ADR 0112 and issue 118: address the review
- Secrets follow ADR 0085 as amended: a module's own secret is a provision the controller mints and the vault records. The previous commit had that backwards. Whether the vault should generate instead is recorded as an open question, not decided. - A directory's contract is owner and mode only. The persistence flag was the keep flag ADR 0030 refused; a directory is kept while it holds anything, and disposable data is a named volume (0107). - An operator's shared data stays an access (ADR 0051), which rejected an operator-owned directory. Only where its path is written moves to the assignment. - The records it changes on acceptance are named: 0051, 0091, 0046 (settings keyed by instance), 0084 (a provider is a node and an instance), and the glossary, which gains its new words only when the record is accepted. - How it is checked covers every stated rule. Container-side paths are no longer flagged by the host-path rule, and code fallbacks are covered. - Provisions are what other modules provide. A seat's occupant is not listed as one, and the vault is not described as selectable per assignment. - 'Control plane' becomes 'controller'. The provider count is ten of eleven, not eleven of twelve.
This commit is contained in:
@@ -42,9 +42,10 @@ line, a literal in module code.
|
||||
- **The mesh's own wire carries host paths into containers.** Each contribution names its
|
||||
consumer's credential as "the file on this machine holding that consumer's credential", a host
|
||||
path computed from the provider's grants directory. So every provider has to mount that directory
|
||||
at the *identical* path, or it cannot read what it was given. Eleven of the twelve providers do.
|
||||
It is a convention nothing states or checks, and the twelfth is the provider above.
|
||||
- **The warning that would have caught it is lost in the SDK.** The control plane always writes the
|
||||
at the *identical* path, or it cannot read what it was given. Ten of the eleven providers with a
|
||||
grants directory do. It is a convention nothing states or checks, and the eleventh is the
|
||||
provider above.
|
||||
- **The warning that would have caught it is lost in the SDK.** The controller always writes the
|
||||
contributions file, even when empty, so a provider can tell "nothing asked" from "never written".
|
||||
The SDK's reconcile loop treats an unreadable file as empty, and logs nothing.
|
||||
- **Code carries copies with nothing checking them.** Several modules default a path in code when an
|
||||
|
||||
Reference in New Issue
Block a user