Consolidate: 65 decision records to 23
Every remaining cluster merged. Each was one design that had been split across
several records because it was worked out over days rather than at once.
the node host 8 -> 1 applies not decides, depends on nothing,
per operating system, root service, the
launcher, episodic, what a declaration is,
actions from the bundle only
a node and how it joins 4 -> 1 what a node is, joining, the link as
security boundary, the enrolment token
modules and the graph 7 -> 1 everything is a module, no domain modules,
three edges, provisioning, the core library
substrate and control 6 -> 1 the test, seven contexts, one control plane,
plane the authority is not a database, the named
products, the pinned bundle
connectivity 3 -> 1 a route is a grant, reachability declared,
filter rules
delivery 5 -> 1 reconciliation not a pipeline, artifacts,
the three silos, a failed step, the verdict
the lab 5 -> 1 (earlier)
how this repository 10 -> 1 (earlier)
works
Nothing was dropped. Each consolidated record carries the reasoning of the ones
it absorbs -- the measurements, the incidents, the alternatives rejected --
because that reasoning is the only reason to keep a record at all. What is gone
is the fragmentation: eight files to read to understand tier 0, when tier 0 is
one component.
The four superseded records went too. They existed to point at their
successors, and the successors now contain what they said.
The checker made this safe. Each merge left dangling links -- 38 files after
the host merge alone -- and it named every one. Nothing was found by reading,
and a manual pass would certainly have missed some, including references inside
AGENTS.md which every session loads.
This commit is contained in:
@@ -31,7 +31,7 @@ exists to catch — a step that failed, reported success, and left the next step
|
||||
state that was never produced.
|
||||
|
||||
It is also a direct violation of a decision already taken and recorded:
|
||||
[ADR 0008](../../02-DECISIONS/0008-a-failed-step-fails-the-job.md) says a step that fails must fail the
|
||||
[ADR 0058](../../02-DECISIONS/0058-delivery.md) says a step that fails must fail the
|
||||
job. That record notes the rule is applied instance by instance and enforced by no mechanism.
|
||||
This is an instance where it was never applied.
|
||||
|
||||
|
||||
@@ -35,7 +35,7 @@ node recovers itself.
|
||||
## Scope
|
||||
|
||||
**The as-is only.** The design being built has a different answer:
|
||||
[ADR 0061](../../02-DECISIONS/0061-the-host-asks-an-init-for-start-and-restart.md) puts recovery
|
||||
[ADR 0037](../../02-DECISIONS/0037-the-node-host.md) puts recovery
|
||||
in a launcher that supervises the host, and that recovery is tested — 32 assertions, each
|
||||
confirmed to fail when the behaviour is removed.
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ amended-design:
|
||||
|
||||
Two accepted decisions collide, and the collision makes one resource shape untestable.
|
||||
|
||||
- **[ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)** pins images by
|
||||
- **[ADR 0048](../../02-DECISIONS/0048-the-substrate-and-the-control-plane.md)** pins images by
|
||||
digest, and the host **refuses** an image reference that is not pinned:
|
||||
|
||||
```
|
||||
@@ -66,7 +66,7 @@ for.
|
||||
## The shape of a resolution
|
||||
|
||||
**A registry inside the scenario**, on its public segment, that machines pull from. That is not a
|
||||
workaround: it is what the real mesh does — [ADR 0048](../../02-DECISIONS/0048-the-substrate-is-named.md)
|
||||
workaround: it is what the real mesh does — [ADR 0048](../../02-DECISIONS/0048-the-substrate-and-the-control-plane.md)
|
||||
names an OCI registry as substrate, and every node after the first pulls from the mesh's own.
|
||||
Testing against a registry is testing the real path rather than a stand-in for it.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user