jschoubben
50ddaf8408
Merge pull request 'ADR 0196: a node asks the mesh's resolver first, and a public one only when it is silent' ( #330 ) from decision/0196-nodes-ask-the-mesh-resolver-with-a-public-fallback into main
2026-10-03 20:01:05 +00:00
jschoubben
f5d518d256
ADR 0196: a node asks the mesh's resolver first, and a public one only when it is silent
...
ADR 0194 rejected sending every query to the mesh's resolver because a node with its tunnel down
would resolve nothing; a public resolver listed second answers exactly then. That drops the
systemd-resolved stub and the runtime's dns: containers copy the machine's resolvers. Narrows 0194;
amends connectivity §2.
2026-10-03 21:56:33 +02:00
jschoubben
577ddf0089
Merge pull request 'ADR 0194: the mesh has one resolver, and every node asks it for the mesh's names' ( #326 ) from decision/0194-the-mesh-has-one-resolver into main
2026-10-03 19:51:04 +00:00
jschoubben
13e28e6873
ADR 0194: the no-copies check allows each node's loopback stub
2026-10-03 21:51:03 +02:00
jschoubben
6b6ff76a19
ADR 0194: why every node needs a stub, and the systemd-resolved module that provides it
2026-10-03 21:50:33 +02:00
jschoubben
1de4a5f25e
ADR 0194: the mesh has one resolver, and every node asks it for the mesh's names
...
Every resolution fault found on 2026-10-03 was a per-node copy disagreeing with the truth: a hosts
file read once, an operator's old line beside the mesh's, a node's resolver lent to a LAN. Every
tunnel already converges on one node. Retires node-dns-resolver for a mesh-scoped mesh-resolver;
nodes route only the mesh's suffix to it. Narrows 0121; amends connectivity §2 and the seats.
2026-10-03 21:21:49 +02:00
jschoubben
8a1fa37dce
Merge pull request 'ADR 0191: domains are a node's — the resolver holds each node's internal domain, nothing else' ( #323 ) from decision/0191-names-by-origin into main
2026-10-03 19:12:26 +00:00
jschoubben
2344bfb69b
ADR 0191: domains are a node's — one internal, one or more public; the roster is the machines
2026-10-03 16:10:38 +02:00
jschoubben
ca8a865e73
ADR 0191: the mesh's names are known by where they were composed, not by their suffix
...
A progressive insight: the rule and its check were stated as a suffix test; the mesh composes both
names of a route and publishes its internal one. The decision is unchanged.
2026-10-03 15:39:07 +02:00
jschoubben
9873e951a9
Merge pull request 'ADR 0191: the mesh resolves only its own names; a public name resolves publicly' ( #320 ) from decision/0191-the-mesh-resolves-only-its-own-domain into main
2026-10-03 13:16:13 +00:00
jschoubben
e5e6e56ecf
ADR 0191: the mesh's resolver holds only the mesh's own names; a public name resolves publicly
...
Publishing every routed public name at a private address turned ace's LAN-facing resolver into an
outage for non-members: a phone got the control-node's tunnel address for the mail server. Routes
have internal names since 0151 and the proxy certifies public names publicly, so nothing needs the
private answer. Narrows 0066 and 0151; amends connectivity §2 and §5.
2026-10-03 15:11:45 +02:00
jschoubben
e4a0c73e2b
Merge remote-tracking branch 'origin/main' into issues/192-193-console-registration-and-store-query
2026-10-02 22:14:24 +02:00
jschoubben
d1aeee42a4
Regenerate the decision index after merging main
2026-10-02 22:14:21 +02:00
jschoubben
da8b4b4ee4
Renumber to ADR 0188: 0187 landed on main first, as the dead-tracker record
...
Two records shared 0187 (issue 155's collision); the branch landing last
renumbers, and this is it. Only the number changes.
