Commit Graph
100 Commits
Author SHA1 Message Date
jschoubben 91a5c63d65 Merge pull request 'Name the migration repository in the map, so nobody has to be told it exists' (#99) from meta/name-the-migration-repository into main 2026-09-24 00:02:07 +00:00
jschoubben 545d038198 Name the migration repository in the map, so nobody has to be told it exists
hq cannot hold the migration's operational record — it names machines, addresses and
paths, and this repository is public — but it can say where that record is, which is what
this map is for. Asked for by the operator, who had to be told.
2026-09-24 02:01:41 +02:00
jschoubben 7f438d049f Merge pull request 'Issue 092: genesis publishes to a registry the container runtime does not yet trust' (#79) from issue/092-genesis-registry-trust into main 2026-09-23 23:38:46 +00:00
jschoubben 60e43f9446 Merge pull request 'Issue 091: a module definition carries a machine port' (#78) from issue/091-machine-ports-in-manifests into main 2026-09-23 23:38:40 +00:00
jschoubben 36aa722c2a Merge pull request 'Issues 111 and 112: the resolver was told the wrong set of names, twice over' (#98) from issues/111-112-the-resolver-was-told-the-wrong-names into main 2026-09-23 23:32:42 +00:00
jschoubben f704e2ca64 Issues 111 and 112: the resolver was told the wrong set of names, twice over
111, resolved: the map the control plane hands a resolution holds the machines and the
names the mesh merely serves, and the resolver's zones were given both — inventing names
under a suffix it answers authoritatively for. 112, open: adopting a tunnel gives the mesh
the peers' addresses and none of their names, so taking the resolver before they enrol
stops three machines resolving at all.

Both found by reading the plan before pushing it.
2026-09-24 01:32:04 +02:00
jschoubben e7a90be3ee Merge pull request 'Issue 110: on a converged node a container on the runtime's own network cannot reach the resolver' (#97) from issues/110-the-resolver-and-the-default-network into main 2026-09-23 23:13:48 +00:00
jschoubben 3a8515273d Issue 110: on a converged node a container on the runtime's own network cannot reach the resolver
Found reviewing the resolver's conversion. Nothing fails while the node is adopted; it
fails at the flip, and it is the same split that decided which container survived the
hub's address change.
2026-09-24 01:13:30 +02:00
jschoubben 0e70ca0808 Merge pull request 'Issue 109: a container keeps the address it was made with' (#96) from issues/109-a-container-keeps-the-address-it-was-made-with into main 2026-09-23 23:02:48 +00:00
jschoubben 6ccd138729 Issue 109: a container keeps the address it was made with
Found when adopting the tunnel moved the hub's address: the declaration followed, the
running container did not, and the forge lost its database. Issue 102's rule broken one
level down, and issue 103's fix stopping one input short.
2026-09-24 01:02:16 +02:00
jschoubben 07ee79199a Merge pull request 'ADR 0105: what review settled — the tunnel adoption is implemented' (#95) from decide/0105-implemented into main 2026-09-23 22:39:08 +00:00
jschoubben f660620637 ADR 0105: what review settled — carried peers, the flip, the refusals, and keeping the hub's identity
Implemented in mesh-controller #49 and mesh-host #24. One proposal was rejected on the
record's own terms: converging the hub is not made to wait on other machines' migrations.
2026-09-24 00:38:54 +02:00
jschoubben f61f047a5d Merge pull request 'Issue 102 resolved and verified on the machine; issue 097's orphan was on the host network' (#94) from issues/102-resolved-and-097-worse into main 2026-09-23 22:15:49 +00:00
jschoubben 133e10a738 Issue 102 resolved, verified on the machine with both forwarders gone; 097's orphan was on the host network
The addresses follow: the control plane holds the ports the node gave, a recorded build
holds no address at all, and the two forwarders that had been holding the control plane
together are removed. 097's stranded container turned out to be listening on every
interface and connected to the mesh's store — by its own old database, which is the only
reason nothing was at risk.
