Commit Graph
100 Commits
Author SHA1 Message Date
jschoubben 111456abb5 ADR 0100 accepted; the node host, connectivity, the node lifecycle and raising a mesh amended for a node adopted before it is converged 2026-09-22 16:20:27 +02:00
jschoubben 5fc3cbde4c Research 012: migrating a node that is in use, measured on the control-node; ADR 0100 proposed — a node in use is adopted before it is converged 2026-09-22 16:16:28 +02:00
jschoubben 21baf397a8 Merge pull request 'Issue 083 resolved: nothing the control queue carries is lost while the store restarts' (#73) from multiple-fixes into main 2026-09-22 14:43:00 +02:00
jschoubben 4de74880cb Issue 083: the proof, the replay caveat, and what is not closed, as three reviews found them 2026-09-22 14:39:29 +02:00
jschoubben 266ee34b5c Issue 083: the diagnosis describes held messages, the enrolment's order, and what is not closed 2026-09-22 14:24:31 +02:00
jschoubben 2d45aa5f42 Issue 083 resolved: nothing the control queue carries is lost while the store restarts; an enrolment claims its token and spends it last 2026-09-22 14:11:44 +02:00
jschoubben 4e74cf29e4 Merge pull request 'Issues 081 and 082 resolved; 083 opened' (#72) from multiple-fixes into main 2026-09-22 13:53:16 +02:00
jschoubben 0d40918e92 Issue 081: proven by the two-node bed, and what it found about baserow's data directory 2026-09-22 13:53:00 +02:00
jschoubben f6ded3102d Issue 083 opened (other control messages lost while the store restarts); 082's diagnosis carries its review 2026-09-22 13:34:05 +02:00
jschoubben 9a75f2b6a9 Issue 082: a report that arrives while the store restarts was lost; 081's diagnosis corrected on review 2026-09-22 13:25:33 +02:00
jschoubben 5d1a0372cb Issue 081 resolved: neither cache consumer can keep its keys under its login, so neither takes the shared cache 2026-09-22 12:27:12 +02:00
jschoubben f1e3925009 Merge pull request 'Issues 079 and 080, found by running the large mesh bed; 074's addendum' (#71) from multiple-fixes into main 2026-09-22 02:19:17 +02:00
jschoubben 35e44c3e5e Issue 081 opened (a cache consumer does not use its login); 079 and 080 diagnoses carry the review's consequences 2026-09-22 02:04:29 +02:00
jschoubben f760bf632c Issue 080: a cache grant let the consumer flush the server; 079: the names follow the resolver's rule for the private network 2026-09-22 01:39:29 +02:00
jschoubben e31e077fc8 Issue 079: the suffix is handed down, not written twice 2026-09-22 01:27:53 +02:00
jschoubben 17cc36069f Issue 079: every machine named twice over, found by the large mesh bed; what running that bed cost, on 074 2026-09-22 01:13:29 +02:00
jschoubben 446553dd1f Merge pull request 'ADR 0099; issues 077, 078 and 074 resolved; designs 08 and 20 amended' (#70) from multiple-fixes into main 2026-09-21 23:58:50 +02:00
jschoubben 3ea5e47c21 Review: 077 says what closed it and what did not; 078 names module issue; 074's retired fixture; ADR 0099's scope 2026-09-21 23:58:15 +02:00
jschoubben ead8913a74 Issue 078: module issue's orphan account, refused before it is made 2026-09-21 23:46:51 +02:00
jschoubben faa7196ad6 Issue 074: opened date restored 2026-09-21 23:44:22 +02:00
jschoubben 8d159cee84 Issue 074 resolved: the declared list is empty of WEARING; what the last three cost 2026-09-21 23:43:31 +02:00
