ADRs 0087 and 0088; issues 031, 035 and 054 resolved; designs 05, 07 and 18 amended

A seeded file is created once (0087); the foundation filters before anything
listens (0088); a machine becomes the last thing it was told (design 05).
Each says how it is checked.
This commit is contained in:
2026-09-21 12:11:50 +02:00
parent a211aecdfa
commit ee67f69ef4
9 changed files with 166 additions and 12 deletions
+6 -1
View File
@@ -5,8 +5,9 @@ code:
- mesh-controller cmd/mesh-builder
- mesh-controller internal/builder
- mesh-catalog modules/builder
updated: 2026-09-15
updated: 2026-09-21
decisions:
- 02-DECISIONS/0087-a-seeded-file-is-created-once.md
- 02-DECISIONS/0040-what-a-module-is.md
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
- 02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md
@@ -206,6 +207,10 @@ disagrees with it.
| `service` | an **existing** unit put into a state | for software shipping its own unit |
| `action` | a command to run | ❌ **refused** — [ADR 0005](../../02-DECISIONS/0005-the-node-host.md) |
A `file` may also say `create-once`: written when absent, left alone when present, reported as
kept — a seed a program then owns ([ADR 0087](../../02-DECISIONS/0087-a-seeded-file-is-created-once.md)).
Checked by the host's apply tests and by the vault bed, which grows into one and pushes again.
**The two at the bottom are the interesting rows.** `action` is refused outright: the link may not
carry a command, so a module needing something done ships a program that reconciles — which is what
a run-once `process` is. `service` installs no unit by design, which is right for software that