One agent directory per machine is shared by every session; a worker's own licence lives in a home of its own (operator's correction)

This commit is contained in:
jochen
2026-10-02 17:12:06 +02:00
parent 479b8fe72d
commit e710abd9b8
3 changed files with 16 additions and 4 deletions
@@ -132,8 +132,13 @@ the node is bound to, and refuses with a notification otherwise.
- **What got harder:** a manager that is down leaves every node on its last token until it expires;
the agent module keeps the last token and says so. And a node whose agent module has not registered
its key cannot be handed a token, which the manager reports by name.
- **Not decided here:** an automated switch on exhaustion; a second concurrent session under another
licence on one machine; whether a refresh token is single-use, to be measured in the lab.
- Every interactive session on a machine shares the node's one agent directory, and so its licence;
twenty sessions share it as one does. A consumer with a licence of its own on the same machine is a
worker running from a home of its own with its own agent directory — the worker touchpoint above, for
when workers exist ([ADR 0003](0003-agents-are-persistent-employees.md)); the predecessor ran its
agents that way.
- **Not decided here:** an automated switch on exhaustion; whether a refresh token is single-use, to be
measured in the lab.
## How it is checked
@@ -188,8 +188,10 @@ installer is rejected: it puts a self-updating binary under the person's home, i
## What this does not settle
- **Several operator accounts on one node** (ADR 0176 decides one).
- **A parallel session under another licence on one machine.** The retired shell helper allowed it by
keeping tokens readable; not provided.
- **A worker's own licence on a machine.** Every interactive session shares the node's one agent
directory and its licence, however many run. A worker runs from a home of its own with an agent
directory in it, bound to its own licence through the manager (to-be 37 §5); that is for when workers
exist, and nothing here changes for it.
- **The package repository seat** (§7).
- **How the module's code is run** — a supervised process per module ([ADR 0150](../../02-DECISIONS/0150-a-modules-own-code-runs-as-supervised-processes-under-one-account.md))
today, one executor per node when research 018 graduates. Nothing here depends on which.
@@ -101,6 +101,11 @@ Three consumer kinds, the predecessor's touchpoints with their fallbacks:
| **the mesh's session on a node** | the node, for that session | the node's agent licence | refused |
| **a worker** | the worker | the node's session licence, then the node's | refused: a worker never borrows a person's account |
**One agent directory per machine, shared by every interactive session**, so a node's binding is the
licence of all its sessions at once. A worker is a consumer of its own because it runs from a home of its
own, with its own agent directory and credentials file, which the agent module on that node writes for
it as it writes the operator's — the predecessor ran its agents exactly so.
**Binding is a person's act through the seat's verbs**, listed by the console: `bind`, `switch`,
`release`. **Exhaustion is observed, not acted on**: usage is read every few minutes, a crossing of a
declared threshold in the five-hour window is notified once per crossing, and moving a consumer is the