From dfac01a6dd1d9bf5537db40795846b8af01d8afc Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 27 Sep 2026 17:59:26 +0200 Subject: [PATCH] 5.2: the readiness half is in, and what a failed move actually costs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `rollout check` answers from records whether this mesh could move its bus, and names the next step for each thing missing. The move itself waits on that check having been run against a real mesh — writing the irreversible half before its question has ever been asked of something real breaks the plan's own rule about beds by another route. And the cost of being wrong is written down rather than assumed: the old broker stays for its other clients, nothing in a served request's path goes over the mesh's own bus, and what a failed move costs is the mesh's ability to change things rather than the services its modules serve. --- 03-DESIGN/01-to-be/28-building-the-bus.md | 28 +++++++++++++++++++++-- 1 file changed, 26 insertions(+), 2 deletions(-) diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index ee9b863..21877ad 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -631,8 +631,32 @@ reserves them for after the move, and a flow built ahead of its design would be - [ ] 5.1 the cutover bed: a mesh on AMQP with a predecessor stand-in on the deprecated broker moves its bus in one rollout, every node reporting on NATS afterwards, the stand-in's own client still connected throughout -- [ ] 5.2 the rollout: accounts composed, then the controller, every host and every runtime - together; every node confirmed heard before AMQP stops +- [~] 5.2 the rollout: accounts composed, then the controller, every host and every runtime + together; every node confirmed heard before AMQP stops. + + **The readiness half is in and is the half worth having.** The move takes every node at once, so + there is nothing to inspect afterwards and no half to roll back — either the mesh was ready or it + was not. `rollout check` answers that from records, with one dial: is a bus answering, does a + machine hold the seat, has it been sent the composed user list, does every machine and every + module that speaks have a credential. Each missing thing names its own next step, because "not + ready" that cannot be acted on is not an answer at the point where the next step is irreversible. + + **A machine with no credential is what must stop it.** It keeps running, cannot come back, and + afterwards there is no bus to tell it anything over. + + The move itself is deliberately not written yet, and the command says so rather than pretending: + it waits on the check having been run against a real mesh. Writing the irreversible half before + the question it depends on has ever been asked of something real is how the plan's own rule about + beds gets broken by another route. + + > **What this costs if it goes wrong, measured rather than assumed.** On the installation this is + > for, the old broker is also what a whole automation layer outside the mesh connects to — so it + > stays, as an ordinary provider of `amqp` ([ADR 0119](../../02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md)), + > and this step is not its retirement. Nothing in a served request's path goes over the mesh's own + > bus: modules serve from their own containers. What a failed move costs is the mesh's ability to + > *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That + > is worth knowing before rather than after, and it is why the operator's "as long as my services + > keep running" is a reasonable position rather than a gamble. - [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing of the mesh speaks to it, and an account nothing uses is one nobody rotates