Renumber the records 1 to 23
The consolidation left a sparse sequence -- 1, 4, 6, 7, 9, 10, 12, 15, 16, 18, 19, 25, 34, 35, 36, 37, 40, 42, 44, 45, 48, 49, 58 -- where the gaps were only the archaeology of what used to be there. Renumbered contiguously. Renames run in ascending order, so every target number is already free and no two files ever collide. The reference rewrite is one simultaneous pass rather than a sequence of replacements. Numbers moved into slots other numbers were vacating -- the node host went 37 to 16 while the lab went 16 to 9 -- so replacing one at a time would have cascaded and silently pointed things at the wrong record. Seven plain-text references survived the merges as prose rather than links, naming records that no longer existed: the enrolment token, the link boundary, what a declaration is, reachability, the repository structure. Each mapped to the consolidated record that now holds it. Verified rather than assumed: every [ADR NNNN](path) link now has matching text and target, checked across the whole repository, and the checker passes. Frontmatter `consolidates:` lists dropped -- they named records that are gone, and each consolidated record already says in prose what it absorbed.
This commit is contained in:
@@ -31,14 +31,14 @@ exists to catch — a step that failed, reported success, and left the next step
|
||||
state that was never produced.
|
||||
|
||||
It is also a direct violation of a decision already taken and recorded:
|
||||
[ADR 0058](../../02-DECISIONS/0058-delivery.md) says a step that fails must fail the
|
||||
[ADR 0023](../../02-DECISIONS/0023-delivery.md) says a step that fails must fail the
|
||||
job. That record notes the rule is applied instance by instance and enforced by no mechanism.
|
||||
This is an instance where it was never applied.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Observed 2026-08-22 while declaring the virtualisation package required by
|
||||
[ADR 0016](../../02-DECISIONS/0016-the-lab.md).
|
||||
[ADR 0009](../../02-DECISIONS/0009-the-lab.md).
|
||||
- A fix is written and open as a pull request, unmerged since 2026-08-20.
|
||||
|
||||
## Open questions
|
||||
|
||||
@@ -21,7 +21,7 @@ recoverable by retrying — it removes the ability to issue a certificate anyone
|
||||
|
||||
The consequence lands hardest on exactly the work most likely to iterate: standing up a new
|
||||
node, changing how names resolve, or testing the lab's certificate authority split
|
||||
([ADR 0016](../../02-DECISIONS/0016-the-lab.md)).
|
||||
([ADR 0009](../../02-DECISIONS/0009-the-lab.md)).
|
||||
|
||||
## Evidence
|
||||
|
||||
|
||||
@@ -29,7 +29,7 @@ coverage was assumed, not checked.
|
||||
## Evidence
|
||||
|
||||
- The workspace was removed by pull request #240 on 2026-06-04
|
||||
([ADR 0007](../../02-DECISIONS/0007-no-npm-workspace.md)).
|
||||
([ADR 0004](../../02-DECISIONS/0004-no-npm-workspace.md)).
|
||||
- The harness has not built since that date.
|
||||
- Recorded in the knowledge base as a standing entry, not as a fixed incident.
|
||||
|
||||
|
||||
@@ -59,7 +59,7 @@ checked it — including in the same commit that wrote the rule.
|
||||
## Proposed direction — Nox is the search
|
||||
|
||||
*Added 2026-08-23.* Rather than syncing these documents into the knowledge base, **Nox
|
||||
([ADR 0019](../../02-DECISIONS/0019-how-this-repository-works.md)) works from within this
|
||||
([ADR 0011](../../02-DECISIONS/0011-how-this-repository-works.md)) works from within this
|
||||
repository and holds its knowledge directly.** Retrieval becomes an agent reading the source,
|
||||
not a copy living in a second store.
|
||||
|
||||
@@ -71,7 +71,7 @@ This is a better answer than the one the README originally promised, on three co
|
||||
was that it adds a fourth knowledge *system*. An agent with read access adds no store at all.
|
||||
- **It is always current**, including for uncommitted work in progress.
|
||||
|
||||
**But it changes the promise, and that is worth stating rather than glossing.** ADR 0019's
|
||||
**But it changes the promise, and that is worth stating rather than glossing.** ADR 0011's
|
||||
answer was that these documents would be returned *beside everything else* in a symptom search.
|
||||
An agent that must be **asked** is reachable; it is not surfacing. The two differ in exactly
|
||||
the case the operational memory is designed for: someone debugging an error who has no reason
|
||||
@@ -82,9 +82,9 @@ So the open question narrows to one thing:
|
||||
> When a symptom is searched and the answer happens to live in a design document or a decision
|
||||
> record here, does the searcher find it without already suspecting it exists?
|
||||
|
||||
If Nox is the only path, the answer is no, and the reasoning in ADR 0019 needs amending rather
|
||||
If Nox is the only path, the answer is no, and the reasoning in ADR 0011 needs amending rather
|
||||
than satisfying. If Nox also contributes what it knows to a symptom search — or the search
|
||||
consults Nox — the answer is yes and the original promise holds.
|
||||
|
||||
That is a design question for Nox, not a defect in this repository, and it should be settled
|
||||
before ADR 0019 is treated as answered.
|
||||
before ADR 0011 is treated as answered.
|
||||
|
||||
@@ -44,7 +44,7 @@ The distance between the two is the same one the delivery layer already has a na
|
||||
## Why it matters now
|
||||
|
||||
This is the first requirement of the lab
|
||||
([ADR 0016](../../02-DECISIONS/0016-the-lab.md)), which is
|
||||
([ADR 0009](../../02-DECISIONS/0009-the-lab.md)), which is
|
||||
phase 0 of the entire migration. The first capability the new work depends on is present,
|
||||
declared, and unusable — and would have stayed unusable silently.
|
||||
|
||||
|
||||
@@ -35,7 +35,7 @@ node recovers itself.
|
||||
## Scope
|
||||
|
||||
**The as-is only.** The design being built has a different answer:
|
||||
[ADR 0037](../../02-DECISIONS/0037-the-node-host.md) puts recovery
|
||||
[ADR 0016](../../02-DECISIONS/0016-the-node-host.md) puts recovery
|
||||
in a launcher that supervises the host, and that recovery is tested — 32 assertions, each
|
||||
confirmed to fail when the behaviour is removed.
|
||||
|
||||
@@ -53,7 +53,7 @@ is, which is a scheduling question rather than a technical one.
|
||||
## What it would take to be sure
|
||||
|
||||
Read back rather than assumed
|
||||
([ADR 0035](../../02-DECISIONS/0035-a-picture-is-read-from-what-runs.md)): list every unit on a
|
||||
([ADR 0014](../../02-DECISIONS/0014-a-picture-is-read-from-what-runs.md)): list every unit on a
|
||||
node and grep for `OnFailure=`; list every timer and check what each one calls. The finding above
|
||||
came from reading the repository, and confirming it against a running node is the difference
|
||||
between *no unit declares this* and *no unit in the source declares this*.
|
||||
|
||||
@@ -12,7 +12,7 @@ amended-design:
|
||||
|
||||
Two accepted decisions collide, and the collision makes one resource shape untestable.
|
||||
|
||||
- **[ADR 0048](../../02-DECISIONS/0048-the-substrate-and-the-control-plane.md)** pins images by
|
||||
- **[ADR 0021](../../02-DECISIONS/0021-the-substrate-and-the-control-plane.md)** pins images by
|
||||
digest, and the host **refuses** an image reference that is not pinned:
|
||||
|
||||
```
|
||||
@@ -66,7 +66,7 @@ for.
|
||||
## The shape of a resolution
|
||||
|
||||
**A registry inside the scenario**, on its public segment, that machines pull from. That is not a
|
||||
workaround: it is what the real mesh does — [ADR 0048](../../02-DECISIONS/0048-the-substrate-and-the-control-plane.md)
|
||||
workaround: it is what the real mesh does — [ADR 0021](../../02-DECISIONS/0021-the-substrate-and-the-control-plane.md)
|
||||
names an OCI registry as substrate, and every node after the first pulls from the mesh's own.
|
||||
Testing against a registry is testing the real path rather than a stand-in for it.
|
||||
|
||||
@@ -74,7 +74,7 @@ It also removes the lab's export-and-push mechanism rather than fixing it, which
|
||||
outcome: pushing image tarballs over the hypervisor was always a lab-only invention.
|
||||
|
||||
**Not decided here**, because it is design rather than repair: where the registry runs, whether
|
||||
it is scenery like the router ([ADR 0016](../../02-DECISIONS/0016-the-lab.md))
|
||||
it is scenery like the router ([ADR 0009](../../02-DECISIONS/0009-the-lab.md))
|
||||
or a placed artifact, and how images get into it.
|
||||
|
||||
## Incidental, and already fixed
|
||||
|
||||
Reference in New Issue
Block a user