diff --git a/02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md b/02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md index e8023af..12761a0 100644 --- a/02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md +++ b/02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md @@ -131,6 +131,32 @@ the plan says it too. | Genesis raises the forge as its module declares it | a genesis test that raises, assigns, and finds the module holding rather than raising a second | | Live | the next cutover on an adopted machine: `take` shows the comparison, refuses the downgrade if there is one, and the service keeps its configuration and its secret | +## Built, 2026-10-02 + +> **Progressive insight — 2026-10-02.** The decision stands; these are the facts of its building. + +Built across mesh-host 63 and 64 and mesh-controller 201, 202 and the pull request that followed +them. Rule 1: `take` previews every held thing's comparison and ends with a digest; `take --yes +` acts on exactly that preview, and a changed preview or an account older than the flip +allows is refused, as the flip's are. A published port's reach is said as the machine reported it, +behind the found firewall whose rules are not read. Rule 2: an older image, a differing file and a +minted, unaccepted secret for found data refuse, overridden by `--downgrade`, `--replace ` and +`--mint `; the secrets a module holds on a machine are read with where each came from. Rule 3: +`secret accept --provider` reaches a required secret. Rule 4: the per-machine setting is `networks`, +a container id to the found networks it keeps; judged for an adopted machine only, joined by the host +after the container runs, part of the container's spec, named in the preview. Rule 5: the host's +facts, former targets and strays. Rule 6: one judgement, run where a setting is stored and where a +machine is composed; a module whose stored setting its definition can no longer compose is left out +of the declaration, the envelope says so, the host keeps that module's things, and `plan` and `push` +say it by name. A key that reaches nothing is refused where stored and said by `plan`, and never +costs a module. Rule 7: genesis raises the forge under the module's container name, with its image +digest and its data directory; the network is the one difference left, said by the take, because the +bootstrap forge reaches the store on the machine's loopback. + +**Not yet proven live.** Every machine of this mesh is converged, so the table's last row — a take +on an adopted machine — waits for the next adoption. What is live is what the rows above it check. +Issues 086, 098, 099, 100 and 101 stay located until that row is read. + ## References - [ADR 0100](0100-a-node-in-use-is-adopted-before-it-is-converged.md), [ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md), [ADR 0103](0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md), [ADR 0104](0104-a-provision-may-be-answered-by-an-adapter-to-the-predecessor.md), [ADR 0162](0162-a-merge-produces-a-tiered-plan-the-mesh-keeps.md) diff --git a/03-DESIGN/01-to-be/05-the-node-host.md b/03-DESIGN/01-to-be/05-the-node-host.md index c01ca0a..9e5bc82 100644 --- a/03-DESIGN/01-to-be/05-the-node-host.md +++ b/03-DESIGN/01-to-be/05-the-node-host.md @@ -2,7 +2,7 @@ layer: to-be status: in-progress code: [mesh-host] -updated: 2026-10-01 +updated: 2026-10-02 decisions: - 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md - 02-DECISIONS/0141-the-host-delivers-its-own-successor.md @@ -163,6 +163,19 @@ a resource's former targets, removes a container or file it wrote under a name t longer names, never removes what was found, and reports what runs on the machine that it neither wrote nor holds. *How it is checked:* ADR 0163's table. +**What the host joins, keeps and raises for a take** — revision, 2026-10-02 +([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 4, 6 and 7). A +container may name networks it also joins once it runs — the found network a per-machine setting keeps +for a taken container while a neighbour still resolves it there; joined after the run, part of the +container's spec, refused when it cannot be joined. A declaration may name the modules the mesh left +out of it because a stored setting cannot compose with the module's definition: the host keeps what it +wrote and holds for a left-out module and says so, where absence used to read as removal. And