to-be 29: a node has operator accounts, and the mesh owns what lives under a home #138

Merged
jschoubben merged 1 commits from design/29-a-node-has-operator-accounts into main 2026-09-26 21:53:40 +00:00
Owner

Operator's insight: the login identity ("who you and I are on each node") is crucial mesh information, and something must own ~/.ssh inside the nox mesh. Confirmed the gap in code — the node record has no account field, and no nox module writes under a home. Proposes two paired additions: the operator account as a node fact, and a home-scoped resource class (the ~/ mirror of ADR 0112's /var/lib placement, owned by the account), with the login key staying the operator's per ADR 0051. Captures the open questions (one vs many accounts, where the key lives, the sshd boundary) rather than deciding them. Not urgent/not blocking — HAL's generators still run as substrate; load-bearing at node-by-node retirement.

Operator's insight: the login identity ("who you and I are on each node") is crucial mesh information, and *something* must own `~/.ssh` inside the nox mesh. Confirmed the gap in code — the node record has no account field, and no nox module writes under a home. Proposes two paired additions: the operator account as a node fact, and a home-scoped resource class (the `~/` mirror of ADR 0112's `/var/lib` placement, owned by the account), with the login key staying the operator's per ADR 0051. Captures the open questions (one vs many accounts, where the key lives, the sshd boundary) rather than deciding them. Not urgent/not blocking — HAL's generators still run as substrate; load-bearing at node-by-node retirement.
jschoubben added 1 commit 2026-09-26 21:53:34 +00:00
The mesh models machines but not the people on them — a node record
holds no username, and no module places anything under a home. So who
you are on each node (jochens/ace/jochen) is unknown to the mesh, and
nothing owns ~/.ssh, dotfiles or ~/.config. HAL knew it; the nox mesh
dropped it. Proposes the account as a node fact and a home-scoped
resource class (the ~/ mirror of ADR 0112's /var/lib placement), with
the login key staying the operator's (ADR 0051). Not urgent — HAL's
generators still run — load-bearing at node-by-node retirement. Found
generating ~/.ssh/config from HAL's registry, which nox has no
equivalent for.
jschoubben merged commit 8deecf620a into main 2026-09-26 21:53:40 +00:00
jschoubben deleted branch design/29-a-node-has-operator-accounts 2026-09-26 21:53:40 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#138