ADRs 0164–0166 and issue 190: the container runtime gets a module, a seat and declared settings #271
Open
mesh-admin
wants to merge 5 commits from
decision/docker-module into main
pull from: decision/docker-module
merge into: :main
:main
:feat/a-provider-declares-what-it-derives
:feat/claude-code-work-packages
:feat/the-operators-machine
:feat/the-found-front-end-is-uninstalled
:decision/0168-built
:decision/0170-renumbered-and-built
:issues/199-200-console-seat-verbs-and-inbox
:feat/the-firewall-seat-serves-its-verbs
:decision/docker-module
:issues/143-144-resolved
:feat/one-thing-filters-a-converged-machine
:issues/group-6-closed
:issue/194-resolved
:issue/194-the-hosts-own-former-archive-stops-every-apply
:issues/192-193-console-registration-and-store-query
:feat/a-take-is-a-comparison-the-rest
:feat/the-mesh-answers-for-itself
:feat/the-console-shipped
:issue/172-the-ssh-client-block-matches-one-spelling-of-a-machine
:issue/171-a-modules-own-resolver-knows-no-mesh-name
:issue/110-resolved
:issue/149-adopted-data-cannot-be-placed-where-it-is
:decisions/settle-the-proposed
:decision/0146-connectivity-by-name
:decision/0145-a-module-checks-what-the-mesh-claims
:decision/0144-local-is-not-a-boundary
:decision/0143-a-consumer-verifies-its-grant
:issue/145-healthy-while-broken
:decision/0138-insight-reach-and-the-proxy
:issue/143-corrected-diagnosis
:issue/143-and-144-the-found-firewall
:decision/0142-mesh-delivers-its-own-components
:decision/0141-progressive-insight-on-delivery
:decision/0141-the-host-delivers-its-own-successor
:issue/142-the-host-is-not-delivered
:decision/0140-filter-constrains-what-arrives-from-outside
:decision/0138-endpoint-reach-and-0139-declared-networks
:issue/140-endpoint-reach-and-141-forward-chain
:issue/138-the-uplink-seat-and-139-an-internal-route-name
:decision/0137-a-machine-says-which-networks-it-routes
:issue/136-a-module-may-name-a-program-the-machine-lacks
:issue/135-a-containers-mesh-names
:decision/0112-accepted-and-issue-134
:design/28-and-32-what-shipped
:decision/0136-a-step-gates-its-module
:decision/0133-0134-migrations-and-deploy-facts
:issue/133-the-control-plane-migrates-before-it-serves
:decision/0132-a-seat-carries-the-tools-its-holder-must-serve
:issue/132-a-module-can-be-recorded-without-its-directory
:design/28-one-bus-issue-131-resolved
:design/28-the-mesh-runs-on-nats
:design/28-the-move-needs-a-membership-for-enrolled-nodes
:design/26-a-seat-is-held-on-record
:decision/0131-everything-speaks-to-the-broker-seat
:fix/131-nothing-tells-the-mesh-its-source-moved
:feat/nats-genesis
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
All three ADRs are proposed. Flip them to
acceptedonce reviewed; the design amendments (05's capability table, 26's seat table) follow in a separate change, since a design may not rest on a proposed record.container-runtimeis detected from the kernel, asseatis. "A runtime is running" becomes one probe, shared by the preflight and the runtime module's health. The detector change waits until 0166's seat requirement is enforced, so issue 007 cannot come back.node-container-runtimeis a seat of the mesh's own, held by thedockermodule. Its verbs and events cover every container on the machine. The holder runs as a supervised process and serves the verbs locally to the host and on the bus to everyone else. The host creates containers through it and never falls back to the command line. The bus is ruled out for the host because the broker itself is a container. Only the host may create or remove a mesh-held container.Checks: records, index, cycle pass.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.