Phase 1.3 done: ordering was already there, the network was not
Ordering needed no change for the third time running — resources apply in the order declared and nothing sorts them — and is now asserted, because sorting them for any sensible reason would have passed every other test. Separates ordering from readiness, which the task had run together: a container started is not a container ready. Nothing waits, and what needs something usable retries. That is deliberate and more robust than start ordering, since a dependency can restart long after apply. The network was the first thing in Phase 1 that genuinely needed building, and the first that needed a decision: 0029 records why a shape rather than an action, and the vocabulary is nine.
This commit is contained in:
@@ -59,7 +59,7 @@ Found by taking real modules and asking what they would require. Each is a gap i
|
||||
|---|---|---|
|
||||
| ~~1.1~~ | ~~An **object-store provision**~~ — **done 2026-08-31**, and it needed no change to the mesh: see below | seven assertions against a real store |
|
||||
| ~~1.2~~ | ~~**A session as a consumer of a licence**~~ — **done 2026-08-31**, and it also needed no change: see below | two sessions on one machine, different licences, each its own key |
|
||||
| 1.3 | A **network** shape, and ordering within a module | a module of several containers reaches itself, and one that must start after another does |
|
||||
| ~~1.3~~ | ~~A **network** shape, and ordering within a module~~ — **done 2026-08-31** | the shape is created and removed; ordering was already there, and is now asserted |
|
||||
| 1.4 | **Public certificate issuance** | a name reachable from outside is served with a certificate from a public authority, obtained against a **staging** endpoint unless told otherwise ([`04-ISSUES/004`](../../04-ISSUES/004-certificate-issuance-targets-production/00-report.md)) |
|
||||
|
||||
**1.3 and 1.4 block later ones** and are listed now so they are not met as surprises. 1.3 is what
|
||||
@@ -76,7 +76,21 @@ already names them apart, and nothing needed adding.
|
||||
not it*, which is true of a **worker** — many run on one machine from one module — and not true of
|
||||
a session, of which there is one per node and one for the mesh.
|
||||
|
||||
**Two tasks in a row that were already possible.** Both were written from the design rather than
|
||||
### 1.3, and the first one that needed building
|
||||
|
||||
**Ordering was already there** — the apply loop sorts nothing, so a module says *this before that*
|
||||
by writing it first. Untested until now, and the kind of property a later change breaks silently.
|
||||
Worth separating from readiness: a container started is not a container ready, and nothing waits.
|
||||
What needs something *usable* retries, which is what both provisioners do and is the better answer
|
||||
anyway, because a dependency can restart long after everything was applied.
|
||||
|
||||
**The network was a real gap, and the first thing in Phase 1 that needed a decision.** Adding a
|
||||
shape widens what a compromised control plane can express, so
|
||||
[ADR 0029](../../02-DECISIONS/0029-a-network-is-a-shape-because-an-action-cannot-be-undone.md)
|
||||
records why this one is worth it: an `action` could create a network and **nothing could ever
|
||||
remove it**, because an action leaves no footprint the host can undo. The vocabulary is nine.
|
||||
|
||||
**Three tasks in a row that were already possible.** Both were written from the design rather than
|
||||
from the code, which is the review's finding arriving in the plan: *a claim here is counted, not
|
||||
reasoned.* The remaining Phase 1 items should be checked against the code before being started,
|
||||
not after.
|
||||
|
||||
@@ -332,13 +332,15 @@ reported to be distinguishable from one that reported an empty list.*
|
||||
*Written 2026-08-30. Every addition widens what a compromised control plane can express, so the
|
||||
count is asserted by a test and a change to it is a decision rather than a convenience.*
|
||||
|
||||
Six shapes raised the substrate. Two more exist because most of what a person installs is not a
|
||||
Four shapes raise the substrate. Five more exist because most of what a person installs is not a
|
||||
service:
|
||||
|
||||
| | why |
|
||||
|---|---|
|
||||
| **file**, **directory** | the substrate needs neither, and almost everything else does |
|
||||
| **user** | a shell, a terminal, a chat client, a desktop are a package plus configuration **in somebody's home**. A mesh with no user owns `/etc` and nothing anybody looks at |
|
||||
| **archive** | a theme is hundreds of files. Inlining them makes every declaration enormous and rewrites all of them when one changes |
|
||||
| **network** | a module of several containers has to let them reach each other by name, and doing it with an action would create something nothing could ever remove ([ADR 0029](../../02-DECISIONS/0029-a-network-is-a-shape-because-an-action-cannot-be-undone.md)) |
|
||||
|
||||
And `file` gained two fields: `bytes`, because a wallpaper is not a string, and `owner`, because a
|
||||
file in a home belongs to somebody.
|
||||
|
||||
@@ -194,7 +194,7 @@ So the bootstrap uses four shapes: **package**, **container**, **service** and *
|
||||
*counted from `substrate-first-node.lock`, which is the only bundle there is*. It had said six,
|
||||
adding `file` and `directory`, which this bootstrap never asks for.
|
||||
|
||||
All four are built, as are the host's other four
|
||||
All four are built, as are the host's other five
|
||||
([`05-the-node-host.md`](05-the-node-host.md) stage 2), so nothing in this bootstrap is blocked
|
||||
on the host any longer — which is the claim that mattered, and it was true either way.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user