2026-09-24 00:02:13 +02:00
jschoubben c209a575e1 Merge pull request 'ADR 0106: the bus is NATS; issue 104 resolved' (#92) from decide/0106-the-bus-is-nats into main 2026-09-23 21:40:03 +00:00
jschoubben e022798858 ADR 0106: the bus is NATS — native, built beside the migration, cut over after its core; issue 104 resolved 2026-09-23 23:39:17 +02:00
jschoubben 6f173a7912 Merge pull request 'Issue 108: the registry has no garbage collection, and two doors make it harder to add' (#91) from issues/108-registry-gc into main 2026-09-23 21:32:52 +00:00
jschoubben 73091dcb4c Issue 108: the registry has no garbage collection, and two doors make it harder to add 2026-09-23 23:32:29 +02:00
jschoubben f6ec64ee4e Merge pull request 'Issue 107: a declaration carries no order; rescue on an enrolled node is reconcile, not apply FILE' (#90) from issues/107-declarations-carry-no-order into main 2026-09-23 21:27:24 +00:00
jschoubben 671c2f3881 Issue 107: a declaration carries no order; rescue on an enrolled node is reconcile, not apply FILE
Both from the review of the issue-104 fix: a hand-applied file on an enrolled node is
recorded as carried and would remove the foundation, and nothing on the wire orders one
declaration against another.
2026-09-23 23:27:08 +02:00
jschoubben 2445d80565 Merge pull request 'Research 014: the bus on NATS — decide now, build in the lab, cut over once after the core' (#89) from research/014-nats into main 2026-09-23 21:15:22 +00:00
jschoubben a548b34f5d Research 014: fix the reference to ADR 0039 2026-09-23 23:14:57 +02:00
jschoubben b59907ee08 Research 014: the bus on NATS — decide now, build in the lab, cut over once after the core
Measured: AMQP is spoken in three places of the mesh's own code and in none of the
sdk or the modules; the predecessor's world is AMQP and retiring. NATS answers every
guarantee the bus relies on, durability via JetStream. Recommended: not underneath
the migration, not after it either — in parallel, one rehearsed rollout.
2026-09-23 23:14:39 +02:00
jschoubben 8638ba3a4f Merge pull request 'Issues 102–106 and ADR 0105: what the core migration found, and the hub adopting the predecessor's tunnel' (#88) from core/issues-102-106-and-tunnel-adr into main 2026-09-23 20:54:53 +00:00
jschoubben cb2117f1c4 Issues 102–106 and ADR 0105 from the core migration
Two birth-address outages and a registry that would have been the third; a
container that keeps a stale environment after its file changes; a host command
that applied a converged declaration to an adopted node; the hub and the vault
without seats. And the decision the operator made under it all: the hub adopts
the predecessor's tunnel in place, key and peers and range and port.
2026-09-23 22:50:10 +02:00
jschoubben ee2bdf220c Merge pull request 'Issue 101: taking a service its neighbours reach by container name cuts them off' (#87) from issues/101-a-service-reached-by-name-loses-its-network into main 2026-09-23 18:14:08 +00:00
jschoubben 61e4e971a4 Issue 101: taking a service reached by container name cuts its neighbours off
Found checking the third cutover rather than running it. The first two were safe by
accident — both are reached through a host port, which survives a change of owner.
This is the first constraint found that decides the order of the migration.
2026-09-23 20:13:53 +02:00
jschoubben f4f58e7c30 Merge pull request 'Issue 100: a secret the mesh mints cannot be the one the service it takes over already uses' (#86) from issues/100-a-minted-secret-cannot-be-the-one-the-service-already-uses into main 2026-09-23 00:54:21 +00:00
jschoubben 157c6edd50 Issue 100: a minted secret cannot be the one the service already uses
Found at the second cutover. Carrying a value in works only for a module's own
secrets; a secret answered by the provision is minted, and six catalogue modules
take one that way.
2026-09-23 02:54:09 +02:00
jschoubben e9e5df36bd Merge pull request 'Issue 099: a module's image pin ages into a downgrade, and taking it over is where that is discovered' (#85) from issues/099-a-pin-ages-into-a-downgrade into main 2026-09-23 00:48:02 +00:00
jschoubben 9faa985be3 Issue 099: a module's image pin ages into a downgrade
Three modules in a row on one machine; the first was found by taking it and cost a
three-minute outage. The runbook's answer is a rule a person must remember, which is
the shape this repository says not to settle for.