jschoubben 0e0f0298c6 ADR 0099: a step that runs once names what it reads; issues 077 and 078 resolved; designs 08 and 20 amended 2026-09-21 23:33:47 +02:00
jschoubben c2a81cbb20 Merge pull request 'ADR 0098; issue 076 opened and resolved; ADR 0097's base refusal live; ADR 0096 proven against the public hub; 074 down to one bed' (#69) from multiple-fixes into main 2026-09-21 22:58:26 +02:00
jschoubben 6bc9df4b49 Review corrections: 076 and ADR 0098 say what the authority could and could not do; issues 077 (a fetched fact is fetched once) and 078 (secret accept takes any name) opened 2026-09-21 22:55:11 +02:00
jschoubben 6d3cb60949 Issue 076: the route-forwarding bed proves ADR 0098; what the run taught about the overlay 2026-09-21 22:44:24 +02:00
jschoubben 75af72ca27 ADR 0096: the copy is proven against the public hub by the genesis bed 2026-09-21 22:32:03 +02:00
jschoubben 252c6042e8 ADR 0098: a fact a provider makes at first start is fetched from it; issue 076 resolved; design 08 amended; 074 down to one bed 2026-09-21 22:27:32 +02:00
jschoubben bc373797c7 Issue 076 opened: a served fact made at first start cannot be served; ADR 0097's refusal of an undeclared base is live 2026-09-21 22:16:15 +02:00
jschoubben 559683318b Merge pull request 'Multiple fixes: issues 064, 066 and 020 resolved; 074 narrowed to two beds' (#68) from multiple-fixes into main 2026-09-21 22:13:20 +02:00
jschoubben ac11bea77f Issue 020 resolved: the symptom was the bed's, proven against Pebble and step-ca alike 2026-09-21 22:12:51 +02:00
jschoubben c1a10dc3f8 Issue 066 resolved: a file and its reader are guarded by a gate, proven by the coupled-pair spike; design 20 says so 2026-09-21 22:04:14 +02:00
jschoubben e993233004 Issue 074: six of the ten beds retired rather than converted 2026-09-21 21:53:11 +02:00
jschoubben 2d77911511 Issue 064 resolved: the package half placed by the genesis run, the image half by ADR 0097 2026-09-21 21:52:32 +02:00
jschoubben f11824d299 Merge pull request 'Multiple fixes: ADRs 0094–0097; issues 069, 049, 046 resolved; 064's image half decided' (#67) from multiple-fixes into main 2026-09-21 21:05:13 +02:00
jschoubben 43ca9ce0ae ADR 0097: an undeclared base is said, not yet refused 2026-09-21 20:48:19 +02:00
jschoubben 71072e240d ADR 0097: a vendor image is a declared build input; issue 064's image half decided; design 18 amended 2026-09-21 20:45:36 +02:00
jschoubben 8d981e21b1 ADR 0096: an upstream image is copied between registries; issue 046 resolved; design 18 amended 2026-09-21 20:43:07 +02:00
jschoubben 39a01b7f7e ADR 0095: the control plane is the way to ask a module; issue 049 resolved; design 19 amended 2026-09-21 20:38:23 +02:00
jschoubben acc9824949 ADR 0094: a module may hold several secrets from one provider; issue 069 resolved; design 24 amended 2026-09-21 20:29:29 +02:00
jschoubben a259d1292f Merge pull request 'ADR 0093: a fixture that runs a module's runtime carries its name; 074 diagnosed; 075 resolved' (#66) from feat/mesh-tests-and-runtimes into main 2026-09-21 19:36:44 +02:00
jschoubben 76cd91413e ADR 0093: a fixture that runs a module's runtime carries its name; 074 diagnosed, two beds converted; 075 resolved 2026-09-21 19:30:35 +02:00
jschoubben 6427afe6ae Merge pull request 'Issues 072 and 073 name their merges, the branches being gone' (#65) from chore/merges-named into main 2026-09-21 19:25:06 +02:00
