Issues 102–106 and ADR 0105 from the core migration

Two birth-address outages and a registry that would have been the third; a
container that keeps a stale environment after its file changes; a host command
that applied a converged declaration to an adopted node; the hub and the vault
without seats. And the decision the operator made under it all: the hub adopts
the predecessor's tunnel in place, key and peers and range and port.
This commit is contained in:
2026-09-23 22:50:10 +02:00
parent ee2bdf220c
commit cb2117f1c4
8 changed files with 365 additions and 1 deletions
+18 -1
View File
@@ -7,9 +7,10 @@ code:
- mesh-controller internal/identity/authority.go
- mesh-host internal/identity/serving.go
- mesh-host internal/apply (the service that reflects a rule set)
updated: 2026-09-22
updated: 2026-09-23
decisions:
- 02-DECISIONS/0104-a-provision-may-be-answered-by-an-adapter-to-the-predecessor.md
- 02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md
- 02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md
@@ -715,3 +716,19 @@ The list is worth having in one place, because it is most of the argument:
resolvable inside the mesh, not only routable from outside it; the mechanism that writes
`<node>.internal` into containers does not yet also write the routed names, which is why an
internal issuer cannot currently validate one without a hand-placed entry.
## The hub adopts the predecessor's tunnel
*2026-09-23, [ADR 0105](../../02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md).*
On an adopted node that is the hub, the private network is not raised beside the tunnel it finds;
it **takes it over**: the found interface's private key, its port, its address and range, and every
peer it had, carried as peers not yet enrolled. The found interface is stopped, its configuration
kept on disk. A predecessor machine sees the same server key at the same endpoint and cannot tell
the tunnel changed hands; when it enrols, it keeps the address the tunnel already held for its key.
The mesh's own addresses are the adopted range's — every binding, hosts entry and endpoint the
controller composes follows it, as readers of a setting. ADR 0100's non-overlap rule applies only
where a found tunnel is left running beside the mesh's; where it is adopted there is one tunnel.
The guard admits the mesh's ports from that one interface, and the predecessor's peers arrive on
it.