|
||||
module's configuration and secrets in the container's environment, which a bundle does not have — the
|
||||
question research [020](../../01-RESEARCH/020-what-a-bundled-tool-is-given/00-overview.md) opens
|
||||
before the rest move.
|
||||
question research [020](../../01-RESEARCH/020-what-a-bundled-tool-is-given/00-overview.md) opened
|
||||
and [ADR 0192](../../02-DECISIONS/0192-a-tools-bundle-declares-what-it-is-given-and-the-runtime-hands-it-to-that-bundle-alone.md)
|
||||
settled the same day: a tools bundle declares `env` on its artifact, the composer resolves it as a
|
||||
container's, the runtime hands each bundle its own. That is WP4b below.
|
||||
|
||||
## WP4b — Every tool container moves
|
||||
|
||||
*mesh-controller, mesh-tools, mesh-catalog. One day. The rest of ADR 0175, under ADR 0192.*
|
||||
|
||||
**What changes**, in order: the manifest's tools artifact gains `env` and the catalogue check
|
||||
refuses a secret's content in it; the composer resolves a bundle's `env` per machine and carries it
|
||||
beside the bundle's archive, `restart-on` included; the runtime hands each bundle its own
|
||||
environment — the contributor's argument for an imported bundle, the child's environment for a
|
||||
launched one — and a test holds two bundles apart. Then the thirty-one remaining tool containers
|
||||
move in one change: each container's `env` becomes its tools artifact's, mount targets folded into
|
||||
the host paths they came from, the container, its base images, its Dockerfile and its own bus
|
||||
credential gone. Last, the registration gate refuses the container shape for every module.
|
||||
|
||||
**Proof.** The controller's and the runtime's tests named in ADR 0192; live, every module's tools
|
||||
answer from the runtime on the machines that run it, `docker ps` shows no tool container on any of
|
||||
the four, and `status` is well.
|
||||
|
||||
## WP5 — The shell, on a server first
|
||||
|
||||
|
||||
Reference in New Issue
Block a user