diff --git a/00-META/how-we-build.md b/00-META/how-we-build.md index 696a941..55d9611 100644 --- a/00-META/how-we-build.md +++ b/00-META/how-we-build.md @@ -39,7 +39,7 @@ incident behind it is not written down, and the fix is to write it down, not to | **Never write to a production database directly** | No insert, update, delete or schema statement executed against production by hand. Schema changes go through numbered migrations; data changes go through application code or the module's own capabilities. Raw statements skip every side effect the proper path has — events, audit, cache invalidation, fan-out. | | **Every schema change is a migration** | Numbered, in the module's own language, compiled with it. Both a baseline for a fresh installation *and* an incremental migration for installations that already exist. If code references a column, the migration creating it must exist. [ADR 0006](../02-DECISIONS/0006-schema-changes-are-numbered-migrations.md) | | **Never bypass the pipeline** | No manual database edit, no manual restart as a workaround. Fix the cause and deploy. A workaround that works is a workaround that is never removed, and the next person cannot tell the node from its declaration. | -| **Never create a symlink** | A hand-made link caused production data loss through container volume resolution, and the judgement needed to make a safe exception is exactly the judgement unavailable at the moment it matters. Today the installer owns and reconciles the links the mesh still uses [ADR 0011](../02-DECISIONS/0011-the-installer-owns-linking.md); the intent is that the mesh creates none at all [ADR 0018](../02-DECISIONS/0018-the-mesh-creates-no-symlinks.md). Neither reading permits you to make one. | +| **Never create a symlink** | A hand-made link caused production data loss through container volume resolution, and the judgement needed to make a safe exception is exactly the judgement unavailable at the moment it matters. **The mesh creates none at all** ([ADR 0018](../02-DECISIONS/0018-the-mesh-creates-no-symlinks.md), which supersedes [ADR 0011](../02-DECISIONS/0011-the-installer-owns-linking.md)). The links the installer still reconciles are a migration, not a permission. | | **Never push directly to the main branch** | Branch, push, review, merge. Every merge is a human checkpoint, without exception — **including in this repository**. A documentation repository is not a lower tier of care; a decision record lands the same way a service does. | | **One change per pull request, and never merge your own** | Unrelated improvements bundled together cannot be reviewed or reverted separately. Self-merging removes the checkpoint that is the entire point. | | **Never open a pull request unprompted** | A permissions list saying it is allowed is not a request. | @@ -154,8 +154,6 @@ effect. Absence reads as success unless something looked. ### A test defends a decision -*Proposed — [ADR 0034](../02-DECISIONS/0034-a-test-defends-a-decision.md), pending review.* - The rule above applies to prose. It applies to **decisions** too: a decision record states something that must be true, and a test asserts it. A decision with no test is one that will quietly stop being true, and nobody will learn that from a document. diff --git a/02-DECISIONS/0011-the-installer-owns-linking.md b/02-DECISIONS/0011-the-installer-owns-linking.md index 1fbad3d..9c1dfbc 100644 --- a/02-DECISIONS/0011-the-installer-owns-linking.md +++ b/02-DECISIONS/0011-the-installer-owns-linking.md @@ -1,5 +1,6 @@ --- -status: accepted +status: superseded +superseded-by: 02-DECISIONS/0018-the-mesh-creates-no-symlinks.md date: 2026-07-10 deciders: jochen reconstructed: true diff --git a/02-DECISIONS/0018-the-mesh-creates-no-symlinks.md b/02-DECISIONS/0018-the-mesh-creates-no-symlinks.md index efa9a43..762c1f9 100644 --- a/02-DECISIONS/0018-the-mesh-creates-no-symlinks.md +++ b/02-DECISIONS/0018-the-mesh-creates-no-symlinks.md @@ -1,5 +1,5 @@ --- -status: proposed +status: accepted date: 2026-08-23 deciders: jochen reconstructed: false @@ -50,7 +50,7 @@ State is derived onto nodes; it does not reach back. ## Decision -*Proposed — the position is settled; the migration is not designed. See "Open" below.* +*Accepted 2026-08-25. The position is settled; the migration is not designed. See "Open" below.* **The mesh creates no symlinks.** A file a node needs is placed on that node as a real file, derived from the mesh and reconciled by the installer like every other managed file diff --git a/02-DECISIONS/0034-a-test-defends-a-decision.md b/02-DECISIONS/0034-a-test-defends-a-decision.md index 93ef48f..492b7a0 100644 --- a/02-DECISIONS/0034-a-test-defends-a-decision.md +++ b/02-DECISIONS/0034-a-test-defends-a-decision.md @@ -1,5 +1,5 @@ --- -status: proposed +status: accepted date: 2026-08-24 deciders: jochen reconstructed: false