2026-10-02 21:01:02 +02:00
jschoubben
c026d5221e
Merge remote-tracking branch 'origin/main' into renumber-0187
2026-10-02 21:00:45 +02:00
jschoubben
9ac2493e2c
ADRs 0180, 0186 and 0187: their live rows, done — all four machines filtered by the mesh alone, both front ends removed, no machine wrong or behind
2026-10-02 20:46:35 +02:00
jschoubben
9e0288128b
ADR 0187: a dead tracker is not the machine's failure; design 32
2026-10-02 20:41:30 +02:00
jschoubben
d4a2f99ab5
ADR 0186: a ban list never holds a neighbour, and the mesh's own bans are its own wherever they hang; design 31
2026-10-02 18:42:16 +02:00
jschoubben
131a5e4714
Issue 201: what was established about the race while closing the outage half
2026-10-02 18:19:12 +02:00
jschoubben
329a24fdae
ADRs 0184 and 0185: a service is still running a moment later; a control plane behind its row serves what it can; issue 201 half closed
2026-10-02 18:16:24 +02:00
jschoubben
114a71f36f
ADR 0179: built and proven live; the one fault the machine found, and the check that refuses it
2026-10-02 17:28:38 +02:00
jschoubben
0f407417f3
Merge main: the ufw record renumbered to 0180, and ADR 0175 retires the per-module tool runtime this one ships
2026-10-02 17:28:23 +02:00
jschoubben
d0d5799884
Issue 201: a push recreated the controller at a digest older than the seat row its successor wrote
2026-10-02 17:15:22 +02:00
jschoubben
9ba4de5557
ADR 0179: the intrusion seat serves its verbs, a container may log to the journal, and every door declares its jail; designs 31 and 33
2026-10-02 17:02:49 +02:00
jschoubben
4ce967619a
Research 019: a warm twin of the running mesh in the lab
2026-10-02 16:59:36 +02:00
jschoubben
8c9a2c7501
ADR 0175: the found front end is uninstalled once a machine is converged; design 08 note
2026-10-02 16:27:33 +02:00
jschoubben
116b2d1793
ADR 0168: built and proven live — the live row read on the home server and the control node, the five rule sets removed through ADR 0170's verb
2026-10-02 15:08:58 +02:00
jschoubben
98eb3aa76f
ADR 0169 → 0170: the firewall seat's record renumbered after a collision on main; its built note; cycle.py refuses two records sharing a number
...
Another session's 0169 landed first. The collision check from issue 155
covered issue folders only; it covers decision records now, and would have
refused this.
2026-10-02 14:51:22 +02:00
jschoubben
0e7b85f184
Issues 199 (resolved: a node-scoped seat's verb through the console) and 200 (the controller's answer to a long console call is refused by the bus)
2026-10-02 14:25:03 +02:00
jschoubben
0d9208dbbf
ADR 0172: the lab is a module, and runs a bed when the mesh asks
2026-10-02 14:15:44 +02:00
jschoubben
4567e13071
ADR 0169: the firewall seat serves its verbs, and a foreign rule set is removed through one of them
...
Designs 33 and 08 revised. The first node-scoped seat with verbs: rules,
reload, remove; the nftables module holds it from a runtime with NET_ADMIN,
the first container to declare a capability.
2026-10-02 13:27:03 +02:00
jschoubben
79642251a1
ADR 0169 accepted; design 08's join order starts with the tunnel
2026-10-02 13:17:32 +02:00
jschoubben
331cb94c6e
ADR 0169 (proposed): a machine joins through the tunnel, and the bus is never public
...
The bus was public only so a new machine could enrol before it had a
tunnel. The machine now makes its tunnel key first, the token is issued
for it and makes it a peer of the hub, and enrolment happens over the
tunnel.
2026-10-02 13:13:15 +02:00
jschoubben
17ca9a262b
0164: a setting names the file it lands in (issue 198's leak between one module's files); 190 notes the fourth machine now has the resolver
2026-10-02 12:23:28 +02:00
jschoubben
967c793eaa
Merge remote-tracking branch 'origin/main' into decision/docker-module
2026-10-02 12:23:27 +02:00
jschoubben
426f741ad0
Issue 198: the home network's DNS server ran outside the mesh, and its filter closed it
2026-10-02 12:22:31 +02:00
jschoubben
9bed54d3be
Issue 197 resolved: the wired port is guarded before it is plugged in
2026-10-02 12:22:15 +02:00
jschoubben
413daf8ad5
Issue 197: a physical link that is down is not filtered when it comes up
2026-10-02 12:22:15 +02:00
jschoubben
7c3be48db2
Issues 143 and 144 resolved: the live row of ADR 0168 read on the home server and the control node
2026-10-02 12:11:17 +02:00
jschoubben
1bd13446d4
ADR 0168: a converged machine is filtered by the mesh alone, and the host says what else refuses (group 7)
...
