diff --git a/02-DECISIONS/0117-a-machines-uplink-is-a-seat.md b/02-DECISIONS/0117-a-machines-uplink-is-a-seat.md index 3cbbbbb..79a2f57 100644 --- a/02-DECISIONS/0117-a-machines-uplink-is-a-seat.md +++ b/02-DECISIONS/0117-a-machines-uplink-is-a-seat.md @@ -34,9 +34,9 @@ by accident: - **The private network's interface is exposed to the manager.** A manager that considers every interface its own may try to configure `mesh0`, or tear it down on a profile change. Nothing tells it not to. -- **Two managers on one machine go unnoticed.** Of the four machines adopted so far, one runs - systemd-networkd, two run NetworkManager, and one runs NetworkManager *and* dhcpcd at once: - two programs that each believe they own the machine's addresses and its resolver file. +- **Two managers on one machine go unnoticed.** Among the machines adopted so far, one runs + NetworkManager *and* dhcpcd at once: two programs that each believe they own the machine's + addresses and its resolver file. Nothing detected it, because nothing in the mesh knows the role exists. The machines differ in a way that matters: servers are wired and never move, while @@ -72,13 +72,16 @@ other: - the manager's package, and its service running and enabled at boot; - the manager's own configuration that leaves the resolver file to the mesh (`dns=none` for - NetworkManager, `nohook resolv.conf` for dhcpcd, and for systemd-networkd the equivalent - that stops it handing DNS to a resolver the machine does not use); + NetworkManager, `nohook resolv.conf` for dhcpcd, and nothing for systemd-networkd, which + never writes the resolver file); - the manager's own configuration that leaves the private network's interface alone - (NetworkManager's `unmanaged-devices` naming `mesh0`; for systemd-networkd, no network file - of the module's matches it); + (NetworkManager's `unmanaged-devices` naming `mesh0`; dhcpcd's `denyinterfaces mesh0`; for + systemd-networkd a network file of the module's matching `mesh0` as `Unmanaged=yes`); - each as a drop-in beside the manager's main file where the manager reads one, and written - *into* a shared file otherwise ([ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md)); + *into* a shared file otherwise, as a marked region the host owns + ([ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md)'s idea for text files), + placed where the manager reads it as global — at the start of `dhcpcd.conf`, above any + `interface` line, because every line after one belongs to that interface; - the service **reloaded** when a drop-in changes, never restarted — a restart drops the link, and the link is the mesh's own channel to the machine. **A manager that cannot reload is not restarted instead:** its setting takes effect at the manager's next start. Measured on the @@ -102,11 +105,23 @@ them, and the module's `access`, if it needs one, is read-only. replaced under another name. - A machine running two managers is found at assignment: the second holder is refused, and the operator decides which manager the machine keeps before either module is taken. -- Workstations keep joining networks the way they always have. The host already cooperates - with the manager — its dispatcher hook wakes it on every connectivity change — and nothing - here changes that. +- Workstations keep joining networks the way they always have. Under NetworkManager and + systemd-networkd the host already cooperates with the manager — its dispatcher hook wakes it + on every connectivity change — and nothing here changes that. A dhcpcd-only machine has no + such hook, and nothing here adds one. - The seat table gains one entry: `the-uplink`, node scope, delivering nothing, decided here. - **Not decided here:** whether the mesh should ever *offer* known networks to a machine — a sealed, add-only list the operator curates once for all workstations. That is a different question (the mesh holding credentials for links it must never be able to break) and gets its own record if it is wanted. + +## References + +- [ADR 0110](0110-a-seat-is-a-module-assignment-from-a-closed-set.md): the closed set this seat joins; + [to-be 26](../03-DESIGN/01-to-be/26-the-seats.md): the seat table +- [ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md): written into, never over +- [ADR 0051](0051-shared-data-is-the-operators.md): what is the operator's stays the operator's +- mesh-controller `internal/catalogue/seats.go` (the seat), `internal/overlay/generator.go` (the + mesh installs on top of the machine's own networking) +- mesh-catalog `modules/networkmanager`, `modules/systemd-networkd`, `modules/dhcpcd` +- mesh-host `internal/apply/block.go` (a file written into a marked region, `at` start or end) diff --git a/03-DESIGN/01-to-be/26-the-seats.md b/03-DESIGN/01-to-be/26-the-seats.md index 65dc1b9..bf2317d 100644 --- a/03-DESIGN/01-to-be/26-the-seats.md +++ b/03-DESIGN/01-to-be/26-the-seats.md @@ -8,11 +8,12 @@ code: - mesh-controller cmd/mesh-controller/source.go - mesh-controller internal/inventory/migrations/0032-a-source-may-live-on-a-seat.sql - mesh-catalog modules/gitea/module.json -updated: 2026-09-26 +updated: 2026-09-27 decisions: - 02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md - 02-DECISIONS/0111-a-build-source-is-on-the-git-seat-or-external.md - 02-DECISIONS/0109-a-package-registry-seat-is-one-per-ecosystem.md + - 02-DECISIONS/0117-a-machines-uplink-is-a-seat.md --- # 26 — The seats @@ -64,6 +65,7 @@ nobody argued for is an entry nobody can explain. | `the-private-network` | node | — | the private network the mesh runs over | | `the-resolver-configuration` | node | — | whichever of the alternative resolver configurations is chosen | | `the-showcase` | node | — | the showcase module | +| `the-uplink` | node | — | the program that manages the machine's own network ([ADR 0117](../../02-DECISIONS/0117-a-machines-uplink-is-a-seat.md)) | The controller holds this set in code, and a test asserts both its size and that every entry names the record that made it a seat. **This table and [ADR 0110](../../02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md)