ADR 0110: admit the-private-network, claimed by a manifest the control plane composes in code

The enumeration behind the first set read manifests in two repositories and missed a claim made
in the control plane's own code: the private-network module it ships claims the-private-network at
node scope. A closed set without it would refuse the control plane's own module. Thirteen claims in
use, naming twelve seats.
This commit is contained in:
jochen
2026-09-25 20:35:31 +02:00
parent dbe100ca96
commit c4cac767f8
2 changed files with 11 additions and 7 deletions
@@ -25,12 +25,13 @@ The names in use were each invented by the module that claims them: `the-showcas
lists seats. Holdings are assembled while planning, one node at a time, and discarded afterwards.
The only way to answer "which seats does this mesh have, and which module holds each" is to read
every manifest in two repositories, because the core modules' manifests moved into the control
plane's own repository ([ADR 0069](0069-a-module-is-a-repository-and-a-path.md)). While this record
was being prepared, that enumeration was done once by hand, and it missed the control plane's own
manifest: eleven claims were reported where there are twelve.
plane's own repository ([ADR 0069](0069-a-module-is-a-repository-and-a-path.md)), and then the
control plane's code, because one module it ships has its manifest composed there. While this
record was being prepared, that enumeration was done by hand, and it missed both of the last two
sources: eleven claims were reported where there are thirteen.
**Some seats are the mesh's one of something that others consume, and nothing uses that fact.**
Of the twelve claims, four are held by a module that provides something consumers require:
Of the thirteen claims, four are held by a module that provides something consumers require:
`mesh-store` (`postgres-database`, eleven consumers), `mesh-broker` (`amqp`), `the-artifact-store`
(`artifact-store`) and `the-dns-port`. The rest deliver nothing to anybody, and are still
meaningful: they say which module is this mesh's packet filter, or resolver configuration.
@@ -85,9 +86,10 @@ requires the provision still resolves to the holder without anybody naming it.
and which assignment holds it, including seats nobody holds. An unheld seat is an answer, "this mesh
has no X", not an error.
**The first set is the eleven seats already claimed, plus one.** Twelve claims are in use, and they
name eleven seats because two alternative modules claim `the-resolver-configuration`. This record
admits every seat the catalogue and the control plane claim today, so no module is refused by it:
**The first set is the twelve seats already claimed, plus one.** Thirteen claims are in use, and
they name twelve seats because two alternative modules claim `the-resolver-configuration`. This
record admits every seat the catalogue and the control plane claim today, so no module is refused
by it:
| seat | scope | delivers | held today by | made a seat by |
|---|---|---|---|---|
@@ -101,6 +103,7 @@ admits every seat the catalogue and the control plane claim today, so no module
| `the-dns-port` | node | — | `dnsmasq` | this record |
| `the-intrusion-prevention` | node | — | `fail2ban` | this record |
| `the-packet-filter` | node | — | `nftables` | this record |
| `the-private-network` | node | — | the control plane's private-network module | this record |
| `the-resolver-configuration` | node | — | `resolv-conf` or `resolved-split-dns` | this record |
| `the-showcase` | node | — | `showcase` | this record |
+1
View File
@@ -56,6 +56,7 @@ argued for is an entry nobody can explain.
| `the-dns-port` | node | — | the local resolver |
| `the-intrusion-prevention` | node | — | an intrusion-prevention service |
| `the-packet-filter` | node | — | the packet filter |
| `the-private-network` | node | — | the private network the mesh runs over |
| `the-resolver-configuration` | node | — | whichever of the alternative resolver configurations is chosen |
| `the-showcase` | node | — | the showcase module |