1.7 is done; 4.1 waits on nothing but the bed
Minting on both halves, the file delivered per push, and the bus's objects asserted on every start — verified against a real server that asserting twice changes nothing, that a machine joining an already-raised bus is accepted, that each node's consumer is bound to its own declaration subject, and that CONTROL does not dead-letter before the controller gives up. Which bus the mesh is on is one fact, and being told about both is refused at start rather than warned about: a mesh half on each is one where a declaration goes out on one bus and the report comes back on the other while every component logs success — ADR 0074's failure arriving through configuration rather than code. So 4.1 no longer waits on code. Both links speak NATS, the composition happens, and every claim behind them has a unit test or a check against a running server. What none of those can stand in for is a mesh raising itself, which is what the bed is — this is where the code stops and the lab starts.
This commit is contained in:
@@ -150,7 +150,7 @@ paper is wrong until there is a second mesh to find out.
|
|||||||
and names no broker module anywhere in its source. What remains is naming `nats` instead of
|
and names no broker module anywhere in its source. What remains is naming `nats` instead of
|
||||||
the deprecated broker where a genesis module set is declared, which is scenario and installer
|
the deprecated broker where a genesis module set is declared, which is scenario and installer
|
||||||
configuration — carried with 1.6 rather than before it.
|
configuration — carried with 1.6 rather than before it.
|
||||||
- [~] 1.7 **the composition, delivered** — the controller gathering its principals, composing the
|
- [x] 1.7 **the composition, delivered** — the controller gathering its principals, composing the
|
||||||
file, and asserting the streams and consumers on start.
|
file, and asserting the streams and consumers on start.
|
||||||
|
|
||||||
**In**: the user list is derived from the mesh's records and the credentials are kept.
|
**In**: the user list is derived from the mesh's records and the credentials are kept.
|
||||||
@@ -202,14 +202,32 @@ paper is wrong until there is a second mesh to find out.
|
|||||||
list rewritten, the module noticing and reloading the server itself with no signal from
|
list rewritten, the module noticing and reloading the server itself with no signal from
|
||||||
outside, and the connection the mesh already had still working afterwards.
|
outside, and the connection the mesh already had still working afterwards.
|
||||||
|
|
||||||
*Still out — minting, and it is transport-coupled.* A password is minted at enrolment and at assignment,
|
**Minting is in, on both halves.** A node at enrolment, a module when its credential is
|
||||||
and an enrolment reply carries exactly one. **A node on the old bus must not be handed a
|
issued. Three things differ from a management call and each is the point of the move: the
|
||||||
credential for the new one**, so which bus a node is joining has to be a fact the controller
|
credential is minted into the mesh's records and becomes usable at the next composition, so no
|
||||||
holds before it can mint for both — the same switch the host's `Transport` is, from the other
|
server need be reachable for it; the password travels beside the address rather than inside it,
|
||||||
end.
|
because a credential embedded in a URL leaks into every log line that prints a connection; and
|
||||||
|
a module's durable consumer is derived from what it declared rather than named, so it cannot ask
|
||||||
|
for delivery of something it did not say it consumes. A node reconnecting may be refused until
|
||||||
|
the composition reaches the machine running the bus — which is what the host's reconnect backoff
|
||||||
|
is for, where waiting for the push would hold an enrolment open for as long as a declaration
|
||||||
|
takes to apply.
|
||||||
|
|
||||||
*Still out — asserting on start.* The streams, the controller's consumers and every node's
|
**Which bus is one fact, and being told about both is refused at start.** Not warned about: a
|
||||||
are defined and idempotent; nothing calls them from a start path yet.
|
mesh half on each is one where a declaration goes out on one bus and the report comes back on
|
||||||
|
the other, and every component logs success while it happens — ADR 0074's failure arriving
|
||||||
|
through configuration instead of through code. A node that came away holding a credential for
|
||||||
|
each could be half-moved, and nothing would say which half.
|
||||||
|
|
||||||
|
**The objects are asserted on every start**, not created once at genesis: a stream somebody
|
||||||
|
deleted, a mesh raised from a restored backup, or a bus whose data directory was replaced all
|
||||||
|
have records and no objects, and a node whose consumer is missing hears nothing while everything
|
||||||
|
else about it looks correct. Against a real server: every object accepted, asserting twice
|
||||||
|
changes nothing (a start that failed the second time is a controller that cannot restart), a
|
||||||
|
machine joining an already-raised bus accepted, each node's consumer bound to its own
|
||||||
|
declaration subject and no other's, and CONTROL not dead-lettering — because the store window's
|
||||||
|
bound is the controller's, and a server that gave up first would discard the push the stream
|
||||||
|
exists to protect.
|
||||||
|
|
||||||
**People are not in the list**, deliberately: the account model is built and `operator issue`
|
**People are not in the list**, deliberately: the account model is built and `operator issue`
|
||||||
is not (4.4), so there is nobody to derive. Left empty rather than guessed at.
|
is not (4.4), so there is nobody to derive. Left empty rather than guessed at.
|
||||||
@@ -495,9 +513,10 @@ it, and the beds that need a mesh living on NATS can finally run.
|
|||||||
held by a `nak`-with-delay cycle still reaches the enrolling node, proving the reply travels
|
held by a `nak`-with-delay cycle still reaches the enrolling node, proving the reply travels
|
||||||
in the payload and not the transport field the consumer's ack has claimed. The server-enforced
|
in the payload and not the transport field the consumer's ack has claimed. The server-enforced
|
||||||
permissions were proved at step 1 and are not re-proved here
|
permissions were proved at step 1 and are not re-proved here
|
||||||
— **waiting on 1.7, the composition.** Both links speak NATS and every claim above has a unit
|
— **nothing is outstanding but the bed itself.** Both links speak NATS, the composition
|
||||||
test or a check against a running server behind it; what none of them needs is a bus that
|
happens, and every claim above has a unit test or a check against a running server behind it.
|
||||||
composed its own accounts, because each supplies its own. A mesh raising itself does need one
|
What none of them can stand in for is a mesh raising itself, which is what this bed is — so this
|
||||||
|
is where the code stops and the lab starts
|
||||||
- [ ] 4.2 a build source's change reaches the builder over the bus, and the build that follows is
|
- [ ] 4.2 a build source's change reaches the builder over the bus, and the build that follows is
|
||||||
the one the change asked for — **blocked by
|
the one the change asked for — **blocked by
|
||||||
[issue 127](../../04-ISSUES/127-a-module-event-derives-a-subject-nothing-publishes/00-report.md)**
|
[issue 127](../../04-ISSUES/127-a-module-event-derives-a-subject-nothing-publishes/00-report.md)**
|
||||||
|
|||||||
Reference in New Issue
Block a user