Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c4151e6bc4 |
@@ -131,6 +131,32 @@ the plan says it too.
|
|||||||
| Genesis raises the forge as its module declares it | a genesis test that raises, assigns, and finds the module holding rather than raising a second |
|
| Genesis raises the forge as its module declares it | a genesis test that raises, assigns, and finds the module holding rather than raising a second |
|
||||||
| Live | the next cutover on an adopted machine: `take` shows the comparison, refuses the downgrade if there is one, and the service keeps its configuration and its secret |
|
| Live | the next cutover on an adopted machine: `take` shows the comparison, refuses the downgrade if there is one, and the service keeps its configuration and its secret |
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
> **Progressive insight — 2026-10-02.** The decision stands; these are the facts of its building.
|
||||||
|
|
||||||
|
Built across mesh-host 63 and 64 and mesh-controller 201, 202 and the pull request that followed
|
||||||
|
them. Rule 1: `take` previews every held thing's comparison and ends with a digest; `take --yes
|
||||||
|
<digest>` acts on exactly that preview, and a changed preview or an account older than the flip
|
||||||
|
allows is refused, as the flip's are. A published port's reach is said as the machine reported it,
|
||||||
|
behind the found firewall whose rules are not read. Rule 2: an older image, a differing file and a
|
||||||
|
minted, unaccepted secret for found data refuse, overridden by `--downgrade`, `--replace <path>` and
|
||||||
|
`--mint <name>`; the secrets a module holds on a machine are read with where each came from. Rule 3:
|
||||||
|
`secret accept --provider` reaches a required secret. Rule 4: the per-machine setting is `networks`,
|
||||||
|
a container id to the found networks it keeps; judged for an adopted machine only, joined by the host
|
||||||
|
after the container runs, part of the container's spec, named in the preview. Rule 5: the host's
|
||||||
|
facts, former targets and strays. Rule 6: one judgement, run where a setting is stored and where a
|
||||||
|
machine is composed; a module whose stored setting its definition can no longer compose is left out
|
||||||
|
of the declaration, the envelope says so, the host keeps that module's things, and `plan` and `push`
|
||||||
|
say it by name. A key that reaches nothing is refused where stored and said by `plan`, and never
|
||||||
|
costs a module. Rule 7: genesis raises the forge under the module's container name, with its image
|
||||||
|
digest and its data directory; the network is the one difference left, said by the take, because the
|
||||||
|
bootstrap forge reaches the store on the machine's loopback.
|
||||||
|
|
||||||
|
**Not yet proven live.** Every machine of this mesh is converged, so the table's last row — a take
|
||||||
|
on an adopted machine — waits for the next adoption. What is live is what the rows above it check.
|
||||||
|
Issues 086, 098, 099, 100 and 101 stay located until that row is read.
|
||||||
|
|
||||||
## References
|
## References
|
||||||
|
|
||||||
- [ADR 0100](0100-a-node-in-use-is-adopted-before-it-is-converged.md), [ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md), [ADR 0103](0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md), [ADR 0104](0104-a-provision-may-be-answered-by-an-adapter-to-the-predecessor.md), [ADR 0162](0162-a-merge-produces-a-tiered-plan-the-mesh-keeps.md)
|
- [ADR 0100](0100-a-node-in-use-is-adopted-before-it-is-converged.md), [ADR 0102](0102-the-mesh-writes-into-a-shared-file-never-over-it.md), [ADR 0103](0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md), [ADR 0104](0104-a-provision-may-be-answered-by-an-adapter-to-the-predecessor.md), [ADR 0162](0162-a-merge-produces-a-tiered-plan-the-mesh-keeps.md)
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
layer: to-be
|
layer: to-be
|
||||||
status: in-progress
|
status: in-progress
|
||||||
code: [mesh-host]
|
code: [mesh-host]
|
||||||
updated: 2026-10-01
|
updated: 2026-10-02
|
||||||
decisions:
|
decisions:
|
||||||
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
|
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
|
||||||
- 02-DECISIONS/0141-the-host-delivers-its-own-successor.md
|
- 02-DECISIONS/0141-the-host-delivers-its-own-successor.md
|
||||||
@@ -163,6 +163,19 @@ a resource's former targets, removes a container or file it wrote under a name t
|
|||||||
longer names, never removes what was found, and reports what runs on the machine that it neither
|
longer names, never removes what was found, and reports what runs on the machine that it neither
|
||||||
wrote nor holds. *How it is checked:* ADR 0163's table.