Designs 08 and 05 revised; 141 resolved by ADR 0140 and 084 by ADR 0102 and
issue 128, both by reading; 143 and 144 decided, built on the matching
branches in mesh-host and mesh-controller, resolved when the home server's
record names the predecessor's chain.
2026-10-02 11:58:18 +02:00
jschoubben
bd6c55d225
Group 6 closed: 086, 090, 098, 099, 100, 101 resolved on the operator's decision, each saying the live row was not run
2026-10-02 11:37:08 +02:00
jschoubben
c8935aceca
Issue 194 resolved: the fixed host forgot its former archive on all four machines
2026-10-02 11:31:29 +02:00
jschoubben
d05ac367f1
Issue 196 resolved: the hub relays the mesh, re-swept live
2026-10-02 11:23:37 +02:00
jschoubben
1c0dafb918
Issue 196: the hub relays the mesh only on the ports it publishes itself
2026-10-02 11:17:11 +02:00
jschoubben
28d53dcc28
Issue 191 resolved: internal-only routes are served to the mesh, live on both proxies
2026-10-02 09:49:25 +02:00
jschoubben
df667eb710
ADR 0167: a membership carries what its module receives, and who the mesh is
...
Issue 191's route proxy needs to know who the mesh is to serve an
internal name correctly, and the first fix had it work that out alone.
The membership on the bus now carries it, from the same list the filter
uses. ADR 0138 gains an insight that the proxy is where internal reach
is kept; designs 08 and 25 say how.
2026-10-02 09:49:19 +02:00
jschoubben
098a2ca485
Issue 191: a route with only an internal name is dropped as naming nothing
2026-10-02 09:49:19 +02:00
jschoubben
db5ff5a5ee
Issue 195: every assigned module is counted as a bus user without a credential
...
The status warning names 49 users; 48 are modules that never speak on the
bus, and the one real fault, a declared broker secret filled with a
generated value, looked the same as the rest.
2026-10-02 02:44:24 +02:00
jschoubben
780c2b6e58
Issue 194: the host's own former archive stops every machine applying anything
...
Rule 5 of ADR 0163 (a former target is removed) met issue 162 (an archive
has no removal) in the host's own archive, the first time a host carrying
former targets replaced itself; every machine applied nothing from then on.
2026-10-02 02:42:19 +02:00
jschoubben
27c1db8a86
Review of 0164-0166 and 190: the mesh's own setting words stay settable; changing runtime verbs are not the console's wildcard; migration steps 1-2 are one push; dnsmasq's dns key dates from 09-23
2026-10-02 00:48:06 +02:00
jschoubben
24aeb203f7
Issue 193 resolved: both readers live on every machine, checked by asking each copy who it is
2026-10-02 00:35:03 +02:00
jschoubben
afbfd5f29d
Issue 193: mssql's variable substitution and shell commands, proven and fixed by mesh-catalog PR 210
2026-10-02 00:25:48 +02:00
jschoubben
696957aa5e
Issue 193: proven on a throwaway server, fixed for postgres by mesh-catalog PR 209; mssql has the same hole
2026-10-02 00:09:38 +02:00
jschoubben
3d54fcbb86
Merge remote-tracking branch 'origin/main' into decision/docker-module
2026-10-02 00:02:57 +02:00
jschoubben
b13ef1be81
Issues 192 and 193: the console reaches a person only by hand; the store's read-only query is not
...
192: no provision says where the console is, its port was never assigned, and nothing
owns a person's agent configuration since the predecessor left. 193: the query verb wraps
the caller's text in a read-only transaction the text can end, and its rows come back
keyed by BEGIN.
2026-10-02 00:02:51 +02:00
jschoubben
c4151e6bc4
ADR 0163 built: the take digest, the minted-secret refusal, the networks setting, settings judged where stored, genesis raising the forge as declared; issues 096, 097, 126 resolved
...
The record gets its built note; designs 05 and 09 the revisions; 086, 098,
099, 100 and 101 stay located because every machine is converged and the
record's live row — a take read on an adopted machine — has not been run;
090 is built in part, its network difference left for the take to say.
2026-10-01 23:45:57 +02:00
jschoubben
f1941304cc
ADRs 0164-0166 and issue 190: the container runtime gets a module, a seat and declared settings
...
