ADR 0145: a module checks what the mesh claims is reachable, and it checks itself
The mesh asserts three things are callable and has never checked any of them. A module on every machine serves an endpoint of its own and dials every other machine's, from the position the callers are in — not the host and not the control plane, both of which reach those addresses by paths no ordinary caller uses and would have passed throughout the outage. Its probe is its own endpoint, declared reachable over the private network, so it is admitted by exactly the rule that governs every internally-exposed service. The tempting target is a service every machine has, and those are the ones never closed — ssh above all — which would have passed for all eleven hours. Resolution and connection reported separately, because they have different owners. One failure is not a fault, and the count travels with the result. It reports and repairs nothing. Built on a scheduled container, a rendered roster fact and a bundle: no new vocabulary. Adopted on its own merits, which is what 0143 was not.
This commit is contained in:
@@ -225,6 +225,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0141** — [The host delivers its own successor, and versions live side by side](0141-the-host-delivers-its-own-successor.md)
|
||||
- **0143** — [A consumer verifies the grant it is given](0143-a-consumer-verifies-the-grant-it-is-given.md) *(superseded)*
|
||||
- **0144** — [Anything on a machine may call anything on it, and that is the whole of "local"](0144-anything-on-a-machine-may-call-anything-on-it.md)
|
||||
- **0145** — [A module checks what the mesh claims is reachable, and it checks itself](0145-a-module-checks-what-the-mesh-claims-is-reachable.md)
|
||||
|
||||
### How it is built
|
||||
|
||||
|
||||
Reference in New Issue
Block a user