From e4a5d9b1d0a606b5cddeef6076969e19585f4084 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 11 Sep 2026 00:11:39 +0200 Subject: [PATCH] Lab installation: the reachability check joins the assertions it belongs with MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The doc's own rule is that the lab verifies capability by outcome, never by reading a setting. A path out is exactly that kind of claim — a route and a policy can both read correctly while nothing gets through — so it is asserted by fetching something, in the table with the rest. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- 03-DESIGN/01-to-be/04-lab-installation.md | 1 + 1 file changed, 1 insertion(+) diff --git a/03-DESIGN/01-to-be/04-lab-installation.md b/03-DESIGN/01-to-be/04-lab-installation.md index 5c4944e..2d00788 100644 --- a/03-DESIGN/01-to-be/04-lab-installation.md +++ b/03-DESIGN/01-to-be/04-lab-installation.md @@ -48,6 +48,7 @@ present, but that the machine can actually do the work: | **the pool the lab will use is on that driver** | a pool exists, and is the slow kind — the failure that has no symptom | | hardware virtualisation is present | machines will be emulated and unusably slow | | an image can be fetched or is cached | the first raise will fail late instead of early | +| **a machine on an uplink reaches something real**, by fetching it — not by reading a route or a policy | forwarding is being dropped by something else on the workstation; names still resolve, and every pull hangs | Each check states **why it matters**, in the terms of what it costs. *"The pool uses the `dir` driver"* means nothing to someone who does not already know it means seventy-six times slower