|
wrote nor holds. *How it is checked:* ADR 0163's table.
|
||||||
|
|
||||||
|
**What the host joins, keeps and raises for a take** — revision, 2026-10-02
|
||||||
|
([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 4, 6 and 7). A
|
||||||
|
container may name networks it also joins once it runs — the found network a per-machine setting keeps
|
||||||
|
for a taken container while a neighbour still resolves it there; joined after the run, part of the
|
||||||
|
container's spec, refused when it cannot be joined. A declaration may name the modules the mesh left
|
||||||
|
out of it because a stored setting cannot compose with the module's definition: the host keeps what it
|
||||||
|
wrote and holds for a left-out module and says so, where absence used to read as removal. And genesis
|
||||||
|
raises the bootstrap forge under the forge module's container name, with the module's image digest and
|
||||||
|
its data directory, so the module holds it by the found rule; the network is the one difference a take
|
||||||
|
has left to say. *How it is checked:* a host test joins a kept network and refuses one it cannot; a
|
||||||
|
host test keeps a left-out module's record and hold and removes an absent module's; a bootstrap test
|
||||||
|
holds the installer's constants to the module's manifest where the catalogue is checked out beside it.
|
||||||
|
|
||||||
**Found reaches every kind that can touch what the machine has**
|
**Found reaches every kind that can touch what the machine has**
|
||||||
([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)). For a module not yet taken, a directory present with no record
|
([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)). For a module not yet taken, a directory present with no record
|
||||||
keeps its mode and owner, a unit present with no record keeps its state and boot setting, a
|
keeps its mode and owner, a unit present with no record keeps its state and boot setting, a
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ code:
|
|||||||
- mesh-host packaging/nox-mesh-host-network.sh
|
- mesh-host packaging/nox-mesh-host-network.sh
|
||||||
- mesh-controller internal/token
|
- mesh-controller internal/token
|
||||||
- mesh-controller internal/inventory/nodes.go
|
- mesh-controller internal/inventory/nodes.go
|
||||||
updated: 2026-10-01
|
updated: 2026-10-02
|
||||||
decisions:
|
decisions:
|
||||||
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
|
- 02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md
|
||||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||||
@@ -323,6 +323,21 @@ network are said. `take --yes <digest>` cuts over what was previewed, as the fli
|
|||||||
container may keep a found network by a per-machine setting while its neighbours are not yet taken.
|
container may keep a found network by a per-machine setting while its neighbours are not yet taken.
|
||||||
*How it is checked:* ADR 0163's table.
|
*How it is checked:* ADR 0163's table.
|
||||||
|
|
||||||
|
**A setting is judged where it is stored, and the take's words** — revision, 2026-10-02
|
||||||
|
([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1, 2, 4 and 6).
|
||||||
|
The preview ends with a digest of what it said; `take --yes <digest>` acts on that preview and nothing
|
||||||
|
else, and a preview that has changed since, or an account of the machine older than the flip allows, is
|
||||||
|
refused as the flip's is. A module the machine holds nothing for has nothing to compare, and `--yes`
|
||||||
|
suffices. The overrides are `--downgrade`, `--replace <path>` and `--mint <name>`; the per-machine
|
||||||
|
setting that keeps a found network is `networks`, a container id to the networks it keeps, accepted
|
||||||
|
for an adopted machine only. Storing a setting composes it against the module's current definition and
|
||||||
|
refuses, naming node, module, layer and key, what cannot compose or reaches nothing. A definition that
|
||||||
|
later moves under a stored setting costs that module its place in the machine's declaration, said by
|
||||||
|
name in `plan`, `push` and the declaration itself, and the machine is told everything else; a stray
|
||||||
|
setting no longer refuses the machine where it is read. *How it is checked:* controller tests over the
|
||||||
|
one judgement — refused where stored, a module left out where composed, the envelope naming it — and
|
||||||
|
over a take's digest, staleness and secrets.
