From 7abb268de68ad92a23bdd854edc30a22210556fa Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 26 Sep 2026 21:03:35 +0200 Subject: [PATCH] Step 1 done but for its bed 1.1 to 1.4 built and tested. 1.5 turned out to need no controller change: it already resolves the broker by seat and names no broker module in its source, which is what ADR 0079 was for. The genesis module set naming is scenario and installer config, carried with the bed. Recorded what must NOT change yet: the amqps:// credential shape and the 5671 default are correct until the rollout, because steps 1-4 leave every node on AMQP. --- 03-DESIGN/01-to-be/28-building-the-bus.md | 28 +++++++++++++++++------ 1 file changed, 21 insertions(+), 7 deletions(-) diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 78f1924..1bea5a2 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -130,23 +130,37 @@ defined. The mesh this is for will never travel this path — it is already runn — but genesis is the definition every other path is measured against, and one that exists only on paper is wrong until there is a second mesh to find out. -- [ ] 1.1 the `nats` module: manifest, image, one container, its client, TLS and monitoring ports, +- [x] 1.1 the `nats` module: manifest, image, one container, its client, TLS and monitoring ports, JetStream on a named volume — the shape of design 25 §5, and the same shape the broker module beside it already has -- [ ] 1.2 the composed configuration as a **directory** resource, and the entrypoint that watches +- [x] 1.2 the composed configuration as a **directory** resource, and the entrypoint that watches the one file and signals the server itself — design 25 §5's correction, kept inside the module because a container has no reload and a recreate would drop every connection the mesh has -- [ ] 1.3 the controller composes that file: accounts, permissions, TLS, JetStream — a user's +- [x] 1.3 the controller composes that file: accounts, permissions, TLS, JetStream — a user's permissions derived from its declaration and nothing else, over the three namespaces of [design 29](29-what-a-module-declares.md) §2, plus its own ack subject and its own inbox prefix (design 25 §4) -- [ ] 1.4 the mesh's own streams, created at genesis and asserted idempotently on start, by the +- [x] 1.4 the mesh's own streams, created at genesis and asserted idempotently on start, by the controller as their only writer — **the mesh's own, not all of them**: a seat's streams are created when the module declaring it is registered, and a module's durable consumers when it is assigned, so this task is the fixed foundation set and 3.x carries the derived rest -- [ ] 1.5 genesis raises it as foundation, claiming the seat **`mesh-broker`** — the seat is the - server's role, not the product -- [ ] 1.6 the genesis-broker bed +- [x] 1.5 genesis raises it as foundation, claiming the seat **`mesh-broker`** — the seat is the + server's role, not the product. **Already true of the controller and needed no change**: it + resolves the broker by seat ("that is where the broker is, whatever else the topology says") + and names no broker module anywhere in its source. What remains is naming `nats` instead of + the AMQP broker where a genesis module set is declared, which is scenario and installer + configuration — carried with 1.6 rather than before it. +- [ ] 1.6 the genesis-broker bed — **deferred**: beds are run once, at the end, rather than per + step (novox/hq design 22's rule, and the operator's instruction). Every claim step 1 makes + is covered by a unit test or was demonstrated against the real server; what the bed adds is + the claims that need a mesh. + +> **Not done here, deliberately.** The controller builds a module's broker credential as an +> `amqps://` URL and defaults a portless genesis address to 5671. Those are correct until the +> rollout and must not move: steps 1 to 4 leave every node on AMQP +> ([ADR 0116](../../02-DECISIONS/0116-the-bus-is-built-in-five-steps.md)), so changing the +> credential's shape now would break the running bus to serve a bus nothing speaks yet. They +> change with the links, in step 3. **Done when.** A mesh raised from nothing has the server standing with the streams asserted and every account and permission composed from the manifests; a user cannot publish outside its