jschoubben
4f599f361b
to-be 43: in progress — the seat, the restic holder and the stores' contributions
2026-10-05 11:47:59 +02:00
jschoubben
daf2f6d2b1
Merge pull request 'to-be 43: backups against mistakes (graduates research 030)' ( #90 ) from design/43-backups-against-mistakes into main
2026-10-05 09:35:22 +00:00
mesh-admin
4924b26b3c
Merge pull request 'ADR 0215: the machine's message bus is a node seat, and it is never restarted live' ( #91 ) from decision/0215-the-message-bus-is-a-node-seat into main
2026-10-05 09:33:36 +00:00
jochen
d088f8ec2f
ADR 0215: the machine's message bus is a node seat, and it is never restarted live
2026-10-05 11:33:20 +02:00
jschoubben
431375d16c
to-be 43: backups against mistakes, declared by modules, kept on the machine
...
Graduates research 030 into a design for ADR 0214, which merged without one and left the cycle
check failing on main.
2026-10-05 11:31:19 +02:00
jschoubben
e51d6f1d86
Merge pull request 'Research 030 + proposed ADR 0214: backups against our own mistakes' ( #88 ) from research/030-backups-against-our-own-mistakes into main
2026-10-05 09:30:35 +00:00
jschoubben
a906cd8e67
ADR 0214: accepted by the operator
2026-10-05 11:30:33 +02:00
jschoubben
3d0ce3e6dd
Research 030 and proposed ADR 0214: backups guard against mistakes and stay on the machine
...
The operator scoped backups to mistakes, not disasters (issue 242). Issue 238: fix the failed logins
at their source instead of exempting the operator's address.
2026-10-05 10:07:36 +02:00
mesh-admin
bc51d8e7aa
Merge pull request 'Issue 195: resolved' ( #86 ) from issue/195-resolved into main
2026-10-05 08:01:20 +00:00
mesh-admin
85c6db0600
Merge pull request 'Research 029: the agent configured through its module, as a plugin the mesh serves' ( #85 ) from research/029-the-agent-configured-through-its-module into main
2026-10-05 08:01:16 +00:00
mesh-admin
9d18968323
Merge pull request 'Issue 243: a rebuilt licence store silences every node' ( #84 ) from issue/243-a-rebuilt-licence-store-silences-every-node into main
2026-10-05 08:01:13 +00:00
jochen
127675e2da
Issue 243: a rebuilt licence store silences every node
...
The manager's generation counter restarted with its store after issue 241,
and nodes that wait for a higher number discarded every binding unseen.
2026-10-05 09:59:17 +02:00
jochen
0e87aad949
Research 029: a running session takes the plugin on reload
2026-10-05 09:53:13 +02:00
jschoubben
2a501af0eb
Merge pull request 'Issues 239–242: a name taken over, a dry run recorded, every database dropped, no backups' ( #83 ) from issues/239-242 into main
2026-10-05 00:25:50 +00:00
jschoubben
bd7fc40099
Issue 239: name no installation
2026-10-05 02:24:27 +02:00
jschoubben
93d4d29b72
Issues 241, 242: one unreadable grants file dropped every database, and the mesh has no backups
...
241: the SDK harness read a failed read as "no consumer" and withdrew all seven databases on the
control node; withdrawal destroyed data in seven providers. Fixed in mesh-sdk 0.1.10, mesh-catalog#44
and mesh-host#22; the recovery and what it lost are recorded. 242: nothing backs anything up.
2026-10-05 02:24:11 +02:00
jochen
6ff2440e5d
Research 029: the plugin route confirmed on one workstation
...
Six of seven checks confirmed and autoMode from managed settings very likely;
the agent cannot undo its own managed settings, which a design must allow for.
2026-10-04 23:46:32 +02:00
jochen
65c3315a14
Research 029: the agent's configuration is managed at three scopes
...
The operator's direction: mesh, node and home. A plugin carries the first
two; the home scope places items the module owns path by path; instructions
follow the same layering.