2026-09-23 02:47:50 +02:00
jschoubben cda7a4e348 Merge pull request 'Issue 094 diagnosed and resolved; 096, 097 and 098 opened from what it uncovered' (#84) from issues/094-diagnosis-and-096 into main 2026-09-23 00:37:27 +00:00
jschoubben 668ce3ad62 Issue 094 resolved: a given port names either end and is answered once
The first pass answered under both ends, which review showed is the same fault seen
from the other side where two mappings share a number. Verified on the machine: the
forge is back on the port its own configuration has always advertised.
2026-09-23 02:37:07 +02:00
jschoubben 0c8615aa8f Issue 098: taking a module replaces a configuration nobody compared
Found reading the second module's cutover rather than running it: the catalogue's
config drops a rule the machine's has, and no step puts the two side by side.
2026-09-23 02:23:58 +02:00
jschoubben 235b9ea0e5 Issues 096 and 097, and 094 diagnosed: a setting stored where it cannot work, and a resource that changed target
094's cause is one blind spot read from two ends, written up in its diagnosis; the fix
answers the first open question and not the other two, which become 096. 097 was found
looking at what the forge's cutover left running.
2026-09-23 02:20:48 +02:00
jschoubben 1b8e5043ee Merge pull request 'Issues 094 and 095, both found in the first module's cutover' (#83) from issues/094-095-from-the-first-cutover into main 2026-09-22 23:57:48 +00:00
jschoubben 515cb8adc1 Issues 094 and 095, both found in the first module's cutover 2026-09-23 01:57:10 +02:00
jschoubben 0d8b683ad7 Merge pull request 'Research 013: the forge and the registries — a seat answers the wrong question' (#82) from research/013-the-forge-and-the-registries into main 2026-09-23 01:03:10 +02:00
jschoubben 43b55d6664 Research 013: the forge and the registries — a seat answers the wrong question; issues 090 and 085 corrected from the code 2026-09-23 00:38:34 +02:00
jschoubben 6c81ea2204 Merge pull request 'ADR 0104: a provision may be answered by an adapter to the predecessor' (#81) from decide/0104-route-adapter into main 2026-09-22 23:57:54 +02:00
jschoubben a23ede495e ADR 0104: a provision may be answered by an adapter to the predecessor; issue 093 located; connectivity says how the proxy hands over 2026-09-22 23:57:38 +02:00
jschoubben a2323ade2e Merge pull request 'Issue 093: the successor proxy cannot serve what the predecessor still serves' (#80) from issue/093-proxy-handover into main 2026-09-22 23:57:04 +02:00
jschoubben d697c6f776 Issue 093: the successor proxy cannot serve what the predecessor still serves, so no web module can migrate one at a time 2026-09-22 23:45:49 +02:00
jschoubben a7b3f7823b Issue 092: it happened twice more — the registry's mesh name, and the mesh's own trust naming the default port 2026-09-22 23:37:05 +02:00
jschoubben cc3af29084 Issue 092: genesis publishes to a registry the container runtime does not yet trust 2026-09-22 22:43:17 +02:00
jschoubben fb9d3035d4 Issue 091: a module definition carries a machine port, measured across the catalogue 2026-09-22 22:26:14 +02:00
jschoubben dd81523eab Merge pull request 'Issue 085 resolved' (#77) from fix/085-resolved into main 2026-09-22 22:00:49 +02:00
jschoubben 5c5821b210 Issue 085 resolved: the packages port is a node setting; two of its open questions stay open 2026-09-22 22:00:38 +02:00
jschoubben c46c508c03 Merge pull request 'Issues 088, 089 and 090, found fixing 085' (#76) from fix/issue-085-followups into main 2026-09-22 22:00:02 +02:00
jschoubben 1728765fe3 Issues 089 and 090: a contributed route does not follow a moved port; the forge module cannot take over the forge genesis raised 2026-09-22 21:54:35 +02:00
jschoubben e609ccdbfb Issue 088: the forge's own address names a port it may not have 2026-09-22 21:41:58 +02:00
jschoubben 60eae92fb1 Merge pull request 'Adoption mode as built: ADRs 0101–0103, issues 084–086' (#75) from feat/adoption-mode into main 2026-09-22 21:02:00 +02:00
