From 43bffdc0c3b9df47cfbfe56509fd0ea7aece0c6d Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 8 Oct 2026 01:53:07 +0200 Subject: [PATCH] Issue 146: the enrolment-time consumer is answered by issue 208's assertion; design 08 names the join's code The branch building ADR 0169 carried a fix making a node's declaration consumer as it enrols. The controller already asserts every node's consumer before each send, and the self-check's healer asserts a missing one again, so the fix is dropped rather than merged and the record says why. The installer now places the bus's accounts at genesis. --- 03-DESIGN/01-to-be/08-connectivity.md | 4 ++- .../01-diagnosis.md | 34 +++++++++++++++++++ 2 files changed, 37 insertions(+), 1 deletion(-) diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index 54e66aaf..a3fe273e 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -20,7 +20,9 @@ code: - mesh-catalog modules/systemd-resolved (a machine's own resolver, ADR 0247) - mesh-host internal/identity/serving.go - mesh-host internal/apply (the service that reflects a rule set; a whole file handed to its new owner) -updated: 2026-10-07 + - mesh-controller cmd/mesh-controller/nodes.go (a token issued for a machine's tunnel key, ADR 0169) + - mesh-host cmd/mesh-host/join_tunnel.go (a machine joins through the tunnel, ADR 0169) +updated: 2026-10-08 decisions: - 02-DECISIONS/0247-a-machine-with-a-vpn-client-routes-names-by-domain-through-a-resolver-of-its-own.md - 02-DECISIONS/0226-the-private-network-is-assigned-by-its-own-name-and-the-proxy-names-its-public-issuer.md diff --git a/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/01-diagnosis.md b/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/01-diagnosis.md index 317bb01c..1aae3eca 100644 --- a/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/01-diagnosis.md +++ b/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/01-diagnosis.md @@ -182,3 +182,37 @@ Every lab bed still names `foundation-first-node.lock` in its own instructions, raises the previous broker with a control plane that refuses to start without `MESH_BUS_NATS`. Until the fourth fault is answered and the two bundles become one, a bed runs with `MESH_LAB_BUNDLE` pointing at the NATS bundle by hand, and stops at the enrolment. + +## 7 — joined, and then heard nothing *(answered by issue 208's assertion, 2026-10-08)* + +*Found 2026-10-02 raising a first node, recorded here 2026-10-08.* With the accounts placed, the first +machine enrolled and its host then retried *consumer not found* without end: the durable consumer a +node reads its declarations through was asserted only when the controller started, and the first +machine of a mesh enrols after the controller is already up. + +A fix was written that day on the branch that builds +[ADR 0169](../../02-DECISIONS/0169-a-machine-joins-through-the-tunnel-and-the-bus-is-never-public.md): +the controller made the node's consumer as it answered the enrolment. **It is dropped, not merged, +because the controller already does it another way.** Since +[issue 208](../208-a-seats-worker-is-made-only-when-the-controller-starts/00-report.md) the controller +asserts every stream and durable consumer its records imply — every known node's declaration consumer +among them — before every send, and a node is sent nothing it would need the consumer for until a +send. A consumer that is missing anyway is the self-check's `consumer-lost` (to-be 45, D6), which +healer H3 answers by asserting the bus's objects again. So the consumer exists by the time there is +anything to hear, and a second place that makes it would be a second list of what the bus should hold. + +What the host says before the first send — *consumer not found*, retried — is a machine with nothing +to hear yet, not a fault. A first send ends it. + +## 8 — the installer places the accounts *(on a branch, 2026-10-08)* + +Fault 5's hand step — compose the users with `broker accounts`, write them beside the bus, make the +bus re-read them, once before the enrolment and once after — is done by the installer now, on +mesh-host's branch for ADR 0169: it raised the bus from its bundle, so it is the one that knows where +the bus reads them. The fourth fault's decision (the installer's bus raised as the module the mesh +goes on managing, or genesis carrying the list) stays open; this is the second answer, done by the +program rather than by a person. + +Measured 2026-10-08 in mesh-lab's `joins-through-the-tunnel` bed, from bare: a first node raised from +the NATS bundle enrols against its own bus with the accounts placed as above, becomes the hub, and a +second machine joins through the tunnel with the bus's port closed to its own address.