ADR 0120: a roster fact carries its format as a template; rewrite to-be 29 #144

Merged
jschoubben merged 2 commits from design/roster-fact-is-a-template into main 2026-09-26 23:51:21 +00:00
Owner

ADR 0120 inverts the facts mechanism from a closed list of controller-formatted names to a path + a Go template over the roster: the mesh owns the data, the module owns the format, and the control plane holds no format at all. /etc/hosts becomes a template on the mesh's own network module; dnsmasq's zones move into dnsmasq.

to-be 29 (operator accounts + what lives under a home) is rewritten to ride it:

  • the ssh files become roster templates (known_hosts, config, authorized_keys) — zero controller ssh syntax;
  • the whole ~/.ssh is owned, with a found/owned boundary that cannot lock the operator out;
  • keys are mesh-owned through an SSH CA (existing keys adopted not regenerated; the operator's personal key signed, never minted);
  • the ssh-agent is a user-scoped service running as the account.

Pairs with mesh-controller and mesh-catalog PRs of the same name (the implementation).

ADR 0120 inverts the `facts` mechanism from a closed list of controller-formatted names to a path + a Go template over the roster: the mesh owns the data, the module owns the format, and the control plane holds no format at all. `/etc/hosts` becomes a template on the mesh's own network module; dnsmasq's zones move into dnsmasq. to-be 29 (operator accounts + what lives under a home) is rewritten to ride it: - the ssh files become roster templates (known_hosts, config, authorized_keys) — zero controller ssh syntax; - the whole `~/.ssh` is owned, with a found/owned boundary that cannot lock the operator out; - keys are mesh-owned through an SSH CA (existing keys adopted not regenerated; the operator's personal key signed, never minted); - the ssh-agent is a user-scoped service running as the account. Pairs with mesh-controller and mesh-catalog PRs of the same name (the implementation).
jschoubben added 1 commit 2026-09-26 23:34:23 +00:00
The facts mechanism formatted the roster in Go in the control plane — one
formatter per fact, in the consumer's own configuration language. ADR 0120
makes a fact a path and a template: the mesh owns the data, the module owns
the format, and the control plane holds no format at all.

to-be 29 (operator accounts + what lives under a home) is rewritten to ride
it: the ssh files become roster templates, the whole ~/.ssh is owned with a
found/owned boundary that cannot lock the operator out, keys are mesh-owned
through an SSH CA (existing keys adopted not regenerated, the operator's
personal key signed not minted), and the ssh-agent is a user-scoped service.
jschoubben added 1 commit 2026-09-26 23:42:03 +00:00
A roster fact may be shared — written into a marked region of the machine's
file (into: block, hq 128) rather than as the whole file. The template
renders the content; shared decides how the host lays it down. Composes with
hq 128: the region mechanism is the host's, the format is the module's.
jschoubben merged commit 92a5e8fc05 into main 2026-09-26 23:51:21 +00:00
jschoubben deleted branch design/roster-fact-is-a-template 2026-09-26 23:51:21 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#144