diff --git a/02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md b/02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md new file mode 100644 index 0000000..ec30e2e --- /dev/null +++ b/02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md @@ -0,0 +1,64 @@ +--- +topic: the mesh +status: accepted +date: 2026-09-27 +deciders: jochen +reconstructed: false +extends: 02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md +--- + +# 122. The predecessor is ending, and its broker goes with it + +## Context + +[ADR 0119](0119-amqp-is-a-provision-not-the-bus.md) settled that the old broker is an ordinary +provider of the `amqp` provision rather than a compatibility module with an end date. It rejected +giving it a retirement condition, and said why: *"its clients are not only the predecessor's, so the +retirement condition describes a day that will not come."* + +**The operator has said that day is coming.** The predecessor is deprecated. Some of it is still +running, and it is not being migrated — it is being left to stop. Its broker may be shut down. + +That is a fact about this installation, not a change of mind about what a broker is. It is recorded +because three documents reason from the premise it overturns: +[design 25](../03-DESIGN/01-to-be/25-the-bus-on-nats.md) §5 and §9, and +[design 28](../03-DESIGN/01-to-be/28-building-the-bus.md)'s closing note that the predecessor's world +"does not need to move: its broker is the compatibility module until its last client is gone." + +## Decision + +**The predecessor's broker retires when nothing requires `amqp`, by being unassigned like any other +provider.** No retirement condition, no end-date machinery, no special case — which is ADR 0119 being +paid off rather than revised. Because that record made the broker an ordinary provider, ending it +needs nothing that does not already exist: a provision with no consumers has its provider unassigned, +and the module system has done that since it existed. + +**So step 5.3 has an ending.** "The mesh's own accounts removed from the deprecated broker" was +written as the last thing that could be said, because the broker itself was going to outlive the +question. It now finishes: once the mesh's own traffic has moved and the predecessor's remnants have +stopped, the module is unassigned and the port is free. + +**And the transitional doubling has a date.** The build outcome is announced under both the module's +name and the role's on the old bus, so that a catalogue deployed before the rename and one deployed +after both hear it. That exists only while the old bus does, and goes with it. + +## Consequences + +**The remote access path goes with it, and that is the one practical consequence worth planning +around.** The predecessor's own mesh communicates over that broker — so shutting it down ends the +tooling that reaches this installation's machines remotely. Work on the node after that point is done +from the node. **This matters most for the rollout**, which is the step that would otherwise be driven +from a workstation: it has to be driven locally, or driven before the broker stops. + +**What is still running on it stops when it stops.** Some of the predecessor's services are live and +are not being moved. That is the operator's decision and it is recorded here so that nobody later reads +a broker with clients as an accident. + +**Nothing in a served request's path is affected.** Modules serve from their own containers; the mesh's +bus carries the mesh's own traffic — declarations, reports, events, tool calls. This was checked rather +than assumed when the question came up, and it is why the operator's position (*"as long as my services +keep running"*) is a bounded risk rather than a gamble. + +**One reason to keep the broker survives**: `amqp` remains a provision a module may require, and a +module that genuinely needs an AMQP broker can be given one. What retires is *this* broker's role as +the predecessor's, not the mesh's ability to provide the thing. diff --git a/02-DECISIONS/README.md b/02-DECISIONS/README.md index 7c325c6..f7647e0 100644 --- a/02-DECISIONS/README.md +++ b/02-DECISIONS/README.md @@ -137,6 +137,7 @@ python3 00-META/checks/index.py fail if stale - **0119** — [AMQP is a provision, not the bus](0119-amqp-is-a-provision-not-the-bus.md) - **0120** — [The mesh bus is required, not ambient](0120-the-mesh-bus-is-required-not-ambient.md) - **0121** — [A seat carries the protocol of its role](0121-a-seat-carries-the-protocol-of-its-role.md) +- **0122** — [The predecessor is ending, and its broker goes with it](0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md) ### Its tiers, from the bottom up diff --git a/03-DESIGN/01-to-be/25-the-bus-on-nats.md b/03-DESIGN/01-to-be/25-the-bus-on-nats.md index 8613129..ea550da 100644 --- a/03-DESIGN/01-to-be/25-the-bus-on-nats.md +++ b/03-DESIGN/01-to-be/25-the-bus-on-nats.md @@ -19,6 +19,7 @@ decisions: - 02-DECISIONS/0083-one-push-leaves-the-mesh-consistent.md - 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md - 02-DECISIONS/0121-a-seat-carries-the-protocol-of-its-role.md + - 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md --- # 25. The bus on NATS @@ -311,6 +312,15 @@ foundation, never raised at genesis, installed when something wants it and absen that does not. There is no retirement condition, because the day its last client disappears is not a day anything is waiting for. +**Revised 2026-09-27** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)): +**that day is coming.** The predecessor is deprecated — some of it still running, none of it being +migrated, left to stop rather than moved — so the broker retires once nothing requires `amqp`. Still no +retirement *condition* and no end-date machinery: a provision with no consumers has its provider +unassigned, which is the ordinary mechanism and is ADR 0119 being paid off rather than revised. What +also goes with it is the tooling that reaches this installation's machines remotely, because the +predecessor's own mesh talks over that broker — so the rollout is driven from the node, or before the +broker stops. + What is deprecated is AMQP as **the mesh's transport**, which is this whole document. The rule that remains is about direction rather than software: *inter-module communication goes over the bus.* A module may hold a broker, a database or a cache for itself; it may not use one as a diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 21877ad..065e3fd 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -15,6 +15,7 @@ decisions: - 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md - 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md - 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md + - 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md --- # 28. Building the bus @@ -657,8 +658,20 @@ reserves them for after the move, and a flow built ahead of its design would be > *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That > is worth knowing before rather than after, and it is why the operator's "as long as my services > keep running" is a reasonable position rather than a gamble. -- [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing - of the mesh speaks to it, and an account nothing uses is one nobody rotates +- [ ] 5.3 the mesh's own accounts removed from the deprecated broker, and then the broker itself: + after the rollout nothing of the mesh speaks to it, and an account nothing uses is one nobody + rotates. **It finishes now** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)): + the predecessor is deprecated rather than kept, so once its remnants have stopped the module is + unassigned and the port is free. No retirement machinery — a provision with no consumers has its + provider unassigned, which is ADR 0119 being paid off rather than revised. + + Retiring with it: the build outcome's second announcement under the module's own name, which + exists only so a catalogue deployed before the rename and one deployed after both hear it. + + > **The remote tooling goes with it too.** The predecessor's own mesh talks over that broker, so + > shutting it down ends the path that reaches this installation's machines from a workstation. + > The rollout has to be driven from the node, or driven before the broker stops — which is a + > sequencing constraint on 5.2 and not an afterthought. > **5.4 is gone, and was wrong from ADR 0119 onward.** It read "the deprecated broker retires > when its condition holds — no client connected for the period the operator sets", which is @@ -685,8 +698,10 @@ itself moves once, at the end, on one day. - **Observation** — research 017's, after the move, by its own design. - **Leaf nodes** — design 25 §11 keeps this out of scope and says so; a leaf per machine is a later question, noted so it is not forgotten. -- **The predecessor's world.** It is AMQP, it cannot move, and it does not need to: its broker is - the compatibility module until its last client is gone. +- **The predecessor's world.** It is AMQP and it is not moving — + [ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md): it is + deprecated, some of it is still running, and it is being left to stop rather than migrated. Its + broker goes with it, unassigned like any provider whose provision nothing requires. ## How this list is kept true