diff --git a/00-META/repos.md b/00-META/repos.md index 7b07323..f1ac765 100644 --- a/00-META/repos.md +++ b/00-META/repos.md @@ -21,7 +21,7 @@ and a forge address is an operational detail (see [`README`](../README.md)). ## What the mesh becomes [ADR 0019](../02-DECISIONS/0019-how-this-repository-works.md) records the repositories the -monorepo decomposes into. **`mesh-lab` and `mesh-host` exist so far** — the lab is built first +monorepo decomposes into. **`mesh-lab`, `mesh-host` and `mesh-control` exist so far** — the lab is built first ([ADR 0016](../02-DECISIONS/0016-the-lab.md)); the rest are the target, not the present. @@ -29,7 +29,7 @@ target, not the present. |---|---|---| | `mesh-host` | 0 | **exists.** The node host — one statically linked binary, requiring nothing present ([ADR 0005](../02-DECISIONS/0005-the-node-host.md)) | | `mesh-substrate` | 1 | the four pinned services, as declarations | -| `mesh-control` | 2 | the control plane and its contexts | +| `mesh-control` | 2 | **exists.** The control plane and its contexts — one of seven built ([ADR 0024](../02-DECISIONS/0024-running-the-control-plane.md)) | | `mesh-surfaces` | 3 | tools, web, cli | | `mesh-sdk` | — | contracts shared across tiers | | `mesh-lab` | — | **exists.** The lab — scenario lifecycle, networking, placement. Ships to nobody; runs on a workstation. | diff --git a/03-DESIGN/01-to-be/06-the-control-plane.md b/03-DESIGN/01-to-be/06-the-control-plane.md index 771a776..ff18258 100644 --- a/03-DESIGN/01-to-be/06-the-control-plane.md +++ b/03-DESIGN/01-to-be/06-the-control-plane.md @@ -1,14 +1,15 @@ --- layer: to-be status: designed -code: [] -updated: 2026-08-27 +code: + - mesh-control +updated: 2026-08-29 decisions: + - 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md - 02-DECISIONS/0005-the-node-host.md - 02-DECISIONS/0006-the-substrate-and-the-control-plane.md + - 02-DECISIONS/0008-a-context-owns-its-store.md - 02-DECISIONS/0019-how-this-repository-works.md - - 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md - - 02-DECISIONS/0006-the-substrate-and-the-control-plane.md --- # The control plane @@ -69,6 +70,13 @@ and [research 006](../../01-RESEARCH/006-mesh-from-scratch/skeleton.md) leaves * unresolved — putting it in the substrate risks recreating the circularity the tier design just removed. Listing it here would settle by naming what has not been settled by arguing. +**One of the seven is built.** `inventory` owns a database of that name and holds the node records; +the rest do not exist. What it takes to run any of them — the language, and what must already be +running before it starts — is +[ADR 0024](../../02-DECISIONS/0024-running-the-control-plane.md), which also records where the +build stopped and why: at **identity**, because what a node presents to prove who it is is not +decided anywhere, and a migration is the most expensive place in this system to guess. + **These are contexts, not services.** They are separate in the sense that matters — each owns its own store, and they integrate through the record rather than by reading one another ([`how-we-build`](../../00-META/how-we-build.md) §4). They are not separate deployables, and diff --git a/03-DESIGN/01-to-be/09-the-node-lifecycle.md b/03-DESIGN/01-to-be/09-the-node-lifecycle.md index 5f30a18..047a5e4 100644 --- a/03-DESIGN/01-to-be/09-the-node-lifecycle.md +++ b/03-DESIGN/01-to-be/09-the-node-lifecycle.md @@ -134,9 +134,17 @@ to link to and nothing to apply. It answers `profile`, `inventory` and `version` nox-mesh-host enrol --token ``` -The token carries three things and is carried by a person +The token carries **four** things and is carried by a person ([ADR 0004](../../02-DECISIONS/0004-a-node-and-how-it-joins.md)): the broker's -address, the fingerprint to expect, and the right to join once. +address, the fingerprint to expect, **the control plane's signing identity**, and the right to +join once. + +**The fourth is the one this document listed three of.** A node connects to the broker and takes +instruction from the control plane behind it, and those are two different identities. Pinning only +the broker would make the control plane's authority *transitive* — a compromised broker could then +forge declarations, which, since the host applies whatever the link delivers, is the whole machine. +So the transport is verified once at connect, and **each declaration is verified by its signature, +every time**. What happens, in order: