From e36b1a9e9caad61d77873583add362bf1f3406f7 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 21:42:11 +0200 Subject: [PATCH] Issue 213: the controller is a Go program and still runs in a container --- .../00-report.md | 50 +++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 04-ISSUES/213-the-controller-is-a-go-program-run-in-a-container/00-report.md diff --git a/04-ISSUES/213-the-controller-is-a-go-program-run-in-a-container/00-report.md b/04-ISSUES/213-the-controller-is-a-go-program-run-in-a-container/00-report.md new file mode 100644 index 0000000..b464f02 --- /dev/null +++ b/04-ISSUES/213-the-controller-is-a-go-program-run-in-a-container/00-report.md @@ -0,0 +1,50 @@ +--- +status: open +opened: 2026-10-03 +located-in: + - mesh-controller + - mesh-catalog +fixed-by: +amended-design: +--- + +# 213 — The controller is a Go program, and it still runs in a container + +## What was observed + +2026-10-03. The controller — the program that holds the `mesh-controller` seat and answers its +verbs (`status`, `nodes`, `push`, `assign` …), composes every machine's declaration and plans the +builds — runs on its machine as a container built from an image: + +``` +mesh-controller Up … (docker ps on the machine that runs it) +``` + +It is written in Go and compiles to one static binary, as the node host does. The host is delivered +as a bundle and run as a process; the node's tool runtime now is too +([ADR 0193](../../02-DECISIONS/0193-every-bundle-the-runtime-serves-is-launched-and-the-runtime-knows-no-language.md)). +The controller is the one piece of the mesh's own Go code still shipped as an image. + +## Why it matters beyond this instance + +[ADR 0188](../../02-DECISIONS/0188-a-modules-own-code-is-bundles-in-any-language-and-a-tools-bundle-speaks-mcp-to-the-runtime.md) +§1 says a module's own code is bundles, never an image, and §3 that a bundle that is a service is a +`process` the host runs. The controller breaks the rule it is the mechanism of: the registration +gate that will refuse an image of a module's own code has to exempt the controller, or refuse it. +It also costs what an image costs — a container runtime on its machine as a hard requirement, a +container network between it and the bus and store, an image rebuild for a binary change — and +every restart of it is a container recreation, which is how the controller restarts in the middle +of a plan today. + +## What a fix has to settle + +- The controller's module declares a Go bundle (`system`, `binary`) and a `process` running it + (`./`, mesh-host #81), with its credential and store connection as files and words, not + container mounts and a container network name. +- What the container gives it now that a process would not: its view of the store and the bus by + container name, its own user, any files it writes. Each named and replaced. +- The handover: the controller restarting itself as a process, on the one machine that runs it, + without a window where nothing answers the mesh's verbs. + +Located only by owner; the move is a change of the controller's module and its deployment, not of +its code.