Fix what the records review found

The glossary's authority page still named the controller's seat the-controller in two
entries, contradicting its own seat section after ADR 0079; issue 058's heading kept the
pre-renumber 059; 055's fixed-by named branches that stop existing after merge (now merge
commits/PRs) and its located-in listed file paths where the convention wants repos; 056's
located-in named mesh-host, which received no fix, instead of mesh-catalog; and the design
layer never said the one-store/one-broker property is enforced — 07-the-foundation and the
installation table now state the seats.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-17 22:24:57 +02:00
parent 5856555390
commit 94fee5d849
6 changed files with 15 additions and 10 deletions
+2 -2
View File
@@ -9,7 +9,7 @@ another — and a mesh you cannot name precisely is a mesh two people describe d
- **node** — a machine in the mesh. There are 0..n of them, and each runs the host agent. A node is - **node** — a machine in the mesh. There are 0..n of them, and each runs the host agent. A node is
just a machine that has joined; being one implies nothing about what it runs. just a machine that has joined; being one implies nothing about what it runs.
- **control-node** — the one node that also holds the `the-controller` seat. There is exactly one - **control-node** — the one node that also holds the `mesh-controller` seat. There is exactly one
per mesh. "control-node" is not a separate kind of machine — it is a node that additionally runs per mesh. "control-node" is not a separate kind of machine — it is a node that additionally runs
the controller (and, today, the foundation). Lose it and the other nodes keep running what they the controller (and, today, the foundation). Lose it and the other nodes keep running what they
were last told; they simply cannot be told anything new. were last told; they simply cannot be told anything new.
@@ -21,7 +21,7 @@ another — and a mesh you cannot name precisely is a mesh two people describe d
- **controller** — the component that decides what each node should be, holds the mesh's records, - **controller** — the component that decides what each node should be, holds the mesh's records,
and tells nodes over the broker. Replaces **"control plane"** (borrowed from networking's and tells nodes over the broker. Replaces **"control plane"** (borrowed from networking's
control-plane/data-plane, and opaque here). control-plane/data-plane, and opaque here).
- **mesh-controller** — the module that runs the controller. It **claims** the `the-controller` - **mesh-controller** — the module that runs the controller. It **claims** the `mesh-controller`
seat at mesh scope, which is what makes it singular. Replaces the module name **`mesh-control`**. seat at mesh scope, which is what makes it singular. Replaces the module name **`mesh-control`**.
(The git repository has been renamed `mesh-control` -> `mesh-controller` on the forge; the module, (The git repository has been renamed `mesh-control` -> `mesh-controller` on the forge; the module,
container and image it produces are `mesh-controller`.) container and image it produces are `mesh-controller`.)
+6
View File
@@ -23,6 +23,12 @@ decisions:
# The foundation # The foundation
**One store, one broker — enforced, not conventional.** Each foundation module claims a
mesh-scoped seat named after its server (`mesh-store`, `mesh-broker`, `mesh-controller` —
[ADR 0079](../../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md)), so
assigning a second holder anywhere in the mesh is refused at resolution rather than silently
raising a second server.
Tier 1. Defined the same way [the controller](06-the-controller.md) is, because the same Tier 1. Defined the same way [the controller](06-the-controller.md) is, because the same
gap applied: the word was load-bearing and unpinned. gap applied: the word was load-bearing and unpinned.
@@ -129,8 +129,8 @@ two.
| # | module | provides | note | | # | module | provides | note |
|---|---|---|---| |---|---|---|---|
| 1 | `postgres` | `postgres-database` | **the controller's own records and every module's.** One server, not two | | 1 | `postgres` | `postgres-database` | **the controller's own records and every module's.** One server, not two — it *claims* the mesh-scoped `mesh-store` seat, so a second is refused |
| 2 | `lavinmq` | `amqp` | the broker every node dials, and what modules are granted vhosts on | | 2 | `lavinmq` | `amqp` | the broker every node dials, and what modules are granted vhosts on — *claims* `mesh-broker`, one per mesh |
| 3 | `mesh-controller` | *claims* `mesh-controller` | decides what runs where | | 3 | `mesh-controller` | *claims* `mesh-controller` | decides what runs where |
| 4 | `distribution` | `artifact-store` | what the mesh built, pinned by digest — the module is the software (Distribution), the provision is the job | | 4 | `distribution` | `artifact-store` | what the mesh built, pinned by digest — the module is the software (Distribution), the provision is the job |
| 5 | `builder` | — | turns source into artifacts | | 5 | `builder` | — | turns source into artifacts |
@@ -2,10 +2,9 @@
status: resolved status: resolved
opened: 2026-09-16 opened: 2026-09-16
located-in: located-in:
- mesh-controller/cmd/mesh-controller/modules.go - mesh-controller
- mesh-controller/cmd/mesh-controller/build.go - mesh-catalog
- mesh-catalog/modules/lavinmq/module.json fixed-by: mesh-controller PR 27 (5718add); mesh-catalog PR 24 (a24362b)
fixed-by: mesh-controller multi-node/broker-reaches-over-overlay; mesh-catalog fix/broker-declares-amqps-port
amended-design: amended-design:
--- ---
@@ -1,7 +1,7 @@
--- ---
status: resolved status: resolved
opened: 2026-09-17 opened: 2026-09-17
located-in: [mesh-controller, mesh-host] located-in: [mesh-controller, mesh-catalog]
fixed-by: mesh-catalog + mesh-controller (the foundation modules claim mesh-scoped seats) fixed-by: mesh-catalog + mesh-controller (the foundation modules claim mesh-scoped seats)
amended-design: 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md amended-design: 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
--- ---
@@ -6,7 +6,7 @@ fixed-by:
amended-design: amended-design:
--- ---
# 059 — A provisioner runtime crash-loops until the overlay is up # 058 — A provisioner runtime crash-loops until the overlay is up
## Symptom ## Symptom