diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 98b2253..ab5593e 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -674,10 +674,12 @@ healthy while reacting to nothing. server, and the controller binary was run on the node directly until the managed container could be rebuilt over the bus it was on. -- [ ] 5.3 **the seat changes hands as one act.** A command takes a seat and the assignment taking it +- [x] 5.3 **the seat changes hands as one act.** A command takes a seat and the assignment taking it over, and the seat is never empty in between — the emptiness is the outage of 2026-09-27, when the control plane, which finds its own bus through this seat, lost the address and looped. - Today only `seat rename` exists. This is what 5.2 uses to move `mesh-broker` from the old + **Built 2026-09-27** (`seat_holding`, migration 0039; design 26 says how it is checked), and used + live the next night to hand `mesh-broker` from the old broker's assignment to the new one's. This + is what 5.2 uses to move `mesh-broker` from the old broker's assignment to the new one's, and it is built first ([ADR 0131](../../02-DECISIONS/0131-everything-on-the-mesh-speaks-to-the-broker-seat.md)). - [x] 5.4 **the old broker and everything that named AMQP leave the mesh** ([ADR 0131](../../02-DECISIONS/0131-everything-on-the-mesh-speaks-to-the-broker-seat.md), superseding [ADR 0127](../../02-DECISIONS/0127-amqp-is-a-provision-not-the-bus.md)): the two modules that