ADR 0187: a module's own code is bundles in any language, and a tools bundle speaks MCP to the runtime; design 38 gains WP1b
The operator's direction, absent from every record until now: the SDK must not limit who writes a module; tools and services may be written in any language; one module may ship several bundles (tools, a seat's implementation, a daemon); skeleton first, a full implementation when the work requires it. ADR 0175 had the runtime import a bundle, which only JavaScript can be. 0187 makes a tools bundle a process the node's runtime launches and speaks MCP over stdio to — the vocabulary the runtime already speaks outward — so any language with an MCP library can write one today and the mesh's SDK per language is thin; the transport stays in the runtime (0039's refusal, kept). Importing a TypeScript bundle is the shortcut, not the contract. Notes in 0175, 0039 and 0150 say where their mechanism moved; design 38 records WP1 as built and adds WP1b (the launcher and the skeleton SDKs); the glossary's bundle widens.
This commit is contained in:
@@ -11,6 +11,7 @@ decisions:
|
||||
- 02-DECISIONS/0177-a-unit-may-be-user-scoped-and-the-service-manager-is-a-node-seat.md
|
||||
- 02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md
|
||||
- 02-DECISIONS/0149-the-live-mesh-is-the-test-bed.md
|
||||
- 02-DECISIONS/0187-a-modules-own-code-is-bundles-in-any-language-and-a-tools-bundle-speaks-mcp-to-the-runtime.md
|
||||
---
|
||||
|
||||
# 38. Building the operator's machine
|
||||
@@ -97,6 +98,19 @@ what `tools` answers, and the others serve. The runtime reads `MESH_OPERATOR_ACC
|
||||
five tools and two seat verbs answer on their subjects; `tools` names the failed bundle; a
|
||||
membership republished mid-run re-subscribes without a restart.
|
||||
|
||||
*Built and proven 2026-10-02* (mesh-tools, branch `feat/the-operators-machine`, commit `6390d1d`).
|
||||
|
||||
**WP1b — the launcher beside the loader** ([ADR 0187](../../02-DECISIONS/0187-a-modules-own-code-is-bundles-in-any-language-and-a-tools-bundle-speaks-mcp-to-the-runtime.md)).
|
||||
*mesh-tools, mesh-sdk. A day for the skeleton.* A bundle whose entry is not JavaScript is launched
|
||||
as a child process with the runtime's environment and spoken to over MCP on stdio: `tools/list`
|
||||
once, `tools/call` per call; a tool named `<seat>.<verb>` is the seat's implementation. A child
|
||||
that exits is named as a failed bundle and restarted on the next call. The TypeScript import stays
|
||||
as the shortcut. Beside it, one skeleton SDK per language of the first set — the stdio loop and the
|
||||
tool-definition type, nothing else — each proven by one bundle in that language answering one tool
|
||||
in the runtime's test. **Proof.** The runtime's test: a bundle in a second language, launched, its
|
||||
tool answering on its subject over a real bus; the TypeScript fixture served through the protocol
|
||||
with the shortcut off answers the same.
|
||||
|
||||
## WP2 — The controller composes one runtime per node
|
||||
|
||||
*mesh-controller. Two to three days; the largest package.*
|
||||
@@ -111,12 +125,15 @@ membership republished mid-run re-subscribes without a restart.
|
||||
declaration gains an `archive` placed under a directory the controller derives, so the host
|
||||
fetches and unpacks it as it does any artifact. The bundle's digest is what the build recorded.
|
||||
3. **The runtime's process.** One `process` per node running the runtime from its own bundle
|
||||
(WP3), `MESH_TOOL_MODULES` composed from the unpacked entrypoints, `MESH_OPERATOR_ACCOUNT` and
|
||||
(WP3), `MESH_TOOL_MODULES` composed from the unpacked entrypoints — each as
|
||||
`<module>=<path>`, and the runtime decides from the file whether it is loaded or launched
|
||||
(WP1b) — `MESH_OPERATOR_ACCOUNT` and
|
||||
`MESH_OPERATOR_HOME` from the account fact, `restart-on` naming every bundle so a push that
|
||||
changes one restarts it. A node with no account composes the runtime without the two words.
|
||||
4. **The gate.** A manifest declaring `tools` and a container built on the runtime's base image is
|
||||
refused at registration once the runtime module is registered, naming this record. It is the
|
||||
mechanism that keeps the old pattern from returning by habit.
|
||||
mechanism that keeps the old pattern from returning by habit. ADR 0187 widens it, after WP4:
|
||||
a module whose own code is an image artifact is refused, whatever image it is built on.
|
||||
|
||||
**Proof.** Composition tests: a node with three assigned modules, one holding a seat, yields one
|
||||
process, three archives, one node principal whose grants are the union, and the same three
|
||||
|
||||
Reference in New Issue
Block a user