diff --git a/03-DESIGN/01-to-be/11-a-board.md b/03-DESIGN/01-to-be/11-a-board.md index 2ea5d7b..235bb60 100644 --- a/03-DESIGN/01-to-be/11-a-board.md +++ b/03-DESIGN/01-to-be/11-a-board.md @@ -1,8 +1,10 @@ --- layer: to-be status: designed -code: [] -updated: 2026-08-30 +code: + - mesh-control cmd/mesh-control/board.go + - mesh-control cmd/mesh-control/readable.go +updated: 2026-08-31 decisions: - 02-DECISIONS/0008-a-context-owns-its-store.md - 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md @@ -72,3 +74,36 @@ page that led with the third would bury the first: as it was and what is wrong is in what was sent; failed means it is in a state nobody declared and what is wrong is on the machine. They are fixed in different places, so a page that said "error" for both would send half its readers to the wrong one. + +## What was built + +*2026-08-31.* + +**One reading, three ways of saying it.** The questions are asked once, by one function, and +answered as a person's `status`, as its JSON, and as this page. Three implementations of *which +machine is not doing what it was told* would be three chances to disagree about it — and the +disagreement would surface as two people looking at two screens arguing about which machine is +broken. + +**It holds nothing and changes nothing.** Every request reads the mesh now. There is no cache to +go stale, no table of what the mesh looked like last time, and no button: every action a board +could offer already exists as a command, and one that did something no command does would be a +second implementation of a decision. + +**It never touches a context's store.** That is the whole constraint above, kept: the board is a +client of the same functions the commands use, so provisioning can change its tables without the +change being weighed against a page. + +**A board that cannot read the mesh says so.** An empty page says *nothing is wrong* in the one +situation where nobody can know that, so the failure is rendered instead — and it says explicitly +that it is a statement about the page rather than about the mesh. + +**A machine's own words are shown, and are not markup.** They are the whole reason the page is +useful — a board that said only *failed* would send a person to ask the thing they opened the +board to avoid asking. They are also the only text on the page that nobody in this repository +wrote, which is why the escaping is a test rather than an assumption. + +*Checked by giving a machine a declaration it cannot apply and requiring the page to name that +machine, say `failed` rather than `error`, and quote what the host said — then by comparing the +page's own JSON against the command's, because two answers to "which machine is broken" would be +worse than either alone.*