jschoubben 7bbbfb158a ADR 0103: a unit is found when an administrator installed it or the machine uses it 2026-09-22 20:02:18 +02:00
jschoubben 87ae893407 Issue 087: the controller cannot tell that a node's host is too old for what it sends 2026-09-22 19:43:01 +02:00
jschoubben c74ea2a4a8 Records say what the build does: 0101 names only measured daemons; 0102 adds to lists and keeps what it writes over; 0103 names every held kind, the found-service rule, conflicting found rules, guards, and what of 0100 it replaces; designs 05, 09 and 17 in step; issue 084's diagnosis in its own file 2026-09-22 19:38:16 +02:00
jschoubben ca1f648973 Issue 086: taking a module narrows a port the predecessor served, without saying so 2026-09-22 19:00:59 +02:00
jschoubben 019184ec0f Issue 085: the packages port given at genesis is not a setting, and a later module can undo it 2026-09-22 18:17:21 +02:00
jschoubben 213ab898d6 ADR 0103: what an adopted node holds and what its guard refuses; the node host and connectivity designs name 0102 and 0103 2026-09-22 17:52:58 +02:00
jschoubben 84761f0600 ADR 0102: the mesh writes into a shared file, never over it; issue 084 located 2026-09-22 17:46:06 +02:00
jschoubben 1901a90d68 ADR 0101 accepted; raising a mesh names it 2026-09-22 17:43:13 +02:00
jschoubben 347bbce633 ADR 0101 proposed: a machine's own resolver does not make it in use, as measured on a fresh machine 2026-09-22 17:38:44 +02:00
jschoubben 6165a7ae02 Issue 084: taking networking on an adopted node restarts every container, and the held runtime file blocks pulling 2026-09-22 17:09:21 +02:00
jschoubben dfadfd23c0 Merge pull request 'ADR 0100 (proposed): a node in use is adopted before it is converged' (#74) from feat/adoption-mode into main 2026-09-22 16:35:32 +02:00
jschoubben 3d4ab23830 ADR 0100: the machine's own traffic is known by its interface, not its source address 2026-09-22 16:35:25 +02:00
jschoubben 37252f9c3e ADR 0100: the guard lets the machine itself through; in use is a non-loopback listener; openings say from where; 09 in step with the flip 2026-09-22 16:34:53 +02:00
jschoubben f3152d827f ADR 0100 after re-review: the bus and registry stay reachable for enrolment; the mesh guards the store in a table that only refuses; a machine in use defined; the flip refuses while a found container is held; held containers and returning to adopted spelled out 2026-09-22 16:32:37 +02:00
jschoubben 02c40bcab4 ADR 0100 after review: found means unrecorded; assigning prepares, taking cuts over; openings through the found firewall on both paths; the mesh guards its own ports; ports kept as node settings; a converged genesis refuses a machine in use; designs 05, 07, 08, 09 and 17 in step 2026-09-22 16:28:31 +02:00
jschoubben 111456abb5 ADR 0100 accepted; the node host, connectivity, the node lifecycle and raising a mesh amended for a node adopted before it is converged 2026-09-22 16:20:27 +02:00
jschoubben 5fc3cbde4c Research 012: migrating a node that is in use, measured on the control-node; ADR 0100 proposed — a node in use is adopted before it is converged 2026-09-22 16:16:28 +02:00
jschoubben 21baf397a8 Merge pull request 'Issue 083 resolved: nothing the control queue carries is lost while the store restarts' (#73) from multiple-fixes into main 2026-09-22 14:43:00 +02:00
jschoubben 4de74880cb Issue 083: the proof, the replay caveat, and what is not closed, as three reviews found them 2026-09-22 14:39:29 +02:00
jschoubben 266ee34b5c Issue 083: the diagnosis describes held messages, the enrolment's order, and what is not closed 2026-09-22 14:24:31 +02:00
jschoubben 2d45aa5f42 Issue 083 resolved: nothing the control queue carries is lost while the store restarts; an enrolment claims its token and spends it last 2026-09-22 14:11:44 +02:00
jschoubben 4e74cf29e4 Merge pull request 'Issues 081 and 082 resolved; 083 opened' (#72) from multiple-fixes into main 2026-09-22 13:53:16 +02:00
