jochen
baf82b1cdb
Plan and designs after ADR 0193, 0195 and 0198: bundles are launched and the runtime is their bus; the manager's daemon is a long-running bundle; the console's five tools
...
The dated note on ADR 0183 now rests on ADR 0193 and 0198 rather than on a bundle having no way to
call: the manager starts every exchange by the operator's direction, through mesh/ask. To-be 40's
WP4 no longer waits on a record — ADR 0198 is it — and the live proofs count the console's five
tools (ADR 0195).
2026-10-03 23:41:38 +02:00
jochen
88fd7d9739
Design 36 §4: the console is registered in the exclusive managed tool-server file, because the managed-settings key refuses a non-https URL
2026-10-03 23:41:10 +02:00
jochen
ce0dc7b55b
To-be 40 revised for the tools refactor; the manager starts every exchange (ADR 0183 dated note, designs 36 and 39)
...
Design 38's WP1-WP4b ran: the node's tool runtime is live on all four machines as the operator
account, tools are bundles given only their declared words, and a bundle has no bus credential.
So the wait on design 38 WP3 is over, the agent module calls nothing and the manager starts every
exchange (key, hand-over, waiting login, reconcile), and the manager's daemon now waits on WP4c's
record instead. Accounts are stated on all four, sudo -n works for each, the agent is installed on
all four; the plan's WP0 shrinks and WP2 gets a configuration-only live proof before any licence.
2026-10-03 23:41:10 +02:00
jochen
7d18b0c1d0
To-be 40: building the operator's agent and its licence manager as work packages
...
Designs 36 and 39 say what is built; this says in which order and what proves each step, in the
shape to-be 38 gave the operator's machine. Seven packages: the operator states the facts (accounts,
roles, licences); the console provides its endpoint; the licence manager and the agent module are
built and unit-tested in parallel; the manager goes live on the control node; the agent on one
workstation, with the switch and the predecessor's files removed as the proof of the whole; then the
rest of the nodes and the retirement of the two catalogue modules built on the old placement. The
live proofs wait for to-be 38's WP3, because both modules' tools run in the node's tool runtime
(ADR 0175) and a per-module tool container would rebuild what that record retires.
2026-10-03 23:41:10 +02:00
mesh-admin
895c2afad1
Merge pull request 'Issue 218: a mesh seat answered by a non-holder (located, fixed in mesh-controller#248)' ( #339 ) from issues/218-a-mesh-seat-answered-by-a-non-holder into main
2026-10-03 21:32:24 +00:00
jochen
4b8c5e3b11
Issue 218 located: the controller issued a mesh seat to every claimant; fixed in mesh-controller#248
2026-10-03 23:31:13 +02:00
mesh-admin
d362155401
Merge pull request 'Issue 218: a mesh seat is answered by a module on a machine that does not hold it' ( #338 ) from issues/218-a-mesh-seat-answered-by-a-non-holder into main
2026-10-03 21:25:27 +00:00
jochen
557760e537
Issue 218: a mesh seat is answered by a module on a machine that does not hold it
2026-10-03 23:25:17 +02:00
mesh-admin
6b1ebd1d4a
Merge pull request 'Issue 217: a refused announcement took down every container's runtime, and the console with it' ( #336 ) from issues/217-a-refused-announcement into main
2026-10-03 21:20:06 +00:00
mesh-admin
fa73a17ceb
Merge pull request 'Issues 211, 214, 215, 216 diagnosed' ( #335 ) from issues/211-214-216-diagnosed into main
2026-10-03 21:19:03 +00:00
jochen
08cea893bd
Issue 217: a refused announcement took down every container's runtime, and the console with it
2026-10-03 22:47:28 +02:00
jochen
04625d3e35
Issues 211, 214, 215, 216 diagnosed: root causes and the branches that fix them
2026-10-03 22:28:40 +02:00
mesh-admin
d7bb24b181
