From a7b2db9efc1067314fffa79e88f5ef647d9ac4fc Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 26 Sep 2026 14:28:23 +0200 Subject: [PATCH] Accept ADR 0110 and ADR 0111; the seats design is in progress MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The seats half of to-be 27's review is settled, so the two records it rests on are accepted and the vocabulary catches up: the glossary's *seat* becomes a named role from a closed set, held by an assignment and possibly delivering a provision, and 23 — Choosing a provider gains the seat step in resolution, with ambiguity still refused rather than guessed. Both were held back when 0110 was proposed, because a document may not rest on a record that is not accepted. 26 — The seats moves to in-progress rather than designed: it names the files that implement it, and naming a file claims implementation, which is only defensible once those files are on the owning repositories' main branches. It becomes implemented when mesh-controller #63 and mesh-catalog #69 land. 0112, 0113 and 0114 stay proposed; to-be 27 stays proposed with them. --- 00-META/glossary.md | 15 +++++++++++---- ...at-is-a-module-assignment-from-a-closed-set.md | 2 +- ...build-source-is-on-the-git-seat-or-external.md | 2 +- 02-DECISIONS/README.md | 4 ++-- 03-DESIGN/01-to-be/23-choosing-a-provider.md | 14 +++++++++++--- 03-DESIGN/01-to-be/26-the-seats.md | 2 +- 6 files changed, 27 insertions(+), 12 deletions(-) diff --git a/00-META/glossary.md b/00-META/glossary.md index 7d38f6d..4ffe66e 100644 --- a/00-META/glossary.md +++ b/00-META/glossary.md @@ -44,15 +44,22 @@ another — and a mesh you cannot name precisely is a mesh two people describe d ## How modules relate to the mesh -- **seat** — a named position at a scope (node / site / mesh) with a **capacity**. A capacity-1 seat - is exclusive (one holder); a higher-capacity seat is a **bench** (several holders coexist). +- **seat** — a named role at a scope (node / site / mesh), held by a module assignment, from a + **closed set** the mesh defines: a claim naming a seat outside the set is refused. A seat may + **deliver a provision**, and its holder is then the mesh's answer for it when several modules + provide it ([ADR 0110](../02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md)). + The set, with who holds each seat, is the overview of what a mesh has + ([26 — The seats](../03-DESIGN/01-to-be/26-the-seats.md)). A seat has a **capacity**: a + capacity-1 seat is exclusive (one holder); a higher-capacity seat is a **bench** (several holders + coexist). - **claim** — a module taking a spot on a seat. `claims: [{name, scope}]` in a manifest. A mesh-scoped exclusive claim is how the mesh says "there is one of me". A foundation seat is named after the server it guards: the `mesh-controller`, `postgres` and `lavinmq` modules claim the `mesh-controller`, `mesh-store` and `mesh-broker` seats ([ADR 0079](../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md)). - **provision** — a service one module `provides` and others `require`; the mesh resolves a provider - and wires the two with an endpoint and a credential. This is separate from seats: a provision is - a service you offer, a seat is a slot you occupy. + and wires the two with an endpoint and a credential. A provision is a service you offer, a seat + is a role you occupy, and the two meet where a seat delivers a provision: occupying the seat is + what makes a module *the* provider of it. ## How this page is kept diff --git a/02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md b/02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md index 3101efb..ec85827 100644 --- a/02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md +++ b/02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md @@ -1,6 +1,6 @@ --- topic: what runs on it -status: proposed +status: accepted date: 2026-09-25 deciders: jochen reconstructed: false diff --git a/02-DECISIONS/0111-a-build-source-is-on-the-git-seat-or-external.md b/02-DECISIONS/0111-a-build-source-is-on-the-git-seat-or-external.md index 5cb4f14..02fb432 100644 --- a/02-DECISIONS/0111-a-build-source-is-on-the-git-seat-or-external.md +++ b/02-DECISIONS/0111-a-build-source-is-on-the-git-seat-or-external.md @@ -1,6 +1,6 @@ --- topic: building it -status: proposed +status: accepted date: 2026-09-25 deciders: jochen reconstructed: false diff --git a/02-DECISIONS/README.md b/02-DECISIONS/README.md index dd3835f..6b46026 100644 --- a/02-DECISIONS/README.md +++ b/02-DECISIONS/README.md @@ -156,7 +156,7 @@ python3 00-META/checks/index.py fail if stale - **0087** — [A seeded file is created once, and what grows in it is not the mesh's](0087-a-seeded-file-is-created-once.md) - **0091** — [A mount is declared, and there are three things it can be](0091-a-mount-is-declared-three-ways.md) - **0099** — [A step that runs once names what it reads, and runs again when it changed](0099-a-step-that-runs-once-names-what-it-reads.md) -- **0110** — [A seat is held by one assignment, from a closed set, and it may deliver a provision](0110-a-seat-is-a-module-assignment-from-a-closed-set.md) *(proposed)* +- **0110** — [A seat is held by one assignment, from a closed set, and it may deliver a provision](0110-a-seat-is-a-module-assignment-from-a-closed-set.md) - **0112** — [A module definition names no node, no mesh and no path: everything it needs is a requirement the mesh resolves](0112-a-module-definition-names-no-node-mesh-or-path.md) *(proposed)* - **0113** — [The vault makes every shared secret, a provider makes resources and data, and the mesh carries both](0113-the-vault-makes-every-secret.md) *(proposed)* - **0114** — [A credential two parties hold rotates over two credentials; one a single party holds rotates in place, staged; and retiring a credential never removes what it reached](0114-a-shared-credential-rotates-over-two-credentials.md) *(proposed)* @@ -179,7 +179,7 @@ python3 00-META/checks/index.py fail if stale - **0096** — [An upstream image is copied between registries, never through a machine's image store](0096-an-upstream-image-is-copied-between-registries.md) - **0097** — [A vendor image is a declared build input, and a recipe fetches nothing undeclared](0097-a-vendor-image-is-a-declared-build-input.md) - **0107** — [Persistent data is a directory bind, never a named volume](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md) -- **0111** — [A build source is on the mesh's git seat, or it is an external repository](0111-a-build-source-is-on-the-git-seat-or-external.md) *(proposed)* +- **0111** — [A build source is on the mesh's git seat, or it is an external repository](0111-a-build-source-is-on-the-git-seat-or-external.md) ### How it is checked diff --git a/03-DESIGN/01-to-be/23-choosing-a-provider.md b/03-DESIGN/01-to-be/23-choosing-a-provider.md index 50b3ed3..e3f36c0 100644 --- a/03-DESIGN/01-to-be/23-choosing-a-provider.md +++ b/03-DESIGN/01-to-be/23-choosing-a-provider.md @@ -2,10 +2,11 @@ layer: to-be status: designed code: [] -updated: 2026-09-20 +updated: 2026-09-25 decisions: - 02-DECISIONS/0084-which-provider-serves-a-consumer.md - 02-DECISIONS/0027-a-provision-names-what-the-consumer-is-coupled-to.md + - 02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md --- # 23 — Choosing a provider @@ -50,9 +51,16 @@ provider on a different node. That coupling is exactly what may not be guessed, names the provider. Naming it is also what makes a later move safe — the mesh knows the binding is to that provider and not to whichever one is nearest. +**A seat names the mesh's one provider of a kind.** Where a seat delivers the provision, its holder +answers for it when several providers exist and the consumer named none. That is not picking: the +choice was made once, mesh-wide, by assigning the holder, rather than once per consumer by naming it +([ADR 0110](../../02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md), +[26 — The seats](26-the-seats.md)). A named provider still wins over the seat, because a consumer +coupled to particular contents has said so. + **Ambiguity is refused, never resolved by picking.** If several providers of a kind exist, none is -named, and none is co-located, the requirement is unsatisfiable and is refused with the candidates -shown — the same stance +named, none is co-located, and no seat delivers it, the requirement is unsatisfiable and is refused +with the candidates shown — the same stance [ADR 0027](../../02-DECISIONS/0027-a-provision-names-what-the-consumer-is-coupled-to.md) took against a confidently-wrong match, applied to the instance rather than the dialect. A wrong answer delivered quietly costs more than a refusal. diff --git a/03-DESIGN/01-to-be/26-the-seats.md b/03-DESIGN/01-to-be/26-the-seats.md index 3baacb3..facbfae 100644 --- a/03-DESIGN/01-to-be/26-the-seats.md +++ b/03-DESIGN/01-to-be/26-the-seats.md @@ -1,6 +1,6 @@ --- layer: to-be -status: proposed +status: in-progress code: - mesh-controller internal/catalogue/seats.go - mesh-controller internal/catalogue/resolve.go