ADR 0110: admit the-private-network, claimed by a manifest the control plane composes in code

The enumeration behind the first set read manifests in two repositories and missed a claim made
in the control plane's own code: the private-network module it ships claims the-private-network at
node scope. A closed set without it would refuse the control plane's own module. Thirteen claims in
use, naming twelve seats.
This commit is contained in:
jochen
2026-09-25 20:35:31 +02:00
parent dbe100ca96
commit c4cac767f8
2 changed files with 11 additions and 7 deletions
@@ -25,12 +25,13 @@ The names in use were each invented by the module that claims them: `the-showcas
lists seats. Holdings are assembled while planning, one node at a time, and discarded afterwards. lists seats. Holdings are assembled while planning, one node at a time, and discarded afterwards.
The only way to answer "which seats does this mesh have, and which module holds each" is to read The only way to answer "which seats does this mesh have, and which module holds each" is to read
every manifest in two repositories, because the core modules' manifests moved into the control every manifest in two repositories, because the core modules' manifests moved into the control
plane's own repository ([ADR 0069](0069-a-module-is-a-repository-and-a-path.md)). While this record plane's own repository ([ADR 0069](0069-a-module-is-a-repository-and-a-path.md)), and then the
was being prepared, that enumeration was done once by hand, and it missed the control plane's own control plane's code, because one module it ships has its manifest composed there. While this
manifest: eleven claims were reported where there are twelve. record was being prepared, that enumeration was done by hand, and it missed both of the last two
sources: eleven claims were reported where there are thirteen.
**Some seats are the mesh's one of something that others consume, and nothing uses that fact.** **Some seats are the mesh's one of something that others consume, and nothing uses that fact.**
Of the twelve claims, four are held by a module that provides something consumers require: Of the thirteen claims, four are held by a module that provides something consumers require:
`mesh-store` (`postgres-database`, eleven consumers), `mesh-broker` (`amqp`), `the-artifact-store` `mesh-store` (`postgres-database`, eleven consumers), `mesh-broker` (`amqp`), `the-artifact-store`
(`artifact-store`) and `the-dns-port`. The rest deliver nothing to anybody, and are still (`artifact-store`) and `the-dns-port`. The rest deliver nothing to anybody, and are still
meaningful: they say which module is this mesh's packet filter, or resolver configuration. meaningful: they say which module is this mesh's packet filter, or resolver configuration.
@@ -85,9 +86,10 @@ requires the provision still resolves to the holder without anybody naming it.
and which assignment holds it, including seats nobody holds. An unheld seat is an answer, "this mesh and which assignment holds it, including seats nobody holds. An unheld seat is an answer, "this mesh
has no X", not an error. has no X", not an error.
**The first set is the eleven seats already claimed, plus one.** Twelve claims are in use, and they **The first set is the twelve seats already claimed, plus one.** Thirteen claims are in use, and
name eleven seats because two alternative modules claim `the-resolver-configuration`. This record they name twelve seats because two alternative modules claim `the-resolver-configuration`. This
admits every seat the catalogue and the control plane claim today, so no module is refused by it: record admits every seat the catalogue and the control plane claim today, so no module is refused
by it:
| seat | scope | delivers | held today by | made a seat by | | seat | scope | delivers | held today by | made a seat by |
|---|---|---|---|---| |---|---|---|---|---|
@@ -101,6 +103,7 @@ admits every seat the catalogue and the control plane claim today, so no module
| `the-dns-port` | node | — | `dnsmasq` | this record | | `the-dns-port` | node | — | `dnsmasq` | this record |
| `the-intrusion-prevention` | node | — | `fail2ban` | this record | | `the-intrusion-prevention` | node | — | `fail2ban` | this record |
| `the-packet-filter` | node | — | `nftables` | this record | | `the-packet-filter` | node | — | `nftables` | this record |
| `the-private-network` | node | — | the control plane's private-network module | this record |
| `the-resolver-configuration` | node | — | `resolv-conf` or `resolved-split-dns` | this record | | `the-resolver-configuration` | node | — | `resolv-conf` or `resolved-split-dns` | this record |
| `the-showcase` | node | — | `showcase` | this record | | `the-showcase` | node | — | `showcase` | this record |
+1
View File
@@ -56,6 +56,7 @@ argued for is an entry nobody can explain.
| `the-dns-port` | node | — | the local resolver | | `the-dns-port` | node | — | the local resolver |
| `the-intrusion-prevention` | node | — | an intrusion-prevention service | | `the-intrusion-prevention` | node | — | an intrusion-prevention service |
| `the-packet-filter` | node | — | the packet filter | | `the-packet-filter` | node | — | the packet filter |
| `the-private-network` | node | — | the private network the mesh runs over |
| `the-resolver-configuration` | node | — | whichever of the alternative resolver configurations is chosen | | `the-resolver-configuration` | node | — | whichever of the alternative resolver configurations is chosen |
| `the-showcase` | node | — | the showcase module | | `the-showcase` | node | — | the showcase module |