Merge pull request 'ADR 0198: a module's long-running code is launched by the node's runtime and reaches the bus through it' ( #334 ) from decision/0198-a-modules-long-running-code-is-launched-by-the-runtime into main
2026-10-03 20:21:04 +00:00
jochen
23d6e30b8a
ADR 0198: a module's long-running code is launched by the node's runtime and reaches the bus through it; research 022; design 38 WP4c plan
2026-10-03 22:20:53 +02:00
mesh-admin
2043e90f35
Merge pull request 'Issues 214–216: a plan losing its own controller, a module pinned silently, a bundle never delivered' ( #333 ) from issues/214-216-found-building-0192-0193 into main
2026-10-03 20:15:30 +00:00
jochen
c9418af42e
Issues 214–216: a plan losing its own controller, a module pinned silently, a bundle never delivered
2026-10-03 22:15:19 +02:00
mesh-admin
9c3e77999e
Merge pull request 'Design 38 WP4d: every served bundle launched and node-tools in Go, proven live on all four machines' ( #332 ) from design/38-wp4d-proven into main
2026-10-03 20:07:30 +00:00
jochen
6943843fff
Design 38 WP4d: every served bundle launched and node-tools in Go, proven live on all four machines
2026-10-03 22:07:20 +02:00
mesh-admin
34325d3566
Merge pull request 'ADR 0197: every tool announces itself on the bus, in the NATS services protocol' ( #331 ) from decision/0196-every-tool-announces-itself into main
2026-10-03 20:04:12 +00:00
jochen
fa9e94d863
Renumber to ADR 0197: 0196 landed first on main
2026-10-03 22:03:58 +02:00
jochen
1b34821aa0
ADR 0196: every tool announces itself on the bus in the NATS services protocol
2026-10-03 22:03:34 +02:00
jschoubben
50ddaf8408
Merge pull request 'ADR 0196: a node asks the mesh's resolver first, and a public one only when it is silent' ( #330 ) from decision/0196-nodes-ask-the-mesh-resolver-with-a-public-fallback into main
2026-10-03 20:01:05 +00:00
jschoubben
f5d518d256
ADR 0196: a node asks the mesh's resolver first, and a public one only when it is silent
...
ADR 0194 rejected sending every query to the mesh's resolver because a node with its tunnel down
would resolve nothing; a public resolver listed second answers exactly then. That drops the
systemd-resolved stub and the runtime's dns: containers copy the machine's resolvers. Narrows 0194;
amends connectivity §2.
2026-10-03 21:56:33 +02:00
jschoubben
577ddf0089
Merge pull request 'ADR 0194: the mesh has one resolver, and every node asks it for the mesh's names' ( #326 ) from decision/0194-the-mesh-has-one-resolver into main
2026-10-03 19:51:04 +00:00
jschoubben
13e28e6873
ADR 0194: the no-copies check allows each node's loopback stub
2026-10-03 21:51:03 +02:00
jschoubben
6b6ff76a19
ADR 0194: why every node needs a stub, and the systemd-resolved module that provides it
2026-10-03 21:50:33 +02:00
mesh-admin
8d5e6ef76f
Merge pull request 'ADR 0195: the mesh's tools are found by address, not announced whole; research 021; to-be 34 §3a' ( #329 ) from decision/0195-the-mesh-tools-are-found-by-address into main
2026-10-03 19:49:37 +00:00
jochen
77813f4613
ADR 0195: the mesh's tools are found by address, not announced whole; research 021; to-be 34 §3a
2026-10-03 21:49:26 +02:00
mesh-admin
4ee8e3905d
Merge pull request 'Issue 213: the controller is a Go program and still runs in a container' ( #328 ) from issues/213-the-controller-runs-in-a-container into main
2026-10-03 19:42:31 +00:00
jochen
216faec69e
Issue 213: what the container gives it, measured
2026-10-03 21:42:22 +02:00
jochen
e36b1a9e9c
Issue 213: the controller is a Go program and still runs in a container
2026-10-03 21:42:11 +02:00
mesh-admin
5886969c75
Merge pull request 'Issue 212: a toolchain rebuild keeps the SDK it cached' ( #327 ) from issues/212-a-toolchain-keeps-a-cached-sdk into main
2026-10-03 19:24:49 +00:00
jochen
5fa43ff755
Issue 212: a toolchain rebuild keeps the SDK it cached
2026-10-03 21:24:39 +02:00
jschoubben
1de4a5f25e
ADR 0194: the mesh has one resolver, and every node asks it for the mesh's names
...
