Issue 295: use the glossary's words (ADR 0244)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

This commit is contained in:
jochen
2026-10-07 20:24:59 +02:00
parent be8ea16d28
commit 998980bbda
@@ -43,7 +43,7 @@ The mesh's own record shows it:
- **What each machine reports.** `postgres.server`, `mongodb.server` and nine `mailu.*` containers
have run only since 18:57 on the control node, and `postgres.server` since 18:56 on the anchor.
No release plan was involved. The sends were the plan's own sends to its first machines.
No walk held back for later was involved. The sends were the plan's own sends to its first machines.
## Why it happened
@@ -57,18 +57,18 @@ No release plan was involved. The sends were the plan's own sends to its first m
push". So the gate did not judge the recorded builds, the refusal of ungated sends did not see
them, and the gated send carried them. `record` held only against the end of a person's push to
another machine (issue 259's `heldBack`) and against the bus (the bus step). It did not hold
against a plan, a release plan, a rollback, a healer or a rotation.
against a plan's walk, a rollback, a healer or a rotation.
3. **Nothing tells a person, before or during a send, that it will recreate every container of a
module at once.** A change that only alters how containers are declared reads as harmless. A
health check, an environment variable or a label each recreates the container all the same,
and the node-engine applies a module's containers together. The change plan said mail
and the node-engine applies a module's containers together. The delivery plan said mail
"receives" a build. Nothing said its service would be interrupted, and mail's policy let a plan
decide when.
## What is at stake
`record` is how the mesh keeps the providers, the network path and the irreplaceable data out of
unattended rollout. Tonight showed that it holds only until some other module on the same machine
unattended walks. Tonight showed that it holds only until some other module on the same machine
rolls out. This was still true after the incident: plex (`record`, irreplaceable data) was rebuilt
by a media-catalogue merge at 19:01 and sent nowhere. The next gated send to the anchor, for any
module, would recreate it.