Commit Graph
1345 Commits
Author SHA1 Message Date
mesh-admin 213dcbafe9 Merge pull request 'Research 031: a core that cannot fail silently' (#125) from research/031-a-core-that-cannot-fail-silently into main 2026-10-06 00:32:15 +00:00
jochen 0f163a3e7c Research 031 graduates: ADR 0227 and to-be 45
The operator approved the conclusion: the core must say when it is wrong
instead of waiting to be looked at. Record the nine rules with their
checks, and specify the parts and the six phases a build can take.
2026-10-06 02:31:21 +02:00
mesh-admin 09fa192cac Merge pull request 'ADR 0225: a consumer's identity is bounded by the provision it requires' (#127) from decision/0225-a-consumers-identity-is-bounded-by-the-provision-it-requires into main 2026-10-06 00:28:47 +00:00
mesh-admin 3e55277aa9 Merge pull request 'Issue 268: letta printed its passwords into its log' (#126) from issues/268-letta-printed-its-passwords into main 2026-10-06 00:25:32 +00:00
jochen 8fade781a7 ADR 0225: a consumer's identity is bounded by the provision it requires
Issue 263: one global 20-character bound held keyless provisions to an
object store's key, was found only when a provider composed, and then
refused the provider's whole machine. Take ADR 0049's option C, check
overflows before merge, and leave an overflowing consumer out of its
provider's grants instead of refusing the provider.
2026-10-06 02:18:03 +02:00
jochen f6f5563de2 Issue 268: letta printed its passwords into its log
Record the leak, its cause, the fix and the rotation steps the operator
approves once the fix runs, so the exposed secrets are replaced in order.
2026-10-06 02:15:00 +02:00
jochen 97ff655e34 Research 031: open the effort on a core that cannot fail silently
The operator's mandate: races, ignored commands and silence keep recurring.
Classifies 48 recent issues by class, proposes nine checkable principles and
a phased roadmap, for review before anything graduates.
2026-10-06 02:09:55 +02:00
mesh-admin 202f2aa144 Merge pull request 'Issue 267: a reconcile's report overtook the apply that followed it' (#124) from issues/267-a-reconcile-report-overtook-the-apply into main 2026-10-05 23:47:11 +00:00
jochen d77399055c Issue 267: a reconcile's report overtook the apply that followed it
Record why a release plan waited on a report it had already been given,
and point issue 264 at it, since 264's fix was suspected and is not the
cause.
2026-10-06 01:46:33 +02:00
mesh-admin 3ba75a312b Merge pull request 'Issue 266: a merge on the bus was never handed to the controller' (#123) from issues/266-a-merge-the-bus-never-handed-the-controller into main 2026-10-05 23:33:19 +00:00
mesh-admin 64c2d3a0a1 Merge pull request 'Issue 265: a push outlived its caller, and the bus refused its answer' (#122) from issues/265-a-verb-outlasting-its-caller into main 2026-10-05 23:33:12 +00:00
jochen 14dabf60ee Issue 266: a merge on the bus was never handed to the controller
The bus server's multi-filter consumers skip messages on 2.10; record the
evidence, the reproduction, and the two fixes (server upgrade, catch-up).
2026-10-06 01:30:08 +02:00
jochen 1d8745b54d Issue 265: a push outlived its caller, and the bus refused its answer 2026-10-06 01:14:56 +02:00
mesh-admin f9e0517e0f Merge pull request 'Issue 244: located — the console drops a mesh seat's node, and a push ran on every machine' (#121) from issues/244-located into main 2026-10-05 22:55:03 +00:00
mesh-admin 88f7f79fbb Merge pull request 'Issue 179 recurred; ADR 0224: a provider that keeps failing a consumer is a problem the controller reports' (#119) from issues/179-recurred-and-safety-nets into main 2026-10-05 22:43:01 +00:00
jochen 3ee27b870d Issue 244: located — the console drops a mesh seat's node, and a push ran on every machine
The same empty schemas recurred for push, plan, assign, pin and settings;
for push the dropped machine became a push of the whole mesh. Record the
evidence, the cause in the console's address form, and the open fixes.