Every resolution fault found on 2026-10-03 was a per-node copy disagreeing with the truth: a hosts
file read once, an operator's old line beside the mesh's, a node's resolver lent to a LAN. Every
tunnel already converges on one node. Retires node-dns-resolver for a mesh-scoped mesh-resolver;
nodes route only the mesh's suffix to it. Narrows 0121; amends connectivity §2 and the seats.
2026-10-03 21:21:49 +02:00
jschoubben
8a1fa37dce
Merge pull request 'ADR 0191: domains are a node's — the resolver holds each node's internal domain, nothing else' ( #323 ) from decision/0191-names-by-origin into main
2026-10-03 19:12:26 +00:00
mesh-admin
44eb13acd0
Merge pull request 'ADR 0193: every bundle the runtime serves is launched, and the runtime knows no language; design 38 WP4d' ( #325 ) from decision/0193-every-served-bundle-is-launched into main
2026-10-03 19:05:12 +00:00
jochen
6d53f9168a
ADR 0193: every bundle the runtime serves is launched, and the runtime knows no language; design 38 WP4d
2026-10-03 21:05:03 +02:00
mesh-admin
6a1fc71a4c
Merge pull request 'Design 38 WP4b: four tools-only modules proven live from the runtime; two delivery traps' ( #324 ) from design/38-wp4b-seven-proven into main
2026-10-03 14:13:40 +00:00
jochen
fb76fb7256
Design 38 WP4b: four tools-only modules proven live from the runtime; two delivery traps
2026-10-03 16:13:32 +02:00
jschoubben
2344bfb69b
ADR 0191: domains are a node's — one internal, one or more public; the roster is the machines
2026-10-03 16:10:38 +02:00
jschoubben
ca8a865e73
ADR 0191: the mesh's names are known by where they were composed, not by their suffix
...
A progressive insight: the rule and its check were stated as a suffix test; the mesh composes both
names of a route and publishes its internal one. The decision is unchanged.
2026-10-03 15:39:07 +02:00
mesh-admin
27c6881287
Merge pull request 'Issue 211: a bundle is built before the toolchain it is compiled in; ADR 0192 progressive insight; design 38 WP4b built, WP4c opened' ( #322 ) from issues/211-and-0192-insight into main
2026-10-03 13:36:43 +00:00
jochen
f8458d6f2c
Issue 211: a bundle is built before the toolchain it is compiled in; ADR 0192 progressive insight; design 38 WP4b built, WP4c opened
2026-10-03 15:36:26 +02:00
mesh-admin
c5778f4366
Merge pull request 'ADR 0192: a tools bundle declares what it is given, and the runtime hands it to that bundle alone; research 020 graduated; design 38 WP4b' ( #321 ) from decision/0192-what-a-bundled-tool-is-given into main
2026-10-03 13:18:40 +00:00
jochen
4c1ad0ed45
ADR 0192: a tools bundle declares what it is given, and the runtime hands it to that bundle alone; research 020 graduated; design 38 WP4b
2026-10-03 15:18:22 +02:00
jschoubben
9873e951a9
Merge pull request 'ADR 0191: the mesh resolves only its own names; a public name resolves publicly' ( #320 ) from decision/0191-the-mesh-resolves-only-its-own-domain into main
2026-10-03 13:16:13 +00:00
jschoubben
e5e6e56ecf
ADR 0191: the mesh's resolver holds only the mesh's own names; a public name resolves publicly
...
Publishing every routed public name at a private address turned ace's LAN-facing resolver into an
outage for non-members: a phone got the control-node's tunnel address for the mail server. Routes
have internal names since 0151 and the proxy certifies public names publicly, so nothing needs the
private answer. Narrows 0066 and 0151; amends connectivity §2 and §5.
2026-10-03 15:11:45 +02:00
mesh-admin
65c30c576a
Merge pull request 'Research 020: what a bundled tool is given; design 38 WP4: fail2ban followed, proven live' ( #319 ) from research/020-what-a-bundled-tool-is-given into main
2026-10-03 13:11:24 +00:00
jochen
ee17cddb74
Research 020: what a bundled tool is given; design 38 WP4: fail2ban followed, proven live
2026-10-03 15:11:08 +02:00
mesh-admin
22e96e5bc7
Merge pull request 'Issue 210 resolved by mesh-host #80 : an unchanged process keeps its record' ( #318 ) from issues/210-resolved into main
2026-10-03 11:56:30 +00:00