diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index b564f8d..e511b0e 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -379,11 +379,20 @@ reserves them for after the move, and a flow built ahead of its design would be client still connected throughout - [ ] 5.2 the rollout: accounts composed, then the controller, every host and every runtime together; every node confirmed heard before AMQP stops -- [ ] 5.3 the mesh's accounts removed from the deprecated broker, leaving the predecessor's users -- [ ] 5.4 the deprecated broker retires when its condition holds — no client connected for the - period the operator sets +- [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing + of the mesh speaks to it, and an account nothing uses is one nobody rotates -**Done when.** Every node reports on NATS and the predecessor's clients never noticed. +> **5.4 is gone, and was wrong from ADR 0119 onward.** It read "the deprecated broker retires +> when its condition holds — no client connected for the period the operator sets", which is +> ADR 0106's framing of it as a compatibility module with an end date. +> [ADR 0119](../../02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md) settled that it is an +> **ordinary provider** of the `amqp` provision, like any module answering a backing service: +> no seat, not foundation, and **no retirement condition**, because the day its last client +> disappears is not a day anything is waiting for. Removed rather than reworded — a step that +> waits for a condition nobody set would sit open forever. + +**Done when.** Every node reports on NATS, and nothing of the mesh's own is left connected to the +deprecated broker. ## The through-line