genesis +raises the bootstrap forge under the forge module's container name, with the module's image digest and +its data directory, so the module holds it by the found rule; the network is the one difference a take +has left to say. *How it is checked:* a host test joins a kept network and refuses one it cannot; a +host test keeps a left-out module's record and hold and removes an absent module's; a bootstrap test +holds the installer's constants to the module's manifest where the catalogue is checked out beside it. + **Found reaches every kind that can touch what the machine has** ([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)). For a module not yet taken, a directory present with no record keeps its mode and owner, a unit present with no record keeps its state and boot setting, a diff --git a/03-DESIGN/01-to-be/09-the-node-lifecycle.md b/03-DESIGN/01-to-be/09-the-node-lifecycle.md index 00fec44..760c393 100644 --- a/03-DESIGN/01-to-be/09-the-node-lifecycle.md +++ b/03-DESIGN/01-to-be/09-the-node-lifecycle.md @@ -8,7 +8,7 @@ code: - mesh-host packaging/nox-mesh-host-network.sh - mesh-controller internal/token - mesh-controller internal/inventory/nodes.go -updated: 2026-10-01 +updated: 2026-10-02 decisions: - 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md - 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md @@ -323,6 +323,21 @@ network are said. `take --yes ` cuts over what was previewed, as the fli container may keep a found network by a per-machine setting while its neighbours are not yet taken. *How it is checked:* ADR 0163's table. +**A setting is judged where it is stored, and the take's words** — revision, 2026-10-02 +([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1, 2, 4 and 6). +The preview ends with a digest of what it said; `take --yes ` acts on that preview and nothing +else, and a preview that has changed since, or an account of the machine older than the flip allows, is +refused as the flip's is. A module the machine holds nothing for has nothing to compare, and `--yes` +suffices. The overrides are `--downgrade`, `--replace ` and `--mint `; the per-machine +setting that keeps a found network is `networks`, a container id to the networks it keeps, accepted +for an adopted machine only. Storing a setting composes it against the module's current definition and +refuses, naming node, module, layer and key, what cannot compose or reaches nothing. A definition that +later moves under a stored setting costs that module its place in the machine's declaration, said by +name in `plan`, `push` and the declaration itself, and the machine is told everything else; a stray +setting no longer refuses the machine where it is read. *How it is checked:* controller tests over the +one judgement — refused where stored, a module left out where composed, the envelope naming it — and +over a take's digest, staleness and secrets. + A candidate machine is not empty. It has a package manager, probably a container runtime, configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md) says the host never touches what it did not create — adoption is the deliberate act of taking diff --git a/04-ISSUES/086-taking-a-module-narrows-a-port-without-saying-so/00-report.md b/04-ISSUES/086-taking-a-module-narrows-a-port-without-saying-so/00-report.md index 96c0f40..ccaef78 100644 --- a/04-ISSUES/086-taking-a-module-narrows-a-port-without-saying-so/00-report.md +++ b/04-ISSUES/086-taking-a-module-narrows-a-port-without-saying-so/00-report.md @@ -40,3 +40,9 @@ it changes before it changes it, and for taking a module this one does not. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the preview names a narrowing. Building follows, host first, then the controller's `take`. + +## Built, 2026-10-02 + +mesh-controller 201 and the pull request after it: the preview names it, and `take --yes ` +acts on the preview that was read. Stays located until a take is read on an adopted machine — every +machine of this mesh is converged today, so the record's live row has not been run. diff --git a/04-ISSUES/090-the-forge-module-does-not-take-over-the-forge-genesis-raised/00-report.md b/04-ISSUES/090-the-forge-module-does-not-take-over-the-forge-genesis-raised/00-report.md index 2bbf181..ca624a7 100644 --- a/04-ISSUES/090-the-forge-module-does-not-take-over-the-forge-genesis-raised/00-report.md +++ b/04-ISSUES/090-the-forge-module-does-not-take-over-the-forge-genesis-raised/00-report.md @@ -53,3 +53,13 @@ network, or it is not a takeover. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 7: genesis raises as the module declares. Building follows, host first, then the controller's `take`. + +## Built in part, 2026-10-02 + +mesh-host 64: genesis raises the forge under the module's container name (`gitea`), pinned to the +module's image digest, with the module's data directory mounted at `/data` — so the module finds it, +holds it, and a take compares equal images and the same data. A test holds the installer's constants +to the module's manifest where the catalogue is checked out beside it. The network is the difference +left: the bootstrap forge runs on the machine's network to reach the store on its loopback, the module +runs bridged and publishes its ports, and the take says so. Closing waits for group 9's genesis test — +a mesh raised, the module assigned, and the module found holding rather than raising a second forge. diff --git a/04-ISSUES/096-a-setting-that-cannot-work-is-stored-and-stops-the-node/00-report.md b/04-ISSUES/096-a-setting-that-cannot-work-is-stored-and-stops-the-node/00-report.md index dcc65ab..a8601ec 100644 --- a/04-ISSUES/096-a-setting-that-cannot-work-is-stored-and-stops-the-node/00-report.md +++ b/04-ISSUES/096-a-setting-that-cannot-work-is-stored-and-stops-the-node/00-report.md @@ -1,8 +1,8 @@ --- -status: located +status: resolved opened: 2026-09-23 located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)] -fixed-by: +fixed-by: mesh-controller (the pull request after 201: JudgeSettings, LeftOut), mesh-host 64 (left_out kept) amended-design: --- @@ -63,3 +63,12 @@ knowing the code. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 6: judged where stored; an impossible statement costs a module. Building follows, host first, then the controller's `take`. + +## Resolved, 2026-10-02 + +One judgement, in the catalogue, run where a setting is stored and where a machine is composed. Stored, +a setting that cannot compose with the module's current definition is refused naming the node, the +module, the layer and the key; a key that reaches nothing is refused there too. Composed, a definition +that moved under a stored setting leaves that module out of the machine's declaration — the envelope +names it, the host keeps what it holds and wrote for it, `plan` and `push` say it — and the machine is +told everything else. A stray setting no longer refuses the whole machine where it is read. diff --git a/04-ISSUES/097-a-resource-that-changes-target-leaves-the-old-one-behind/00-report.md b/04-ISSUES/097-a-resource-that-changes-target-leaves-the-old-one-behind/00-report.md index 4486ced..56bf272 100644 --- a/04-ISSUES/097-a-resource-that-changes-target-leaves-the-old-one-behind/00-report.md +++ b/04-ISSUES/097-a-resource-that-changes-target-leaves-the-old-one-behind/00-report.md @@ -1,8 +1,8 @@ --- -status: located +status: resolved opened: 2026-09-23 located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)] -fixed-by: +fixed-by: mesh-host 63 (former targets removed, strays reported), mesh-controller 201/202 (strays shown) amended-design: --- @@ -80,3 +80,11 @@ found, and so would be kept for ever on purpose. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 5: former targets are removed and strays reported. Building follows, host first, then the controller's `take`. + +## Resolved, 2026-10-02 + +mesh-host 63: the host's record keeps a resource's former targets, removes a container or file it +wrote under a name the declaration no longer names, never what was found, and reports strays — what +runs on the machine that the mesh neither wrote nor holds. mesh-controller 201 and 202 show strays +on `node show` for an adopted and a converged machine alike; the live mesh reported four on the +control node the evening it rolled. diff --git a/04-ISSUES/098-taking-a-module-replaces-a-configuration-nobody-compared/00-report.md b/04-ISSUES/098-taking-a-module-replaces-a-configuration-nobody-compared/00-report.md index 23a597e..b58599c 100644 --- a/04-ISSUES/098-taking-a-module-replaces-a-configuration-nobody-compared/00-report.md +++ b/04-ISSUES/098-taking-a-module-replaces-a-configuration-nobody-compared/00-report.md @@ -68,3 +68,9 @@ written. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the difference is shown and a differing file refuses. Building follows, host first, then the controller's `take`. + +## Built, 2026-10-02 + +mesh-host 63 reports the difference between the kept original and the declared content; mesh-controller +201 shows it in the preview and refuses a differing file unless `--replace ` names it, or the +module declares the file partially. Stays located until a take is read on an adopted machine. diff --git a/04-ISSUES/099-a-modules-image-pin-ages-into-a-downgrade/00-report.md b/04-ISSUES/099-a-modules-image-pin-ages-into-a-downgrade/00-report.md index 25671b9..369ded4 100644 --- a/04-ISSUES/099-a-modules-image-pin-ages-into-a-downgrade/00-report.md +++ b/04-ISSUES/099-a-modules-image-pin-ages-into-a-downgrade/00-report.md @@ -65,3 +65,9 @@ expected rate. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the images are compared by age and a downgrade refuses. Building follows, host first, then the controller's `take`. + +## Built, 2026-10-02 + +mesh-host 63 reports the found image and both images' creation dates; mesh-controller 201 says +DOWNGRADE and refuses unless `--downgrade` is said. Stays located until a take is read on an adopted +machine. diff --git a/04-ISSUES/100-a-minted-secret-cannot-be-the-one-the-service-already-uses/00-report.md b/04-ISSUES/100-a-minted-secret-cannot-be-the-one-the-service-already-uses/00-report.md index fb2e94d..3178fab 100644 --- a/04-ISSUES/100-a-minted-secret-cannot-be-the-one-the-service-already-uses/00-report.md +++ b/04-ISSUES/100-a-minted-secret-cannot-be-the-one-the-service-already-uses/00-report.md @@ -70,3 +70,11 @@ the module can only be installed fresh. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 2 and 3: a minted secret for found data refuses; secret accept reaches required secrets. Building follows, host first, then the controller's `take`. + +## Built, 2026-10-02 + +`secret accept --provider ` reaches a required secret (mesh-controller 201). +The pull request after it reads every secret a module holds on a machine with its origin, and a take +of a module whose data was found refuses a minted, unaccepted one — naming the accept that carries +the existing value in, or `--mint ` to let the service take the new one. Stays located until +a take is read on an adopted machine. diff --git a/04-ISSUES/101-taking-a-service-reached-by-container-name-cuts-its-neighbours-off/00-report.md b/04-ISSUES/101-taking-a-service-reached-by-container-name-cuts-its-neighbours-off/00-report.md index fa0c521..3f7f14d 100644 --- a/04-ISSUES/101-taking-a-service-reached-by-container-name-cuts-its-neighbours-off/00-report.md +++ b/04-ISSUES/101-taking-a-service-reached-by-container-name-cuts-its-neighbours-off/00-report.md @@ -66,3 +66,10 @@ exercise. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 4: the neighbours are named; a found network may be kept by a setting. Building follows, host first, then the controller's `take`. + +## Built, 2026-10-02 + +The preview names every neighbour on a found network (mesh-controller 201). The pull request after it +adds the per-machine setting `networks` — a container id to the found networks it keeps — judged for an +adopted machine only, and mesh-host 64 has the taken container join each once it runs. Stays located +until a take is read on an adopted machine. diff --git a/04-ISSUES/126-a-volume-path-is-not-in-the-spec-comparison/00-report.md b/04-ISSUES/126-a-volume-path-is-not-in-the-spec-comparison/00-report.md index c3678c7..703c05e 100644 --- a/04-ISSUES/126-a-volume-path-is-not-in-the-spec-comparison/00-report.md +++ b/04-ISSUES/126-a-volume-path-is-not-in-the-spec-comparison/00-report.md @@ -1,7 +1,9 @@ --- -status: located +status: resolved opened: 2026-09-26 located-in: [mesh-host internal/apply] +fixed-by: mesh-host 63 (every written field compared), mesh-controller 201 (build says the policy) +amended-design: --- # 126 — a volume path is not in the spec comparison, and a roll-out raced a data move @@ -50,3 +52,9 @@ the install-page junk was discarded twice. [ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 5 and 7: every field compared; build says the policy. Building follows, host first, then the controller's `take`. + +## Resolved, 2026-10-02 + +mesh-host 63: every field the host writes is compared before a container is called current, volumes +and paths included. mesh-controller 201: `build` and the take-in say when a module's policy rolls a +result out at once; under ADR 0162 the plan says it too.