Issue 114: should the controller be a container or a process the host supervises #100

Closed
jschoubben wants to merge 2 commits from issue/113-controller-container-or-process into main
Owner

Filed after tonight's migration session, where every mesh-controller interaction went through docker exec rather than any first-class surface.

Its own manifest declares it type: container with network: host — not using the one property (network isolation) that resource type usually buys — while ADR 0006 makes it the mesh's single point of coordination (one deployable, no failover, recovery is restore not failover).

ADR 0005 refuses to let the host run in a container for a related reason: it would need the thing it exists to install. The controller doesn't install the runtime, but shares the profile that argument turns on.

This is an open question, not a claimed defect — checks pass (records.py, cycle.py, index.py), no code changed. See the report for the specific open questions.

Filed after tonight's migration session, where every `mesh-controller` interaction went through `docker exec` rather than any first-class surface. Its own manifest declares it `type: container` with `network: host` — not using the one property (network isolation) that resource type usually buys — while [ADR 0006](02-DECISIONS/0006-the-substrate-and-the-control-plane.md) makes it the mesh's single point of coordination (one deployable, no failover, recovery is restore not failover). [ADR 0005](02-DECISIONS/0005-the-node-host.md) refuses to let the *host* run in a container for a related reason: it would need the thing it exists to install. The controller doesn't install the runtime, but shares the profile that argument turns on. This is an open question, not a claimed defect — checks pass (`records.py`, `cycle.py`, `index.py`), no code changed. See the report for the specific open questions.
jschoubben added 2 commits 2026-09-24 13:52:25 +00:00
Filed after a session where every mesh-controller interaction went through
docker exec — its manifest runs it as a container with network: host, using
none of the isolation that resource type usually buys, while ADR 0006 makes
it the mesh's single point of coordination. Open question, not a claimed
defect: does type: container get the controller anything type: process
(supervised the way the host supervises its own unit, per ADR 0005) would not.
Both used the next number available when opened, and the object-store
withdrawal report merged first. No content change beyond the number.
jschoubben force-pushed issue/113-controller-container-or-process from da41c1cc40 to a97feeefe5 2026-09-24 13:52:25 +00:00 Compare
jschoubben changed title from Issue 113: should the controller be a container or a process the host supervises to Issue 114: should the controller be a container or a process the host supervises 2026-09-24 13:52:29 +00:00
Author
Owner

Superseded by #110, now merged. That PR contains this report verbatim plus a "The general case" section tying it to issue 117, and files it at 04-ISSUES/114-should-the-controller-be-a-container-or-a-process/ — a shorter folder name for the same number. Merging both would have created two folders numbered 114 with the same subject, which git would not have flagged.

Closing without merging; nothing from this branch is lost.

Superseded by #110, now merged. That PR contains this report verbatim plus a "The general case" section tying it to issue 117, and files it at `04-ISSUES/114-should-the-controller-be-a-container-or-a-process/` — a shorter folder name for the same number. Merging both would have created two folders numbered 114 with the same subject, which git would not have flagged. Closing without merging; nothing from this branch is lost.
jschoubben closed this pull request 2026-09-26 12:14:51 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#100