ADR 0120 inverts the facts mechanism from a closed list of controller-formatted names to a path + a Go template over the roster: the mesh owns the data, the module owns the format, and the control plane holds no format at all. /etc/hosts becomes a template on the mesh's own network module; dnsmasq's zones move into dnsmasq.
to-be 29 (operator accounts + what lives under a home) is rewritten to ride it:
the ssh files become roster templates (known_hosts, config, authorized_keys) — zero controller ssh syntax;
the whole ~/.ssh is owned, with a found/owned boundary that cannot lock the operator out;
keys are mesh-owned through an SSH CA (existing keys adopted not regenerated; the operator's personal key signed, never minted);
the ssh-agent is a user-scoped service running as the account.
Pairs with mesh-controller and mesh-catalog PRs of the same name (the implementation).
ADR 0120 inverts the `facts` mechanism from a closed list of controller-formatted names to a path + a Go template over the roster: the mesh owns the data, the module owns the format, and the control plane holds no format at all. `/etc/hosts` becomes a template on the mesh's own network module; dnsmasq's zones move into dnsmasq.
to-be 29 (operator accounts + what lives under a home) is rewritten to ride it:
- the ssh files become roster templates (known_hosts, config, authorized_keys) — zero controller ssh syntax;
- the whole `~/.ssh` is owned, with a found/owned boundary that cannot lock the operator out;
- keys are mesh-owned through an SSH CA (existing keys adopted not regenerated; the operator's personal key signed, never minted);
- the ssh-agent is a user-scoped service running as the account.
Pairs with mesh-controller and mesh-catalog PRs of the same name (the implementation).
The facts mechanism formatted the roster in Go in the control plane — one
formatter per fact, in the consumer's own configuration language. ADR 0120
makes a fact a path and a template: the mesh owns the data, the module owns
the format, and the control plane holds no format at all.
to-be 29 (operator accounts + what lives under a home) is rewritten to ride
it: the ssh files become roster templates, the whole ~/.ssh is owned with a
found/owned boundary that cannot lock the operator out, keys are mesh-owned
through an SSH CA (existing keys adopted not regenerated, the operator's
personal key signed not minted), and the ssh-agent is a user-scoped service.
A roster fact may be shared — written into a marked region of the machine's
file (into: block, hq 128) rather than as the whole file. The template
renders the content; shared decides how the host lays it down. Composes with
hq 128: the region mechanism is the host's, the format is the module's.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
ADR 0120 inverts the
factsmechanism from a closed list of controller-formatted names to a path + a Go template over the roster: the mesh owns the data, the module owns the format, and the control plane holds no format at all./etc/hostsbecomes a template on the mesh's own network module; dnsmasq's zones move into dnsmasq.to-be 29 (operator accounts + what lives under a home) is rewritten to ride it:
~/.sshis owned, with a found/owned boundary that cannot lock the operator out;Pairs with mesh-controller and mesh-catalog PRs of the same name (the implementation).