jschoubben d92068be7b Issues 072 and 073 name their merges, the branches being gone 2026-09-21 19:24:28 +02:00
jschoubben 6a35e5a58c Merge pull request 'Multiple fixes: status vocabulary aligned, 065/026/070/007 resolved, 066/069/049/046 located, 064 diagnosed' (#64) from feat/multiple-fixes into main 2026-09-21 19:23:34 +02:00
jschoubben bf4d99843f Merge pull request 'Issue 072 diagnosed: genesis registers the manifest its build produced; design 17 says so' (#63) from feat/one-controller-manifest into main 2026-09-21 19:23:31 +02:00
jschoubben 702289ad7d Merge pull request 'ADR 0089: a bed reads the catalogue it proves; issue 073 diagnosed; issues 074 and 075 opened' (#62) from feat/beds-read-the-catalogue into main 2026-09-21 19:23:16 +02:00
jschoubben 6ee95a3f31 ADR 0090: a failure is the same by resource id, not by the host's words 2026-09-21 19:23:04 +02:00
jschoubben 159a583cf0 Issue 069: the count is the catalogue's, not the report's 2026-09-21 17:51:40 +02:00
jschoubben 62ff9a5bd3 Issues 046, 049 and 069 located, each with the decision its fix needs named 2026-09-21 17:50:42 +02:00
jschoubben 16442ecd23 ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended 2026-09-21 17:50:41 +02:00
jschoubben ffb7fa52ec Issues 007 resolved, 066 located, 064 diagnosed 2026-09-21 17:48:38 +02:00
jschoubben fcf34727fe ADR 0090: a failure that repeats is said to be stuck; issue 065 resolved
The controller kept one report per machine, replaced, so a resource nothing can
ever apply looked like a failure that had just happened, every few minutes, for
ever. It now counts identical reports and status says stuck after three.
2026-09-21 17:43:02 +02:00
jschoubben a5e351f4cb Nine resolved issues name where their fix landed
The cycle check now asks a resolved issue for its owner, and these had none.
2026-09-21 17:39:34 +02:00
jschoubben e3279f4b5b Issue 054 names where its fix landed 2026-09-21 17:39:09 +02:00
jschoubben d52687d0c8 Issues 067 and 068 name where their fix landed 2026-09-21 17:38:48 +02:00
jschoubben 36d9b38a0d An issue is open, diagnosing, located, resolved or wontfix — nothing else
The playbook, the README and the status skill knew five statuses; the cycle check
knew a sixth, 'fixed', and not 'wontfix'. Eleven issues sat in the sixth for weeks
with their fixes shipped, one step short of closed. They are resolved; the check
refuses the word from now on and accepts the one the playbook allows.
2026-09-21 17:38:17 +02:00
jschoubben da6414c27c Issue 072 diagnosed: genesis registers the manifest its build produced; design 17 says so
ADR 0069 had already placed the controller's manifest in its own repository, and the
raising design called the catalogue copy a thing to remove. The installer's step 3 was
handed that manifest by the build and step 9 read a second copy anyway.
2026-09-21 15:18:32 +02:00
jschoubben 5dcb9dfbf6 ADR 0089: a bed reads the catalogue it proves; issue 073 diagnosed; issues 074 and 075 opened
The end-to-end design held 'the run rebuilds what it tests' for binaries and images
and not for manifests. The beds' inline copies fell into three kinds; only the first
is a stale copy. The other two are named: a mesh test wearing a catalogue module's
name (074) and a stocked runtime image the run never rebuilds (075).
