diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index ee9b863..21877ad 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -631,8 +631,32 @@ reserves them for after the move, and a flow built ahead of its design would be - [ ] 5.1 the cutover bed: a mesh on AMQP with a predecessor stand-in on the deprecated broker moves its bus in one rollout, every node reporting on NATS afterwards, the stand-in's own client still connected throughout -- [ ] 5.2 the rollout: accounts composed, then the controller, every host and every runtime - together; every node confirmed heard before AMQP stops +- [~] 5.2 the rollout: accounts composed, then the controller, every host and every runtime + together; every node confirmed heard before AMQP stops. + + **The readiness half is in and is the half worth having.** The move takes every node at once, so + there is nothing to inspect afterwards and no half to roll back — either the mesh was ready or it + was not. `rollout check` answers that from records, with one dial: is a bus answering, does a + machine hold the seat, has it been sent the composed user list, does every machine and every + module that speaks have a credential. Each missing thing names its own next step, because "not + ready" that cannot be acted on is not an answer at the point where the next step is irreversible. + + **A machine with no credential is what must stop it.** It keeps running, cannot come back, and + afterwards there is no bus to tell it anything over. + + The move itself is deliberately not written yet, and the command says so rather than pretending: + it waits on the check having been run against a real mesh. Writing the irreversible half before + the question it depends on has ever been asked of something real is how the plan's own rule about + beds gets broken by another route. + + > **What this costs if it goes wrong, measured rather than assumed.** On the installation this is + > for, the old broker is also what a whole automation layer outside the mesh connects to — so it + > stays, as an ordinary provider of `amqp` ([ADR 0119](../../02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md)), + > and this step is not its retirement. Nothing in a served request's path goes over the mesh's own + > bus: modules serve from their own containers. What a failed move costs is the mesh's ability to + > *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That + > is worth knowing before rather than after, and it is why the operator's "as long as my services + > keep running" is a reasonable position rather than a gamble. - [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing of the mesh speaks to it, and an account nothing uses is one nobody rotates