Review: three ADRs no longer said what we had concluded
A sweep for claims overtaken by the last few days. Annotated rather than rewritten, following the pattern already in 0049 -- what changed and why is the useful part, and an accepted record should not quietly become something else. 0057's init section was wrong on all three of its claims. It said the host needs FOUR things from an init; 0061 reduced that to one. It said every machine the mesh targets already has systemd; Alpine does not, and it is the intended first node. It said there is no second init to abstract over; there is now, and the answer is still not an abstraction -- it is a four-line file per system. What survives is the part that was always right: an init is not a dependency in 0041's sense, because it is not installed, it is what the machine already is. 0048 named Docker as the container runtime. It is now docker or podman, detected rather than chosen -- because adoption keeps what a machine already has, so naming one contradicted a rule already decided. That row is the only one of the five that names two, and the record now says why. 0060 claimed the bundle is portable across operating systems. Its mechanism is; its contents are not -- package names, unit names, service names all differ, so an Arch host embeds an Arch bundle. That was my error, and it is the exact confusion behind the question that found it. The design layer had the same drift: 07 and 09 said "Docker" where they meant a container runtime, 09 said systemd restarts the host after an upgrade when the launcher does, and both install snippets assumed Arch. They now show Alpine and Arch side by side, which makes the point better than prose did -- step 1 differs per system, step 2 never does. Checked and NOT changed: 0047's "the vocabulary grows by one shape" is a claim about the rate, not the count, and is still true. 0037 lists docker among tools the host manages, which it does. 0041 says nothing about either.
This commit is contained in:
@@ -40,7 +40,7 @@ Two costs, both already accrued:
|
||||
| message bus | **LavinMQ** | In use, speaks AMQP, which is what [ADR 0001](0001-nodes-communicate-over-a-broker.md) assumes. Interchangeable with other AMQP brokers at the protocol level, which is what makes it a safe choice rather than a locked-in one. |
|
||||
| object store | **MinIO** | In use, speaks the S3 protocol, which is the closest thing to a portable object-store interface. |
|
||||
| image registry | **the OCI distribution registry** | In use, and the format is the standard rather than a vendor's. |
|
||||
| container runtime | **Docker** | In use. Podman is the plausible alternative and was not chosen for any deficiency — Docker is what the machines run today and what the current tooling assumes. |
|
||||
| container runtime | **Docker or Podman** — *detected, not chosen* | See below. The other four rows name one product; this one names two, and the difference is the point. |
|
||||
|
||||
### Outside the substrate
|
||||
|
||||
@@ -58,6 +58,15 @@ correction applies — a role is a legitimate abstraction, but the product belon
|
||||
a route is an ordinary grant. Recorded here because finding it was the point — naming the
|
||||
products is what made the unnamed role visible.
|
||||
|
||||
**The container runtime is the one row that is not a choice at all**, and it stopped being one
|
||||
after this record was written ([ADR 0060](0060-the-host-is-built-per-operating-system.md)). The
|
||||
host detects what the machine has and uses it, because adoption keeps a machine's existing
|
||||
configuration rather than replacing it — so naming a single runtime here contradicted a rule
|
||||
already decided. Both are supported, checked against a real podman: only the version probe
|
||||
differs, and one behavioural difference (podman has no daemon, so containers do not return after
|
||||
a reboot unless `podman-restart.service` is enabled) belongs in the declaration rather than the
|
||||
host.
|
||||
|
||||
**Identity is deliberately absent.** Whether an identity provider is substrate at all depends on
|
||||
whether the control plane delegates authentication, which is undecided
|
||||
([`07-the-substrate.md`](../03-DESIGN/01-to-be/07-the-substrate.md)). Naming a product before
|
||||
|
||||
@@ -63,18 +63,29 @@ That split is the tier boundary made concrete rather than an inconsistency.
|
||||
|
||||
### What it needs from an init, and why that is not a dependency
|
||||
|
||||
The host needs four things from whatever supervises it: start at boot, restart when it exits,
|
||||
give up after repeated failures, and run something else when it gives up.
|
||||
> **Overtaken by [ADR 0061](0061-the-host-asks-an-init-for-start-and-restart.md) and
|
||||
> [ADR 0060](0060-the-host-is-built-per-operating-system.md).** All three claims below were
|
||||
> true when written and are not now. Kept rather than rewritten, because what changed and why
|
||||
> is the useful part.
|
||||
|
||||
**Every machine the mesh targets already has systemd**, and the host already treats the service
|
||||
manager as a detected capability rather than an assumption. This is not a dependency in
|
||||
[ADR 0041](0041-the-host-depends-on-nothing.md)'s sense — 0041 is about what must be *installed
|
||||
before the host works*, and an init is not installed, it is what the machine already is.
|
||||
~~The host needs **four** things from whatever supervises it: start at boot, restart when it
|
||||
exits, give up after repeated failures, and run something else when it gives up.~~ **One**: run
|
||||
this at boot. The other three moved into a launcher the host ships, where they can be tested —
|
||||
a unit file's restart policy can only be read and hoped for
|
||||
([ADR 0061](0061-the-host-asks-an-init-for-start-and-restart.md)).
|
||||
|
||||
**Abstracting over init systems is not done**, because there is no second one to abstract over.
|
||||
The unit file is the only systemd-specific artefact, it belongs to the package rather than the
|
||||
binary, and a machine with a different supervisor would ship a different package — which is
|
||||
where that difference belongs.
|
||||
~~**Every machine the mesh targets already has systemd.**~~ **Alpine does not**, and it is the
|
||||
intended first node. It runs OpenRC.
|
||||
|
||||
~~**Abstracting over init systems is not done, because there is no second one to abstract
|
||||
over.**~~ There is now, and the answer is still not an abstraction: the host is built per
|
||||
operating system ([ADR 0060](0060-the-host-is-built-per-operating-system.md)), so each ships its
|
||||
own four-line init file. That the file is the *only* system-specific artefact is what survives,
|
||||
and it is what makes a second one transcription rather than a port.
|
||||
|
||||
The part that stands unchanged: **an init is not a dependency in
|
||||
[ADR 0041](0041-the-host-depends-on-nothing.md)'s sense.** 0041 is about what must be *installed
|
||||
before the host works*, and an init is not installed — it is what the machine already is.
|
||||
|
||||
### It never manages its own unit
|
||||
|
||||
|
||||
@@ -54,8 +54,15 @@ arrive together, as one decision somebody made when they installed the operating
|
||||
### Almost all of it is shared
|
||||
|
||||
Not a rewrite per operating system. The declaration vocabulary, the store, the apply loop, the
|
||||
read-back discipline, the refusal model, the bundle and the link are all portable. **What differs
|
||||
is two appliers**, and the rest is compiled around them.
|
||||
read-back discipline, the refusal model and the link are all portable. **What differs is two
|
||||
appliers**, and the rest is compiled around them.
|
||||
|
||||
**The bundle is the exception, and an earlier version of this record wrongly listed it as
|
||||
portable.** Its *mechanism* is — one embedded declaration, applied with no mesh present. Its
|
||||
*contents* are not: package names, unit names and service names all differ, so an Arch host
|
||||
embeds an Arch bundle and an Alpine host an Alpine one. That is the same thing this record says
|
||||
about package names one section down, and missing it here is what made the distinction hard to
|
||||
see.
|
||||
|
||||
### The control plane names the package, because the host does not decide
|
||||
|
||||
|
||||
Reference in New Issue
Block a user