2026-09-21 14:35:08 +02:00
jschoubben 1c90777124 Merge pull request 'Issues 031, 035 and 054 name their merges, the branch being gone' (#61) from chore/migration-blockers-merges into main 2026-09-21 13:50:06 +02:00
jschoubben ba07b43b18 Issues 031, 035 and 054 name their merges, the branch being gone 2026-09-21 13:49:56 +02:00
jschoubben 1db93ffc64 Merge pull request 'ADRs 0087 and 0088; issues 031, 035 and 054 resolved; issue 041 surveyed; issue 073 opened' (#60) from feat/migration-blockers into main 2026-09-21 13:49:09 +02:00
jschoubben ea42b00d0a Issue 041: mongodb names its secrets' owner; the three conversions are proven 2026-09-21 13:47:39 +02:00
jschoubben 198e4db0a3 Design 07: the base ruleset closes the hub's port until the filter module derives one 2026-09-21 13:30:26 +02:00
jschoubben a438cbdac3 Issue 041: the declared exceptions, surveyed and partly converted 2026-09-21 12:53:14 +02:00
jschoubben 5fa35362ac Issue 073: beds carry copies of catalogue manifests 2026-09-21 12:31:04 +02:00
jschoubben ee67f69ef4 ADRs 0087 and 0088; issues 031, 035 and 054 resolved; designs 05, 07 and 18 amended
A seeded file is created once (0087); the foundation filters before anything
listens (0088); a machine becomes the last thing it was told (design 05).
Each says how it is checked.
2026-09-21 12:11:50 +02:00
jschoubben a211aecdfa Merge pull request 'ADR 0086 (a secret reaches a process as a file), the vault shipped, issues 041 and 072' (#59) from feat/secret-not-in-environment into main 2026-09-21 11:59:21 +02:00
jschoubben 5fb8f06a91 Issue 072: the controller's manifest exists twice; decisions index regenerated for ADR 0086 2026-09-21 10:34:17 +02:00
jschoubben ec7b6e0748 ADR 0086: a secret reaches a process as a file, and an exception is declared
Closes issue 041 by decision and by code on the same branch: the catalogue
engine refuses a secret in a container's env, and a secret-carrying env-file
unless the container declares its reason; the controller reads all six of
its credentials from files; design 13 states the rule and how it is checked.
2026-09-21 10:10:33 +02:00
jschoubben 7015bf58ac The vault shipped: as-is 06 describes it, design 24 is implemented, 071 names its merges 2026-09-21 10:10:33 +02:00
jschoubben aa9b5b99e4 Merge pull request 'The secrets vault: handoff, the amended decision, issues 069–071, and the reconciliation of open issues' (#58) from feat/secrets-vault into main 2026-09-21 10:03:28 +02:00
jschoubben 61f61b5d06 Reconcile the open issues against main
An audit of the six code repositories found eleven open issues fixed on main
with commits and beds to show (025, 027, 033, 036, 037, 040, 045, 047, 050,
052, 053), three partly (007, 026, 035), nine not (020, 031, 041, 046, 049,
054, 064, 065, 066) and one whose fix would live outside those repos (006).
Resolved ones name their evidence; partly ones say what remains; 041 records
that the exposure has widened since it was reported.
2026-09-21 01:52:53 +02:00
jschoubben ffd7592687 Design 24: the export says what an earlier key opens 2026-09-21 01:16:54 +02:00
jschoubben 1bce3f33a8 Designs 07 and 21 and issue 071: genesis now makes the root secrets
The installer half of the amended ADR 0085 is built and proven by the
genesis bed's root-secrets step; the foundation design closes its open item
and the installation design says what the installer does and what it still
cannot check.
2026-09-21 00:50:56 +02:00
jschoubben 8607d21110 Design 24: pair credentials are sealed to the operator too 2026-09-21 00:36:30 +02:00
jschoubben 050a2d08e8 Playbook 07: a feature worktree needs the siblings the lab reads
A bed run from .work/<slug>/mesh-lab derives mesh-tools and mesh-sdk by
sibling path and fails at once when the directory holds only the touched
repos. Detached worktrees on main, never symlinks.
2026-09-21 00:27:01 +02:00
jschoubben baa3351552 Amend ADR 0085: the vault is a foundation module and holds the root secrets
Recorded on the record, dated, before anything shipped against the sentences
that change. The vault is installed at genesis like the store and broker, one
per mesh, and holds every secret a module has for itself sealed a second time
to an operator key whose private half never enters the mesh — the break-glass
path the first version left open, without a key one place holds.