|
||||||
|
|
||||||
A candidate machine is not empty. It has a package manager, probably a container runtime,
|
A candidate machine is not empty. It has a package manager, probably a container runtime,
|
||||||
configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md)
|
configuration somebody chose. [ADR 0005](../../02-DECISIONS/0005-the-node-host.md)
|
||||||
says the host never touches what it did not create — adoption is the deliberate act of taking
|
says the host never touches what it did not create — adoption is the deliberate act of taking
|
||||||
|
|||||||
@@ -40,3 +40,9 @@ it changes before it changes it, and for taking a module this one does not.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the preview names a narrowing. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the preview names a narrowing. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
mesh-controller 201 and the pull request after it: the preview names it, and `take --yes <digest>`
|
||||||
|
acts on the preview that was read. Stays located until a take is read on an adopted machine — every
|
||||||
|
machine of this mesh is converged today, so the record's live row has not been run.
|
||||||
|
|||||||
+10
@@ -53,3 +53,13 @@ network, or it is not a takeover.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 7: genesis raises as the module declares. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 7: genesis raises as the module declares. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built in part, 2026-10-02
|
||||||
|
|
||||||
|
mesh-host 64: genesis raises the forge under the module's container name (`gitea`), pinned to the
|
||||||
|
module's image digest, with the module's data directory mounted at `/data` — so the module finds it,
|
||||||
|
holds it, and a take compares equal images and the same data. A test holds the installer's constants
|
||||||
|
to the module's manifest where the catalogue is checked out beside it. The network is the difference
|
||||||
|
left: the bootstrap forge runs on the machine's network to reach the store on its loopback, the module
|
||||||
|
runs bridged and publishes its ports, and the take says so. Closing waits for group 9's genesis test —
|
||||||
|
a mesh raised, the module assigned, and the module found holding rather than raising a second forge.
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
status: located
|
status: resolved
|
||||||
opened: 2026-09-23
|
opened: 2026-09-23
|
||||||
located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)]
|
located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)]
|
||||||
fixed-by:
|
fixed-by: mesh-controller (the pull request after 201: JudgeSettings, LeftOut), mesh-host 64 (left_out kept)
|
||||||
amended-design:
|
amended-design:
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -63,3 +63,12 @@ knowing the code.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 6: judged where stored; an impossible statement costs a module. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 6: judged where stored; an impossible statement costs a module. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Resolved, 2026-10-02
|
||||||
|
|
||||||
|
One judgement, in the catalogue, run where a setting is stored and where a machine is composed. Stored,
|
||||||
|
a setting that cannot compose with the module's current definition is refused naming the node, the
|
||||||
|
module, the layer and the key; a key that reaches nothing is refused there too. Composed, a definition
|
||||||
|
that moved under a stored setting leaves that module out of the machine's declaration — the envelope
|
||||||
|
names it, the host keeps what it holds and wrote for it, `plan` and `push` say it — and the machine is
|
||||||
|
told everything else. A stray setting no longer refuses the whole machine where it is read.
|
||||||
|
|||||||
+10
-2
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
status: located
|
status: resolved
|
||||||
opened: 2026-09-23
|
opened: 2026-09-23
|
||||||
located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)]
|
located-in: [mesh-controller cmd/mesh-controller/adoption.go (take previews nothing), mesh-host internal/apply (the comparison and the record)]
|
||||||
fixed-by:
|
fixed-by: mesh-host 63 (former targets removed, strays reported), mesh-controller 201/202 (strays shown)
|
||||||
amended-design:
|
amended-design:
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -80,3 +80,11 @@ found, and so would be kept for ever on purpose.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 5: former targets are removed and strays reported. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rule 5: former targets are removed and strays reported. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Resolved, 2026-10-02
|
||||||
|
|
||||||
|
mesh-host 63: the host's record keeps a resource's former targets, removes a container or file it
|
||||||
|
wrote under a name the declaration no longer names, never what was found, and reports strays — what
|
||||||
|
runs on the machine that the mesh neither wrote nor holds. mesh-controller 201 and 202 show strays
|
||||||
|
on `node show` for an adopted and a converged machine alike; the live mesh reported four on the
|
||||||
|
control node the evening it rolled.