2026-10-06 00:38:37 +02:00
mesh-admin 9bcd714ee6 Merge pull request 'Issue 264: a self-updating engine lost the report of the apply that delivered it' (#120) from issues/264-self-update-lost-report into main 2026-10-05 22:31:47 +00:00
jochen 3a8c23ef1a Issue 264: a self-updating engine lost the report of the apply that delivered it
Recorded so the release plan's stall on the anchor has a cause and a fix on
record; the fix is in mesh-host and not yet merged.
2026-10-06 00:30:45 +02:00
mesh-admin fd4df96c21 Merge pull request 'Design: resolv.conf is the uplink's holder's; a machine's names are node-hostname's (ADR 0223 parts 2–3)' (#117) from design/0223-uplink-resolv-and-hostname into main 2026-10-05 22:20:32 +00:00
jochen 1e02593adf Issue 179 recurred; ADR 0224: a provider that keeps failing a consumer is a problem the controller reports
The identity provider's admin lost the mesh's password again when its database
moved, and 31,000 silent failures followed. Record the recurrence, the rule
that makes a failing provider visible in status, and the module's self-repair.
2026-10-06 00:14:38 +02:00
mesh-admin aa5a735994 Merge pull request 'Issue 263: every consumer pays for the tightest backend's name limit' (#118) from issues/263-the-identity-limit into main 2026-10-05 22:09:58 +00:00
jochen 6db919f789 Issue 263: every consumer pays for the tightest backend's name limit 2026-10-06 00:09:53 +02:00
jochen 9b7fac3084 Design: resolv.conf is the uplink's holder's, a machine's names are node-hostname's (ADR 0223 parts 2 and 3)
The build of both parts is in review; the designs now say how they work and
are checked, and ADR 0223 records that the managers' own DNS mechanisms could
not write the mesh's file.
2026-10-05 23:44:41 +02:00
mesh-admin 947965e750 Merge pull request 'Issues 190, 259, 262: resolved' (#116) from issues/190-259-262-resolved into main 2026-10-05 20:56:31 +00:00
jochen 00a0d75ced Issues 190, 259, 262: resolved and verified 2026-10-05 22:56:26 +02:00
mesh-admin 178994ee0d Merge pull request 'ADR 0223: the mesh has two resolvers, and a machine lists only them' (#115) from decision/0223-the-mesh-has-two-resolvers into main 2026-10-05 20:48:09 +00:00
jochen 4f1300fd48 ADR 0223: the mesh has two resolvers, and a machine lists only them
musl asks every listed nameserver at once and takes the first reply, so ADR
0196's public fallback answered NXDOMAIN for mesh names in every Alpine build
on the home server. Decide two mesh resolvers and no public line now; record
resolv.conf moving to the uplink's holder and /etc/hosts with /etc/hostname
moving to one hostname seat as the next steps. Amend to-be 08 and 26.
2026-10-05 22:43:18 +02:00
mesh-admin 6e59281806 Merge pull request 'ADR 0222: a module is told where a mesh seat's holder is reached; the controller writes no file a seat's holder owns (issue 190)' (#113) from issues/190-controller-writes-no-owned-file into main 2026-10-05 20:42:57 +00:00
jochen dae33af8b0 Merge main into issues/190-controller-writes-no-owned-file; index regenerated 2026-10-05 22:42:53 +02:00
mesh-admin 48e4ac9aa7 Merge pull request 'Glossary: node-engine replaces "host agent" and mesh-host' (#114) from glossary/node-engine into main 2026-10-05 20:31:18 +00:00
jochen eb7356360f Glossary: the node-engine, the program every node runs, replaces "host agent" and mesh-host 2026-10-05 22:31:13 +02:00
mesh-admin 6719ab029c Merge pull request 'ADR 0221: a push sends no build a policy or a plan holds back, except to the machine it names' (#112) from decision/0221-a-push-sends-no-held-build into main 2026-10-05 20:26:49 +00:00
jochen 93bed2147f ADR 0222: a module is told where a mesh seat's holder is reached; the controller writes no file a seat's holder owns
Issue 190's remaining steps: the runtime's module states the registry trust through
${seat:mesh-artifact-store:reach}, the private network stops writing it, generated resources
meet the collision check, and the rollout is an order rather than one push. ADR 0082 and 0102
get notes saying where their mechanism now lives.
2026-10-05 22:24:15 +02:00
jochen 95ce92c62f ADR 0221: a push sends no build a policy or a plan holds back, except to the machine it names
A named push's cascade sent every machine a build held back by `record` or by
a plan waiting on its first machine, so a change meant to be walked through
the mesh one machine at a time reached all of them at once (issue 259).
Records the decision, narrows ADR 0083's flush with a dated pointer, amends
to-be 30, and locates issue 259 in the controller.
2026-10-05 22:23:29 +02:00
mesh-admin 072489e653 Merge pull request 'Issues 260, 262: a service waits for what it reads; a mesh name has no IPv6 address rather than no name' (#111) from issues/260-262 into main 2026-10-05 20:08:22 +00:00
jochen eb4b4256a1 Issues 260, 262: a service waits for what it reads; a mesh name has no IPv6 address rather than no name 2026-10-05 22:08:12 +02:00
mesh-admin 553d0c8893 Merge pull request 'ADR 0220: what a machine asks needs its uplink held, and the retired resolver pieces go' (#110) from decision/0220-resolver-config-needs-the-uplink into main 2026-10-05 20:02:59 +00:00
jochen 08643a2128 ADR 0220: resolver config needs the uplink; retired resolver pieces go
The rule that keeps resolv.conf the mesh's was checked by nothing, and a
retired seat and an unused module still read as live options. Amends to-be
26 and 08 to match.
2026-10-05 21:59:28 +02:00
mesh-admin 4fac135a46 Merge pull request 'Issues 257, 261: a reconcile applied an older declaration over a newer one' (#109) from issues/257-261-a-reconcile-applied-an-older-declaration into main 2026-10-05 19:44:14 +00:00
jochen f391c5c36c Issues 257, 261: a reconcile applied an older declaration over a newer one 2026-10-05 21:44:09 +02:00
mesh-admin e6fbb86373 Merge pull request 'Issue 258: resolved' (#108) from issues/258-resolved into main 2026-10-05 19:18:57 +00:00
jochen c8af8d5eb1 Issue 258: resolved 2026-10-05 21:18:49 +02:00
mesh-admin 0e193ebc41 Merge pull request 'Issues 258–260: what the move to one resolver met' (#107) from issues/258-260-the-resolvers-rollout into main 2026-10-05 19:15:18 +00:00
jochen a0de734ed6 Issues 258–260: what the move to one resolver met 2026-10-05 21:15:09 +02:00
mesh-admin 55e776a1cd Merge pull request 'Issue 257: a plan waited on a declaration its first machine never reported' (#106) from issues/257-a-plan-waited-on-a-declaration-its-first-machine-never-reported into main 2026-10-05 18:44:23 +00:00
jochen c233a1bbac Issue 257: a plan waited on a declaration its first machine never reported 2026-10-05 20:42:41 +02:00
mesh-admin 035d4a27e3 Merge pull request 'ADR 0219: the build queue is controlled through the controller and the build seat' (#105) from decision/0219-the-build-queue-is-controlled into main 2026-10-05 18:22:01 +00:00
jochen 77429488b0 ADR 0219: plans say what their builds wait on, and a failed plan can go on 2026-10-05 18:56:18 +02:00
jochen 3944e4f914 ADR 0219: the build queue is controlled through the controller and the build seat
The operator asked for tools to see, cancel, clear, stop, pause, continue,
restart and replay builds; none existed. Queue actions are the controller's,
process actions the build seat's per machine, and every action that drops
work leaves a failed outcome so no plan waits on it. To-be 18 amended.
2026-10-05 18:54:44 +02:00
mesh-admin ab1fbe3202 Merge pull request 'Issues 224, 248-252, 254, 255 resolved; 256 opened and resolved; 253 where it stands' (#104) from records/resolved-2026-10-05 into main 2026-10-05 16:36:27 +00:00