jschoubben 0d40918e92 Issue 081: proven by the two-node bed, and what it found about baserow's data directory 2026-09-22 13:53:00 +02:00
jschoubben f6ded3102d Issue 083 opened (other control messages lost while the store restarts); 082's diagnosis carries its review 2026-09-22 13:34:05 +02:00
jschoubben 9a75f2b6a9 Issue 082: a report that arrives while the store restarts was lost; 081's diagnosis corrected on review 2026-09-22 13:25:33 +02:00
jschoubben 5d1a0372cb Issue 081 resolved: neither cache consumer can keep its keys under its login, so neither takes the shared cache 2026-09-22 12:27:12 +02:00
jschoubben f1e3925009 Merge pull request 'Issues 079 and 080, found by running the large mesh bed; 074's addendum' (#71) from multiple-fixes into main 2026-09-22 02:19:17 +02:00
jschoubben 35e44c3e5e Issue 081 opened (a cache consumer does not use its login); 079 and 080 diagnoses carry the review's consequences 2026-09-22 02:04:29 +02:00
jschoubben f760bf632c Issue 080: a cache grant let the consumer flush the server; 079: the names follow the resolver's rule for the private network 2026-09-22 01:39:29 +02:00
jschoubben e31e077fc8 Issue 079: the suffix is handed down, not written twice 2026-09-22 01:27:53 +02:00
jschoubben 17cc36069f Issue 079: every machine named twice over, found by the large mesh bed; what running that bed cost, on 074 2026-09-22 01:13:29 +02:00
jschoubben 446553dd1f Merge pull request 'ADR 0099; issues 077, 078 and 074 resolved; designs 08 and 20 amended' (#70) from multiple-fixes into main 2026-09-21 23:58:50 +02:00
jschoubben 3ea5e47c21 Review: 077 says what closed it and what did not; 078 names module issue; 074's retired fixture; ADR 0099's scope 2026-09-21 23:58:15 +02:00
jschoubben ead8913a74 Issue 078: module issue's orphan account, refused before it is made 2026-09-21 23:46:51 +02:00
jschoubben faa7196ad6 Issue 074: opened date restored 2026-09-21 23:44:22 +02:00
jschoubben 8d159cee84 Issue 074 resolved: the declared list is empty of WEARING; what the last three cost 2026-09-21 23:43:31 +02:00
jschoubben 0e0f0298c6 ADR 0099: a step that runs once names what it reads; issues 077 and 078 resolved; designs 08 and 20 amended 2026-09-21 23:33:47 +02:00
jschoubben c2a81cbb20 Merge pull request 'ADR 0098; issue 076 opened and resolved; ADR 0097's base refusal live; ADR 0096 proven against the public hub; 074 down to one bed' (#69) from multiple-fixes into main 2026-09-21 22:58:26 +02:00
jschoubben 6bc9df4b49 Review corrections: 076 and ADR 0098 say what the authority could and could not do; issues 077 (a fetched fact is fetched once) and 078 (secret accept takes any name) opened 2026-09-21 22:55:11 +02:00
jschoubben 6d3cb60949 Issue 076: the route-forwarding bed proves ADR 0098; what the run taught about the overlay 2026-09-21 22:44:24 +02:00
jschoubben 75af72ca27 ADR 0096: the copy is proven against the public hub by the genesis bed 2026-09-21 22:32:03 +02:00
jschoubben 252c6042e8 ADR 0098: a fact a provider makes at first start is fetched from it; issue 076 resolved; design 08 amended; 074 down to one bed 2026-09-21 22:27:32 +02:00
jschoubben bc373797c7 Issue 076 opened: a served fact made at first start cannot be served; ADR 0097's refusal of an undeclared base is live 2026-09-21 22:16:15 +02:00
jschoubben 559683318b Merge pull request 'Multiple fixes: issues 064, 066 and 020 resolved; 074 narrowed to two beds' (#68) from multiple-fixes into main 2026-09-21 22:13:20 +02:00
jschoubben ac11bea77f Issue 020 resolved: the symptom was the bed's, proven against Pebble and step-ca alike 2026-09-21 22:12:51 +02:00
jschoubben c1a10dc3f8 Issue 066 resolved: a file and its reader are guarded by a gate, proven by the coupled-pair spike; design 20 says so 2026-09-21 22:04:14 +02:00
jschoubben e993233004 Issue 074: six of the ten beds retired rather than converted 2026-09-21 21:53:11 +02:00
jschoubben 2d77911511 Issue 064 resolved: the package half placed by the genesis run, the image half by ADR 0097 2026-09-21 21:52:32 +02:00