Phase 1.2 done, and it is the same surprise as 1.1

A session as a licence consumer needed no change either: the two
sessions are two modules, so the existing (node, module) binding already
names them apart. 14-model-access.md's "a step toward it and not it" is
true of a worker and not of a session, and the difference is that there
is one session per node rather than many per machine.

Records what stays open: the worker half of that gap is real and
unaffected, and belongs with 0003, which is unbuilt.

Two tasks in a row that were already possible. Both were written from
the design rather than from the code — the review's own finding arriving
in the plan it produced. The remaining Phase 1 items should be checked
against the code before being started rather than after.
This commit is contained in:
2026-08-31 18:41:19 +02:00
parent fdd909ec40
commit ce486fd5d2
2 changed files with 30 additions and 4 deletions
+15 -1
View File
@@ -58,7 +58,7 @@ Found by taking real modules and asking what they would require. Each is a gap i
| # | task | done when | | # | task | done when |
|---|---|---| |---|---|---|
| ~~1.1~~ | ~~An **object-store provision**~~ — **done 2026-08-31**, and it needed no change to the mesh: see below | seven assertions against a real store | | ~~1.1~~ | ~~An **object-store provision**~~ — **done 2026-08-31**, and it needed no change to the mesh: see below | seven assertions against a real store |
| 1.2 | **A session as a consumer of a licence** | the two sessions on one machine hold different licences and each uses its own ([`14-model-access.md`](14-model-access.md), [ADR 0026](../../02-DECISIONS/0026-the-mesh-has-a-session-of-its-own.md)) | | ~~1.2~~ | ~~**A session as a consumer of a licence**~~ — **done 2026-08-31**, and it also needed no change: see below | two sessions on one machine, different licences, each its own key |
| 1.3 | A **network** shape, and ordering within a module | a module of several containers reaches itself, and one that must start after another does | | 1.3 | A **network** shape, and ordering within a module | a module of several containers reaches itself, and one that must start after another does |
| 1.4 | **Public certificate issuance** | a name reachable from outside is served with a certificate from a public authority, obtained against a **staging** endpoint unless told otherwise ([`04-ISSUES/004`](../../04-ISSUES/004-certificate-issuance-targets-production/00-report.md)) | | 1.4 | **Public certificate issuance** | a name reachable from outside is served with a certificate from a public authority, obtained against a **staging** endpoint unless told otherwise ([`04-ISSUES/004`](../../04-ISSUES/004-certificate-issuance-targets-production/00-report.md)) |
@@ -67,6 +67,20 @@ a mail system needs and nothing else so far does.
**Checkpoint:** each is demonstrated in the lab before the module needing it is attempted. **Checkpoint:** each is demonstrated in the lab before the module needing it is attempted.
### 1.2, and the same surprise twice
**A binding is per module per machine, and the two sessions are two modules** — the same mechanism
in different context roots, and a context root is what a module delivers. So `(node, module)`
already names them apart, and nothing needed adding.
[`14-model-access.md`](14-model-access.md) had called per-module-per-machine *a step toward it and
not it*, which is true of a **worker** — many run on one machine from one module — and not true of
a session, of which there is one per node and one for the mesh.
**Two tasks in a row that were already possible.** Both were written from the design rather than
from the code, which is the review's finding arriving in the plan: *a claim here is counted, not
reasoned.* The remaining Phase 1 items should be checked against the code before being started,
not after.
### 1.1, and what it turned out to be ### 1.1, and what it turned out to be
*Done 2026-08-31. Worth recording because the task was not the one written down.* *Done 2026-08-31. Worth recording because the task was not the one written down.*
+15 -3
View File
@@ -83,11 +83,23 @@ per machine, which is a step toward it and is not it.
*2026-08-31: this gap now has named consumers rather than hypothetical ones.* *2026-08-31: this gap now has named consumers rather than hypothetical ones.*
[ADR 0026](../../02-DECISIONS/0026-the-mesh-has-a-session-of-its-own.md) puts two sessions on the [ADR 0026](../../02-DECISIONS/0026-the-mesh-has-a-session-of-its-own.md) puts two sessions on the
control-plane node — the node's own and the mesh's — each bound in its own right. **A per-machine control-plane node — the node's own and the mesh's — each bound in its own right. See
binding cannot express that at all**, not merely awkwardly: the two sessions share a machine and
must be able to hold different licences. See
[`15-the-agent-session.md`](15-the-agent-session.md). [`15-the-agent-session.md`](15-the-agent-session.md).
**And for sessions the gap is already closed, which was not obvious.** A binding is per module per
machine, and this document called that *a step toward it and not it* — reasoning that a machine
cannot name an agent. It cannot; but the two sessions are **two modules**, because they are the
same mechanism started in different context roots and a context root is what a module delivers.
So `(node, module)` tells them apart, and asking for a licence per session needed no new consumer
identity. Checked rather than argued: two sessions on one machine hold different licences, each is
given its own key, and releasing one leaves the other.
**What is still open is the rest of the gap, and it is the harder half.** A *worker* is not one
per machine — many can run on one, from one module — so `(node, module)` cannot name them apart
and this reasoning does not extend to them. That belongs with
[ADR 0003](../../02-DECISIONS/0003-agents-are-persistent-employees.md), which is unbuilt, and it
is the reason this section stays open rather than being struck out.
**Switching is a reaction, not a declaration.** A licence that hits its limit and must be swapped is **Switching is a reaction, not a declaration.** A licence that hits its limit and must be swapped is
a response to something observed. Expressing it as a declaration would make the declaration mean a response to something observed. Expressing it as a declaration would make the declaration mean
*whatever is working right now*, which is not a thing anybody declared. It belongs with *whatever is working right now*, which is not a thing anybody declared. It belongs with