From 5fb8f06a912c31e000b505e4b346b516171e1fb1 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 10:34:17 +0200 Subject: [PATCH] Issue 072: the controller's manifest exists twice; decisions index regenerated for ADR 0086 --- 02-DECISIONS/README.md | 1 + .../00-report.md | 39 +++++++++++++++++++ 2 files changed, 40 insertions(+) create mode 100644 04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md diff --git a/02-DECISIONS/README.md b/02-DECISIONS/README.md index 1207c69..0a51db1 100644 --- a/02-DECISIONS/README.md +++ b/02-DECISIONS/README.md @@ -153,6 +153,7 @@ python3 00-META/checks/index.py fail if stale - **0069** — [A module is a repository and a path within it](0069-a-module-is-a-repository-and-a-path.md) - **0076** — [The SDK is a published package, and the toolchain resolves it by version](0076-the-sdk-is-a-published-package.md) - **0082** — [The registry is reached by name, and the overlay is its security](0082-the-registry-is-reached-by-name-and-trusted-by-the-overlay.md) +- **0086** — [A secret reaches a process as a file, and an exception is declared](0086-a-secret-reaches-a-process-as-a-file.md) ### How it is checked diff --git a/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md b/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md new file mode 100644 index 0000000..da50482 --- /dev/null +++ b/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md @@ -0,0 +1,39 @@ +--- +status: located +opened: 2026-09-21 +located-in: [mesh-controller module.json, mesh-catalog modules/mesh-controller/module.json, mesh-host internal/bootstrap] +fixed-by: +amended-design: +--- + +# The controller's manifest exists twice, and nothing keeps the copies equal + +## Symptom, as observed + +The control plane's manifest lives at the root of its own repository, where the mesh reads it +whenever it builds the controller from source, and again in the catalogue under +`modules/mesh-controller`, where the installer reads it at genesis. The two differ only in how the +image is named — a build section in one, a placeholder digest in the other — and are otherwise +meant to be the same document. + +Changing the catalogue copy alone (to make the controller read its credentials from files, +[ADR 0086](../../02-DECISIONS/0086-a-secret-reaches-a-process-as-a-file.md)) produced a mesh that +installed correctly and then could not be pushed to: the first rebuild of the controller from +source replaced the mesh's record with the repository's copy, which still carried the old shape, +and every later push of the node was refused on the controller's behalf. `status` reported the +machine as doing what it was told throughout, because nothing had been sent. + +## Why it matters beyond this instance + +- **One module, two sources of truth.** [ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md) + says a module is a repository and a path; the controller has two paths, and which one the mesh + believes depends on which command last touched it. +- **The failure is silent at the wrong layer.** The divergence surfaces as a resolution refusal + on an unrelated push, not as a warning that the copies differ. +- **It will happen again** to whoever next edits the controller's manifest for any reason. + +## What would close it + +Either the catalogue copy goes and genesis reads the controller's manifest from the controller's +repository (the installer already has the checkout, since it builds from it), or a check refuses +two copies that differ outside the image lines. The first is the honest one.