diff --git a/03-DESIGN/01-to-be/16-module-coverage.md b/03-DESIGN/01-to-be/16-module-coverage.md index 703d60f..2db5f48 100644 --- a/03-DESIGN/01-to-be/16-module-coverage.md +++ b/03-DESIGN/01-to-be/16-module-coverage.md @@ -82,9 +82,12 @@ head. The module knows its own format because it wrote the rest of the file. ### Health checks — 7 modules `{type: port|url, expect: …}`. The mesh knows whether a container is running, which is not the -same as whether it answers — a distinction this project has paid for twice already. An `action` -with a `verify` is exactly this shape, but actions may not arrive over the link, so a module -cannot declare one. +same as whether it answers — a distinction this project has paid for twice already. + +An `action` carries a `verify` and is exactly this shape. **It is not available to a module**: the +link may not carry a command to run ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)), and a +module's resources reach a machine over the link. So a health check needs a way to say *ask this +and expect that* without saying *run this* — closer to a `listens` entry than to an action. **This is the gap most worth closing**, because *running* and *answering* being conflated is a class of fault, not an inconvenience. @@ -140,3 +143,9 @@ same module. There is one derivation here, and there should stay one. **A live listing returned credentials in plaintext.** Not a coverage question, but the reason sealing is worth its inconvenience. + +**A rule was enforced only at the far end.** A module may not declare an action, and the host +refused one correctly — but the control plane accepted it into the catalogue, resolved it and +pushed it, so the refusal arrived on a machine with nothing tying it back to the manifest. The +rule held; it was just unusable, which is the same shape as the network shape that cost five +failing tests before anyone read the host's log. It is now refused where it is written.