Proposed for the operator's review: settings declared with defaults and cost (0164),
container-runtime as a kernel capability (0165), node-container-runtime seat with the
host creating containers through its holder (0166), and the runtime's file written by
modules that are not its own (190).
2026-10-01 23:13:18 +02:00
jschoubben
6f26f97fdb
Issue 189: the plan's half is built; the moved word stays for a decision
2026-10-01 22:25:31 +02:00
jschoubben
48ca2fb41b
Issue 189: a rebuild from the same commit is not a move, so a packaging module's new image never rolls out
2026-10-01 21:54:44 +02:00
jschoubben
2904c359b8
ADR 0163: taking a module over is a comparison — what it compares, refuses and carries; designs 05 and 09; group 6's issues located, 093 resolved
2026-10-01 21:12:36 +02:00
jschoubben
50e4d9c2a7
ADR 0162: built, and proven live by the first tiered plan
2026-10-01 21:00:10 +02:00
jschoubben
a2c9fbb665
Issues 184 and 188 resolved: the merge handler returns at once; a machine is resolved with its pins and a dropped one is said
2026-10-01 20:54:10 +02:00
jschoubben
606fbb7add
Issue 188: the second fault beneath the first, and its fix
2026-10-01 18:22:19 +02:00
jschoubben
a92e4bf121
Issue 188: what the live fault was and how it was resolved
2026-10-01 18:14:37 +02:00
jschoubben
187442ec7b
Issue 188: a refusal inside on-the-network drops a machine silently
2026-10-01 18:10:57 +02:00
jschoubben
82496536cd
ADR 0162: the three kinds of dependency, where the edges come from, and the one real cycle
2026-10-01 17:53:57 +02:00
jschoubben
b0de267301
ADR 0162: the link to 0157 by its name
2026-10-01 17:46:07 +02:00
jschoubben
b0a74b23fd
ADR 0162: a merge produces a tiered plan the mesh keeps; dependencies are one relation; design 30; issues 184, 186
2026-10-01 17:45:48 +02:00
jschoubben
821cd3b489
ADR 0084: a pin names the module as well as the node ( #258 )
2026-10-01 17:23:34 +02:00
jschoubben
86d1763cfa
Issues 106 and 138 resolved (ADR 0161 built and live); 187 notes a report lost without retry
2026-10-01 17:18:17 +02:00
jschoubben
ea0853ca46
ADR 0160: the live proof, and three facts it taught
2026-10-01 16:51:43 +02:00
jschoubben
03e39316ea
Issue 184: a handler replaced mid-merge loses the rest of its work, and the redelivered announcement reads as history
2026-10-01 16:25:38 +02:00
jschoubben
6be284c781
Issue 187: the mesh tells nobody when it stops working
2026-10-01 16:21:05 +02:00
jschoubben
9ddd7215ad
Issue 186 located: the delivery dropped the asks, not the queue; a merge now rebuilds dependents; the release decision stands
2026-10-01 16:16:59 +02:00
jschoubben
180e3b8f7e
Issue 186: a release across repositories is an order in a person's head, and a build is a line in a queue nobody keeps
2026-10-01 16:01:45 +02:00
jschoubben
f35f3757bb
ADR 0161: what deserves a seat — the vault's seat, the hub as a placement of capacity one, the uplink holder as the machine's dialect; design 26; issues 105, 106, 138
2026-10-01 15:55:15 +02:00
jschoubben
2175d13935
Issue 185: a refused membership publish stopped the controller; 183 points to it
2026-10-01 15:42:37 +02:00
jschoubben
eef03f2b08
ADR 0160 built: both halves, and what the first roll-out taught; issues 183 (the controller's grant) and 184 (a merge blocks the receive loop)
2026-10-01 15:23:26 +02:00
jschoubben
99eb322de5
ADR 0160: the mesh issues an assignment's subjects, and a runtime serves what it is issued; designs 25, 32, 33, 34
2026-10-01 14:33:56 +02:00
jschoubben
0acb47fa55
ADR 0159: a tool call names the machine, every answer says which answered, a holder's runtime serves its seat's verbs; issue 182; designs 33 and 34
2026-10-01 14:00:23 +02:00
jschoubben
bef510fda2
ADR 0158: the controller's half is built (mesh-controller PR 184); the provider definitions remain
2026-10-01 12:27:39 +02:00
jschoubben
d29d3dfc23
ADR 0158: a provider with one credential shares it with every consumer, and the vault remakes it for all at once; designs 24 and 13 carry it