Design 24 says how; 07 and 21 say what genesis does not yet do; issue 071
names the fixed credentials the foundation is raised with today.
2026-09-20 23:55:01 +02:00
jschoubben 187389b7d1 Hand off the secrets vault to mesh-catalog; open issues 069 and 070
Design 24 flips to in-progress with mesh-catalog as its owner (playbook 04).
Starting the build surfaced two gaps the decision did not settle: a module
requiring `secret` receives exactly one value (069), and no command can
accept an operator's value into a consumer↔vault pair (070). Both opened as
issues rather than improvised around.

Also fills fixed-by on 067 and 068, which the cycle check refused as resolved
with no reference.
2026-09-20 23:08:28 +02:00
jschoubben 731027c009 Merge pull request 'Graduate issues 067 and 068 — provider scoping and the secrets vault' (#57) from multi-node/harden-and-prove into main 2026-09-20 21:30:12 +02:00
jschoubben fc4ab370d6 Graduate issues 067 and 068 to decisions and to-be designs
ADR 0084 (extends 0027) — a provision is served by a node-scoped provider the
consumer selects, defaulting to co-location; a module may instead carry a private
embedded instance that is not a provision. Design: 01-to-be/23-choosing-a-provider.

ADR 0085 (extends 0031) — a secret is a provision and the vault is the module that
provides it; a module's own local secret becomes an ordinary pair credential that
rotates through the existing machinery, while the controller's provisioning-credential
mint (0048) is unchanged. Design: 01-to-be/24-the-secrets-vault; doc 13 amended to
cross-link the non-pair secret.

Issues 067/068 marked resolved with amended-design set. ADR index regenerated;
records and index checks pass.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-20 21:27:29 +02:00
jschoubben d66579c8f6 Issue 068 — secrets have no owning module
Store and broker seats were made ordinary modules; secret-minting is still a
privileged property of the controller that no module owns. Propose the vault
become a module that provides a secret provision (generate/hold/rotate/backup/
audit), node-scoped like every other provider (issue 067), subsuming the three
secret paths and giving local-secret rotation a home.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-20 21:24:42 +02:00
jschoubben c4ff0478b7 Issue 067 — fold in the embedded-vs-provisioned axis
Naming which provider is only half of how a module gets a database. The other
half: a module may carry its own version/fork-pinned instance, module-network
only, no published port, not a provision — and the model has no word for it.
Add it as a second axis with its own open questions.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-20 21:24:42 +02:00
jschoubben 1ce9ffe79f Issue 067 — a provision cannot name which provider serves it
The mesh models provisions as mesh-scoped (one provider of a kind, a single
mesh-store). But node-specific services delivered to the mesh was the plan from
the start: both nodes already run their own postgres, SQL server, redis and
object store, and identity — currently single — already serves apps on a second
node. The model cannot express which provider serves a consumer, so it collapses
a deliberately per-node fleet to one. Provider scoping is a whole-mesh decision
across postgres/s3-bucket/oidc, not an SSO patch.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-20 21:24:42 +02:00
jschoubben df2c3f63a5 Merge pull request 'Issues 065 and 066 — the apply failure model's two gaps' (#56) from issue/065-066-apply-failure-model into main 2026-09-20 14:28:18 +02:00
jschoubben a9bc0c1cc5 Open issues 065 and 066 — the apply failure model's two gaps
Surfaced while reviewing the host apply loop for the controller/host
split discussion. 065: a permanently-failing resource retries for ever
with no escalation — reported, but never raises its hand as stuck.
066: a partly-applied declaration leaves a mixed state with no rollback,
which is harmless for independent resources and unexamined for pairs
that are only correct together. Both are questions HQ must answer, not
incidents — status open, no fix proposed.
