The bootstrap starts a step earlier than recorded

Asked whether postgres has to be installed, and the answer exposed a missing
step. The store is a container, so something must run containers before anything
else happens — and a container runtime is a PACKAGE, not a container.

Step 0 is where several threads meet. It is what the host's capability detection
already reports, and the first use of that report by something other than a
person. It is adopted rather than installed when the machine already has a
runtime with configuration somebody chose. And it is a package, needing the
machine's own package manager and a network, both of which ADR 0046 permits.

So the host's bootstrap vocabulary is six shapes: package, container, file,
directory, service, action. Stage 2 built three of them.

The node host design now names which three remain and why the lab cannot yet
exercise them — a sealed scenario fetches nothing and its machines carry no
container runtime, which is lab-installation work rather than a constraint on
the design, because production machines have a network.
This commit is contained in:
2026-08-26 23:58:19 +02:00
parent 93470f6162
commit c631cbd07c
2 changed files with 32 additions and 8 deletions
+13 -5
View File
@@ -163,11 +163,19 @@ what it is. No control plane, no declarations, no network. Verifiable immediatel
the first node's path, and it is the claim the skeleton's Move 1 rests on and has never proved:
that one host can raise the substrate alone.
The first vocabulary is bounded by something the lab makes unavoidable: **a scenario is a
closed address space**, so a resource that must be fetched cannot be applied there at all. So
stage 2 begins with what needs no network — files, directories, service state — and the types
that need artifacts wait on where those come from, which is open in
[`02-scenario-declaration.md`](02-scenario-declaration.md).
Raising the substrate needs six shapes in the host's vocabulary, and stage 2 built three:
| | |
|---|---|
| `directory`, `file`, `service` | **built** |
| `package` | a container runtime must exist before a container can run |
| `container` | pulled by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)) |
| `action` | provisioning steps the bundle declares and the host verifies ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)) |
The lab cannot yet exercise the last three: a scenario is a closed address space, so nothing can
be fetched there, and its machines carry no container runtime. That is lab-installation work
([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design —
production machines have a network.
**3 — link and store.** The node connects, receives declarations, and holds what it applied.