From 6374c1eb6087d823c55b10b4bfed5b3048009378 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 05:28:11 +0200 Subject: [PATCH] Record what "behind" means now It meant failed-or-refused, so the question this record says must not be lost was answerable only for the machines that broke. Out of date, never told, and not worked out are kept apart: the remedy is the same push and they read differently to whoever is looking. --- 03-DESIGN/01-to-be/10-delivery.md | 34 +++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/03-DESIGN/01-to-be/10-delivery.md b/03-DESIGN/01-to-be/10-delivery.md index ee10bc4..1f6db5a 100644 --- a/03-DESIGN/01-to-be/10-delivery.md +++ b/03-DESIGN/01-to-be/10-delivery.md @@ -181,3 +181,37 @@ Not aspirations — things without which the above does not work: - **How the control plane upgrades itself.** It declares its own new version and the host applies it — but if the new one is broken, the thing that would fix it is the thing that is broken. The host has a launcher for exactly this; the control plane has nothing. + +## What "behind" means, and what it used to mean + +*2026-08-31.* + +The risk this record names is losing **did my change go out?** — answerable today by opening a +pipeline, and something has to replace it or the comparison is worse to live with whatever its +other properties. + +**It was answerable only for the machines that broke.** `push --behind` meant *failed or refused*, +so a machine that applied cleanly and whose declaration has since changed was not behind. For every +machine that worked, the answer was silence — and silence meant both *your change is running there* +and *your change has not been sent*, which is the question unanswered rather than answered. + +**So the mesh records a digest of what it last sent each machine.** A digest rather than the +declaration: what a machine should be is recomputable at any moment, and a stored copy would be a +second account of it, able to disagree with the first. What cannot be recomputed is what was +*actually sent*. + +**Recorded after the send.** A digest kept for something that failed to send would make the machine +look current for a declaration it never received — the failure mode this is meant to remove, +arrived at from the other side. + +**Three situations, kept apart**, because they read differently to whoever is looking even where +the remedy is the same push: + +| | | +|---|---| +| **out of date** | it was sent something, and the mesh would now send something else | +| **never told** | nobody has ever asked this machine to be anything | +| **not worked out** | the mesh cannot say what it should be — not reported here at all, because saying "waiting" about it would invent a comparison. `plan` is where that is answered | + +**`status` says it and `push --behind` acts on it**, and both because the alternative is a flag that +knows something the person reading the status does not.