2026-09-20 14:28:04 +02:00
jschoubben 6d28683898 Merge pull request '057 and 058 resolved — fixes merged and proven' (#55) from issue/057-058-resolve into main 2026-09-20 12:55:16 +02:00
jschoubben 82c03a8d10 057 and 058 resolved — their fixes merged and proven
The P1-sweep PR left both at 'located'; the fixes have since merged
(mesh-controller #31, mesh-tools #10) and the bed proves them. Flip to
resolved with their fixed-by.
2026-09-20 12:55:00 +02:00
jschoubben 31c5aee72d Merge pull request 'ADR 0083 and issues 057/058/060/063/064 — the P1 sweep' (#54) from issue/057-058-one-push-patient-runtime into main 2026-09-20 12:53:24 +02:00
jschoubben 05857f71f0 Accept ADR 0083 — one push leaves the mesh consistent 2026-09-20 12:52:55 +02:00
jschoubben 98e9e62fce Issues 060 resolved, 064 opened; 057/058 on this branch too
060: 44 of 70 modules now mesh-buildable (was 8) — the mechanical
majority, proven by direct builds and the bed. The structural
remainders: external-dependency fetch (new issue 064) and route-proxy's
cross-repo build context. 064 records the build environment's isolation
from public npm and Docker Hub.
2026-09-18 02:52:36 +02:00
jschoubben 0d5693cc2c ADR 0083: the cascade compares against what was last sent, not a snapshot 2026-09-18 02:38:00 +02:00
jschoubben 1572d74a18 Issue 063 — the foundation's ports are forwarded, resolved
The broker's port was accepted on input but not forwarded, so a joined
node reached a DNAT'd broker only until it restarted. Fixed in
mesh-controller (25e42b3), proven by the built-store-cross-node bed
adopting the foundation's broker (which restarts it) and the joined
node still receiving declarations.
2026-09-18 02:20:11 +02:00
jschoubben 9fd7e6c458 ADR 0083 proposed; 057/058 diagnosed and located
One push leaves the mesh consistent (the 057 decision, proposed for
acceptance); the shared runtime waits for its broker (058). Fixes on
mesh-control fix/one-push-is-enough and mesh-tools
fix/the-runtime-waits-for-its-broker; the built-store-cross-node bed
enforces both.
2026-09-18 02:10:01 +02:00
jschoubben 5703c86cf6 Merge pull request 'Issue 059 resolved — the broker credential resolves the seat' (#53) from issue/059-broker-address-seat into main 2026-09-18 01:13:13 +02:00
jschoubben d85d74d607 059 resolved — the broker credential resolves the seat
Fixed by mesh-controller PR 30 (79a9e17), rebased onto the merged
registry-reach train and proven by a green fresh run of the no-fake
two-node bed built from that commit.
2026-09-18 01:13:03 +02:00
jschoubben 46efb7ae98 Merge pull request 'ADR 0082 and issues 042/048/061/062 — the registry is reached by name and trusted by the overlay' (#52) from issue/042-048-registry-reach into main 2026-09-18 01:00:55 +02:00
jschoubben 4279e4914b 042/048/061/062 resolved — the network carries the registry trust
One green fresh run of the no-fake two-node bed is the proof: node2's
consumers open the store and broker the mesh built and adopted, over
the overlay. Fixed by mesh-controller PR 29, mesh-catalog PR 26, gated
by mesh-lab PR 34.
2026-09-18 00:26:50 +02:00
jschoubben a0acaad86d Issues 061/062 — two silent-success defects the no-fake bed surfaced
061: the broker module's provisioner never ran; its runtime container
named no command and the image default is the tool host. 062: a failed
artifact-store lookup composed the network without the registry trust,
turning a transient error into permanent silent state. Both located,
fixes on the 042/048 train branches.
2026-09-18 00:23:52 +02:00
jschoubben 08c814aa0a 0082 takes its homes: 042/048 located against it, the delivery design cites it
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 23:02:32 +02:00
jschoubben 32fa6b40f5 ADR 0082: the registry is reached by name, and the overlay is its security
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 23:02:18 +02:00