|
||||||
|
|||||||
@@ -68,3 +68,9 @@ written.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the difference is shown and a differing file refuses. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the difference is shown and a differing file refuses. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
mesh-host 63 reports the difference between the kept original and the declared content; mesh-controller
|
||||||
|
201 shows it in the preview and refuses a differing file unless `--replace <path>` names it, or the
|
||||||
|
module declares the file partially. Stays located until a take is read on an adopted machine.
|
||||||
|
|||||||
@@ -65,3 +65,9 @@ expected rate.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the images are compared by age and a downgrade refuses. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 2: the images are compared by age and a downgrade refuses. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
mesh-host 63 reports the found image and both images' creation dates; mesh-controller 201 says
|
||||||
|
DOWNGRADE and refuses unless `--downgrade` is said. Stays located until a take is read on an adopted
|
||||||
|
machine.
|
||||||
|
|||||||
@@ -70,3 +70,11 @@ the module can only be installed fresh.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 2 and 3: a minted secret for found data refuses; secret accept reaches required secrets. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 2 and 3: a minted secret for found data refuses; secret accept reaches required secrets. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
`secret accept <node> <module> <name> --provider <node>` reaches a required secret (mesh-controller 201).
|
||||||
|
The pull request after it reads every secret a module holds on a machine with its origin, and a take
|
||||||
|
of a module whose data was found refuses a minted, unaccepted one — naming the accept that carries
|
||||||
|
the existing value in, or `--mint <name>` to let the service take the new one. Stays located until
|
||||||
|
a take is read on an adopted machine.
|
||||||
|
|||||||
+7
@@ -66,3 +66,10 @@ exercise.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 4: the neighbours are named; a found network may be kept by a setting. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 1 and 4: the neighbours are named; a found network may be kept by a setting. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Built, 2026-10-02
|
||||||
|
|
||||||
|
The preview names every neighbour on a found network (mesh-controller 201). The pull request after it
|
||||||
|
adds the per-machine setting `networks` — a container id to the found networks it keeps — judged for an
|
||||||
|
adopted machine only, and mesh-host 64 has the taken container join each once it runs. Stays located
|
||||||
|
until a take is read on an adopted machine.
|
||||||
|
|||||||
@@ -1,7 +1,9 @@
|
|||||||
---
|
---
|
||||||
status: located
|
status: resolved
|
||||||
opened: 2026-09-26
|
opened: 2026-09-26
|
||||||
located-in: [mesh-host internal/apply]
|
located-in: [mesh-host internal/apply]
|
||||||
|
fixed-by: mesh-host 63 (every written field compared), mesh-controller 201 (build says the policy)
|
||||||
|
amended-design:
|
||||||
---
|
---
|
||||||
|
|
||||||
# 126 — a volume path is not in the spec comparison, and a roll-out raced a data move
|
# 126 — a volume path is not in the spec comparison, and a roll-out raced a data move
|
||||||
@@ -50,3 +52,9 @@ the install-page junk was discarded twice.
|
|||||||
|
|
||||||
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 5 and 7: every field compared; build says the policy. Building follows,
|
[ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md), rules 5 and 7: every field compared; build says the policy. Building follows,
|
||||||
host first, then the controller's `take`.
|
host first, then the controller's `take`.
|
||||||
|
|
||||||
|
## Resolved, 2026-10-02
|
||||||
|
|
||||||
|
mesh-host 63: every field the host writes is compared before a container is called current, volumes
|
||||||
|
and paths included. mesh-controller 201: `build` and the take-in say when a module's policy rolls a
|
||||||
|
result out at once; under ADR 0162 the plan says it too.
|
||||||
|
|||||||
Reference in New Issue
Block a user