Record the board, which is the last designed document with no code

One reading answered three ways, holding nothing and touching no context's
store — which is the constraint the whole document is about, and the thing the
board being replaced gets wrong.
This commit is contained in:
2026-08-31 04:50:45 +02:00
parent 0bc4b7774f
commit 5ad3641cbf
+37 -2
View File
@@ -1,8 +1,10 @@
---
layer: to-be
status: designed
code: []
updated: 2026-08-30
code:
- mesh-control cmd/mesh-control/board.go
- mesh-control cmd/mesh-control/readable.go
updated: 2026-08-31
decisions:
- 02-DECISIONS/0008-a-context-owns-its-store.md
- 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md
@@ -72,3 +74,36 @@ page that led with the third would bury the first:
as it was and what is wrong is in what was sent; failed means it is in a state nobody declared and
what is wrong is on the machine. They are fixed in different places, so a page that said "error"
for both would send half its readers to the wrong one.
## What was built
*2026-08-31.*
**One reading, three ways of saying it.** The questions are asked once, by one function, and
answered as a person's `status`, as its JSON, and as this page. Three implementations of *which
machine is not doing what it was told* would be three chances to disagree about it — and the
disagreement would surface as two people looking at two screens arguing about which machine is
broken.
**It holds nothing and changes nothing.** Every request reads the mesh now. There is no cache to
go stale, no table of what the mesh looked like last time, and no button: every action a board
could offer already exists as a command, and one that did something no command does would be a
second implementation of a decision.
**It never touches a context's store.** That is the whole constraint above, kept: the board is a
client of the same functions the commands use, so provisioning can change its tables without the
change being weighed against a page.
**A board that cannot read the mesh says so.** An empty page says *nothing is wrong* in the one
situation where nobody can know that, so the failure is rendered instead — and it says explicitly
that it is a statement about the page rather than about the mesh.
**A machine's own words are shown, and are not markup.** They are the whole reason the page is
useful — a board that said only *failed* would send a person to ask the thing they opened the
board to avoid asking. They are also the only text on the page that nobody in this repository
wrote, which is why the escaping is a test rather than an assumption.
*Checked by giving a machine a declaration it cannot apply and requiring the page to name that
machine, say `failed` rather than `error`, and quote what the host said — then by comparing the
page's own JSON against the command's, because two answers to "which machine is broken" would be
worse than either alone.*