2026-10-01 12:17:49 +02:00
jschoubben
e00e3bc3ce
Issue 181 (was 163, was 161): two records answered to 163; renumbered to the next free number across main and open pull requests
2026-10-01 12:15:31 +02:00
jschoubben
b8d8101c45
Issue 180: the live rotation done — searxng's secret on the home server through the console
2026-10-01 12:14:49 +02:00
jschoubben
48a620249b
Issue 180: a module's own secret rotates when it is read at start; the applied form stays open (controller PR 183); design 13 and ADR 0114 carry the word
2026-10-01 11:43:23 +02:00
jschoubben
79d1619f16
Issue 179: an adopted identity provider's admin never took the minted secret (fixed by hand through the server's bootstrap; the design question left open)
2026-10-01 11:02:18 +02:00
jschoubben
e1f2c6bd5b
Issue 178: a routed name resolves to a provider merely told it, and flips between plans (fixed, controller PR 181)
2026-10-01 02:04:55 +02:00
jschoubben
35f7f4401b
Issue 177: the controller's check is run by nobody; the two rotted tests fixed (controller PR 180), the process half open
2026-10-01 01:38:22 +02:00
jschoubben
f841845b0d
Issue 176 resolved: a build is taken in where its outcome is heard; the build tool answers with the id
2026-10-01 01:27:49 +02:00
jschoubben
2ffe1d0915
ADR 0157: a build says what it does on the bus, as it happens; designs 25 and 18 carry it
2026-10-01 00:43:26 +02:00
jschoubben
93f828c5eb
Issue 176: the console's build tool neither waits nor registers, and does not take a forge path
2026-10-01 00:29:05 +02:00
jschoubben
52e9df0f02
Issue 153 resolved: an assignment places a module's directories and its accesses
...
mesh-controller PR 176 and mesh-catalog PR 198. Designs 27 and 18 carry the words: places,
accesses, ${access:<id>}, the default a definition still holds while the catalogue converts.
2026-10-01 00:04:10 +02:00
jschoubben
36454d7e4a
Issues 173 and 174 resolved; the installation check refuses at registration (ADR 0155)
...
A setting overrides a key a contribution or served fact declares and adds none; a provider that must
tell its consumers an operator's value declares it as ${setting:…} (173). The mesh's own files for a
module are a placed directory, `place: "mesh"`, and forty-eight definitions name no host path for
them (174). Registration refuses a definition naming an installation, the day the list emptied
rather than a release later (0155, progressive insight; 134). Designs 27 and 18 carry the rules.
2026-09-30 22:36:20 +02:00
jschoubben
e84c822e89
Merge pull request 'Issue 175: the link to issue 127 resolves' ( #235 ) from fix/issue-175-link into main
2026-09-30 20:10:41 +00:00
jschoubben
a170913202
Issue 175: the link to issue 127 resolves
2026-09-30 22:10:38 +02:00
jschoubben
9a20c16d9b
Merge pull request 'Issue 175: an announcement queued behind a long build came back, and the build ran again' ( #234 ) from fix/one-announcement-at-a-time into main
2026-09-30 19:38:49 +00:00
jschoubben
8bd0ca0bdc
Issue 175: an announcement queued behind a long build came back, and the build ran again
2026-09-30 21:38:45 +02:00
jschoubben
598f6a8952
Merge pull request 'ADR 0156: an artifact is what a build produces, and the store's seat is named for its scope (group 4, step 3)' ( #233 ) from feat/the-artifact-store-seat-is-named-for-its-scope into main
...
Reviewed-on: http://git.novox.be/novox/hq/pulls/233
2026-09-30 19:17:28 +00:00
jschoubben
3341c037cb
Merge pull request 'Issue 119 resolved for a module's own data; issue 174 for the mesh's files (group 4, step 2)' ( #232 ) from feat/definitions-place-their-directories into main
...
Reviewed-on: http://git.novox.be/novox/hq/pulls/232
2026-09-30 19:17:21 +00:00
jschoubben
22a28ad548
ADR 0156: an artifact is what a build produces, and the store's seat is named for its scope
...
Issue 123 resolved; glossary corrected; design 26 and ADR 0121 point at the rename.
2026-09-30 21:14:40 +02:00