2026-10-04 17:52:48 +02:00
jochen
854341d4f0
Research 029: the agent configured through its module, as a plugin the mesh serves
...
Skills, subagents and hooks have no machine-wide place but a plugin, and
hand-copied homes have drifted and gone stale on every machine. Records the
evidence, what the vendor allows, and the options a decision must settle.
2026-10-04 17:46:24 +02:00
jochen
d444458bf6
Issue 195: resolved by the controller composing users only for modules that can read an account
2026-10-04 17:37:20 +02:00
mesh-admin
dd8b15a0df
Merge pull request 'Issue 195: located in the controller's user composition' ( #370 ) from issue/195-diagnosis into main
2026-10-04 15:34:11 +00:00
mesh-admin
02b4ca9bec
Merge pull request 'ADR 0213: the operator sets the agent's managed settings through the agent module' ( #369 ) from feat/claude-code-agent-settings into main
2026-10-04 15:34:09 +00:00
jochen
7cd5b37afe
Issue 195: located in the controller's user composition
...
Records why a module that cannot read an account is no bus user, what else
read those users (durable consumers), and answers the report's questions.
2026-10-04 17:33:27 +02:00
jschoubben
aac0da9c0c
Merge pull request 'ADR 0199: a module that answers names declares its zone, and a node's hosts file is one module's' ( #337 ) from decision/0199-zones-and-the-hosts-file into main
2026-10-04 15:33:07 +00:00
jochen
57b818b669
ADR 0213: the operator sets the agent's managed settings through the agent module
...
Rules for what the agent may do were set by hand per machine, invisible to
the mesh, and a session cannot loosen its own permissions; design 36 now
takes them as a module setting under the mesh's own keys.
2026-10-04 17:32:18 +02:00
jschoubben
33c10aa85a
Issues 239, 240, and 238's diagnosis: a module name taken over, a dry run recorded, the operator banned
...
239: two repositories defined photos; a rebuild to the catalogue's main replaced the app with a stub
and nothing refused it. 240: a dry-run build was recorded and its definition reached the machine.
238: the forge refused three ssh logins as the operator's account in 31 seconds; nothing in the mesh's
ssh configuration names the forge, and no jail ignores the mesh's own public addresses.
2026-10-04 17:31:29 +02:00
mesh-admin
e5042e1e7a
Merge pull request 'Issues 237, 238: a self-contradicting assign answer, and the operator's address banned' ( #367 ) from issues/237-238-a-stale-answer-and-a-banned-operator into main
2026-10-04 15:06:51 +00:00
jochen
2580fb6839
Issues 237, 238: a self-contradicting assign answer, and the operator's address banned
2026-10-04 17:06:38 +02:00
mesh-admin
4a8a378ef9
Merge pull request 'ADR 0212: a seat says what it receives, and the machine's hotkeys are a seat' ( #366 ) from decision/0212-contributions-to-a-seat-and-hotkeys into main
2026-10-04 14:42:31 +00:00
jochen
3f48e685cc
ADR 0212: a seat says what it receives, and the machine's hotkeys are a seat
2026-10-04 16:42:21 +02:00
mesh-admin
1e0b9ee11f
Merge pull request 'As-is: a module's state, and the agent with its licences; designs 36, 39, 40 implemented' ( #365 ) from design/state-and-licences-as-is into main
2026-10-04 14:33:50 +00:00
jochen
1faa63b2d5
As-is: a module's state and the agent with its licences; designs 36, 39 and 40 implemented
...
What runs since 2026-10-04 and what its first live use showed: refused
requests as timeouts, a late machine reading the whole set, the partial
secrets guard; the agent module and the licence manager on every machine.
