ADR 0100 after re-review: the bus and registry stay reachable for enrolment; the mesh guards the store in a table that only refuses; a machine in use defined; the flip refuses while a found container is held; held containers and returning to adopted spelled out

This commit is contained in:
2026-09-22 16:32:37 +02:00
parent 02c40bcab4
commit f3152d827f
7 changed files with 112 additions and 74 deletions
@@ -116,12 +116,15 @@ intention, and each thing the mesh would otherwise take must say what it does in
recorded, until the operator **takes** the module on that node — the cutover, done when the
module's data has moved. Assigning prepares; taking migrates. Without the distinction the rule
never fires: the host only ever sees what assigned modules declare.
- **The firewall found on the machine stays in force.** The mesh does not load its own table on an
adopted node. What it needs open it declares as openings the host converges *through the found
firewall*, on the incoming and the forwarded path, marked as the mesh's and re-checked on every
reconcile so a reload or reboot does not lose them. An accept in a table of its own would not
help: the found firewall's drop would still be final. And the mesh protects its own ports itself,
on the forwarded path, since the found firewall may not.
- **The firewall found on the machine stays in force.** The mesh loads no table on an adopted node
that drops by default or accepts. What it needs open it declares as openings the host converges
*through the found firewall*, on the incoming and the forwarded path, marked as the mesh's and
re-checked on every reconcile so a reload or reboot does not lose them. An accept in a table of
its own would not help: the found firewall's drop would still be final. What a table of its own
*can* do is refuse, and a refusal is final too — so the mesh guards the store and the broker's
management port from outside the private network in a table that only refuses, which the found
firewall may not do and cannot undo. The bus, the registry and the hub's port stay open to
anywhere: a node enrols before it has a private-network address.
- **The foundation's ports are the node's to give** — set at genesis, checked free, and kept as
that node's settings, read everywhere they are used, so adopting the foundation as modules does
not move them back.