The bus is the only broker; step 1 starts

A module does declare requirements the provisioner fulfils — but the broker
it gets that way is a private vhost, the analog of a database, not the
mesh's bus. Two modules of the new mesh depend on it, so the compatibility
broker was never single-purpose and its retirement would have stranded them.

NATS is the heart: one bus, a module's messaging is subjects on it scoped by
what it declares, and no module is handed a server of its own. The seat
delivers nothing; the interface retires with the broker. Also closes the
EVENTS question — one stream, on the bootstrap argument, not preference.

Designs 25 and 28 go in-progress: step 1 is starting.

The insight check caught a false positive on its own first real use — its
bold-run pattern crossed newlines and joined an unrelated `**` to the
marker. Constrained to one line, still catching all four bad shapes.
This commit is contained in:
2026-09-26 19:26:07 +02:00
parent db4ca9b043
commit 814c9e563f
6 changed files with 177 additions and 9 deletions
+20 -5
View File
@@ -1,6 +1,6 @@
---
layer: to-be
status: proposed
status: in-progress
code:
- mesh-controller internal/link (to be replaced)
- mesh-host internal/link (to be replaced)
@@ -10,6 +10,7 @@ code:
updated: 2026-09-26
decisions:
- 02-DECISIONS/0106-the-bus-is-nats.md
- 02-DECISIONS/0117-the-bus-is-the-only-broker.md
- 02-DECISIONS/0116-the-bus-is-built-in-five-steps.md
- 02-DECISIONS/0074-the-wire-is-specified-not-the-types.md
- 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
@@ -188,8 +189,19 @@ current. Nothing is declared as `reload-on` or `restart-on` for this resource at
Its guard is the same rule as the AMQP broker's: the monitoring port is refused from anything but
the private network. It is raised at genesis like the store, adopted as a module in the same
phase. The predecessor's AMQP broker remains a module of its own, `lavinmq-compat`, with a single
purpose and a retirement condition: no client connected for a period the operator sets.
phase. The predecessor's AMQP broker remains a module of its own, `lavinmq-compat`, with a
retirement condition: no client connected for a period the operator sets.
**And with one purpose, which it did not have when this was written.** Revision, second review
([ADR 0117](../../02-DECISIONS/0117-the-bus-is-the-only-broker.md)): two modules of the new mesh
required a broker *of their own* from it — a private vhost per consumer, the analog of
database-per-login, which is a different thing from the mesh's bus and was never examined here.
**There is one bus, and no module is handed a broker as a resource.** A module's messaging is
subjects on the bus under its own account, scoped by its `emits` and `consumes`; a module that
wants a queue of its own has a subject nothing else may publish to and a durable consumer, both
from its declaration. What it does not get is a server of its own. The `amqp` interface retires
with the compatibility broker instead of gaining a successor, and the two modules move to the bus
in step 4.
## 6. Joining: the enrolment handshake
@@ -398,8 +410,11 @@ find what changed and why.
**Still open:**
- Whether EVENTS should be one stream or one per emitting module (retention per module vs. one
policy). One stream is proposed; the review may disagree.
- ~~Whether EVENTS should be one stream or one per emitting module.~~ **Closed**
([ADR 0117](../../02-DECISIONS/0117-the-bus-is-the-only-broker.md)): one stream, and not as a
preference — the streams the bus is made of are composed as configuration before any module
runs, because a provisioner is itself a module that needs a bus account to start. Bootstrapping
decides it.
- The heartbeat interval and the controller's "quiet" threshold on core NATS without persistence —
the same numbers as today are proposed.
- Whether the person's client is a catalogue module (runs on an enrolled workstation node) or a
+6 -2
View File
@@ -1,11 +1,15 @@
---
layer: to-be
status: proposed
code: []
status: in-progress
code:
- mesh-catalog modules/nats
- mesh-controller internal/catalogue
- mesh-lab scenarios
updated: 2026-09-26
decisions:
- 02-DECISIONS/0116-the-bus-is-built-in-five-steps.md
- 02-DECISIONS/0106-the-bus-is-nats.md
- 02-DECISIONS/0117-the-bus-is-the-only-broker.md
- 02-DECISIONS/0074-the-wire-is-specified-not-the-types.md
- 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md