2026-10-04 16:32:29 +02:00
mesh-admin
3a359bf99e
Merge pull request 'ADR 0211: a machine's power is a node seat, its moments take contributions, and its states are events' ( #364 ) from decision/0211-power-is-a-node-seat into main
2026-10-04 13:58:25 +00:00
jochen
ec6d106af8
ADR 0211: a machine's power is a node seat, its moments take contributions, and its states are events
2026-10-04 15:58:16 +02:00
jochen
e2b4f3a5c4
Regenerate the decision index
2026-10-04 15:58:09 +02:00
mesh-admin
dfb2817fe7
Merge pull request 'ADR 0210: a tool's configuration is its seat holder's, and every other module extends it through the seat' ( #361 ) from decision/0210-a-contribution-depends-on-the-seat-that-receives-it into main
2026-10-04 13:42:56 +00:00
mesh-admin
12742e3a3f
Merge pull request 'Designs 36 and 39: the manager's verb is public-key' ( #363 ) from fix/the-verb-is-public-key into main
2026-10-04 13:41:32 +00:00
jochen
5b00bdc7af
Designs 36 and 39: the manager's verb is public-key (a seat's verb takes no underscore)
2026-10-04 15:41:23 +02:00
mesh-admin
d5a96e5c63
Merge pull request 'Research 028: the mesh's output channel' ( #362 ) from research/028-the-meshs-output-channel into main
2026-10-04 13:36:17 +00:00
jochen
73e6400802
Research 028: the mesh's output channel — how the mesh tells its operator what it noticed
2026-10-04 15:36:03 +02:00
jochen
f144ad7be4
To-be 42: who writes what in phase 2 (ADR 0210)
2026-10-04 15:20:01 +02:00
jochen
8394a7bfb1
ADR 0210: a tool's configuration is its seat holder's, and every other module extends it through the seat
2026-10-04 15:19:44 +02:00
mesh-admin
6ac936f170
Merge pull request 'Issues 235, 236: an assignment and a check that let through what then fails' ( #360 ) from issues/235-236-an-assignment-and-a-check-that-let-through-what-fails into main
2026-10-04 13:19:41 +00:00
jochen
3af4179755
Issues 235, 236: an assignment and a check that let through what then fails
2026-10-04 15:17:46 +02:00
mesh-admin
dd04729ec5
Merge pull request 'ADR 0209: a login on a node moves that node to its account; an API key is added from any node, sealed' ( #359 ) from decision/0209-a-login-moves-its-node into main
2026-10-04 13:12:01 +00:00
jochen
2e5f40c9fa
ADR 0209: a login on a node moves that node to its account; an API key is added from any node, sealed
...
Traced live: a login to a second account was adopted and left its node
bound to the first, holding a spent refresh token. Designs 36 and 39
amended.
2026-10-04 15:09:56 +02:00
mesh-admin
2f41b4124d
Merge pull request 'Issues 233, 234: a stale declaration removed four modules, and the host could not recover' ( #358 ) from issues/233-234-a-stale-declaration-and-a-host-that-cannot-recover into main
2026-10-04 13:09:47 +00:00
jochen
9cc00d57ea
Issues 233, 234: a stale declaration removed four modules, and the host could not recover
2026-10-04 14:54:50 +02:00
mesh-admin
438162b5a5
Merge pull request 'Issues 225, 226 and 227 resolved with their live proofs; 232 opened and resolved' ( #357 ) from issues/228-photos-authenticates-against-admin into main
2026-10-04 10:37:53 +00:00
jschoubben
ab1bd5598e
Issues 225, 226, 227 resolved with their live proofs; 232 opened and resolved
...
225: a grant secret is composed with the account that reads it — the node's
account for a bundle, the declared secrets-owner for a container. Zero EACCES
since 12:30:10 where there had been 4330, both users created, mongodb logging
Authentication succeeded for each. The harness also stops calling a permanent
refusal a race, which is the half that cost three hours.
226: normalising moved to the records, where the provenance is known, and a
reference the sweep will not address is skipped rather than ending the sweep.
The first build after the roll-out collected 200 and said 1126 remain — the
backlog falls with every build instead of standing at 1681 for ever.
227: the three photo modules publish the endpoint they declare, and a
catalogue-wide test makes it a rule: a container publishes only a port its
module declares, or the mesh has nothing to assign and the number escapes.
232 came out from under 225: photos asked for a database its user does not
live in, invisible while no user existed at all.
2026-10-04 12:37:31 +02:00