ADR 0121: a system seat is named for its scope; a module may define its own #145

Merged
jschoubben merged 1 commits from design/system-seats-are-named-by-scope into main 2026-09-27 12:15:22 +00:00
Owner

Refines ADR 0110. System seats are named for scope — mesh-* (one holder mesh-wide, on a named node) or node-* (one per node); the control plane defines only system seats, and a module may define its own outside the closed set (showcase is the first).

Folds in the seat review:

  • the-build-machine → mesh-build-machine (scope fix — one builder in the mesh)
  • the-private-network → mesh-private-network (model change — one server on the hub + client modules; drops per-node VPN choice)
  • the-showcase → removed, becomes module-defined
  • node-dns-resolver / node-resolver-config (kept distinct), node-packet-filter, node-intrusion-prevention, node-uplink
  • registry seats (artifact-store, npm, git → mesh-*) decided but gated on consolidating registries onto gitea

Records the two things that make this a project, not a rename: the held-seat renames are a coordinated controller+catalogue+held-state migration (delivering seats risk a mesh-wide outage), and retiring distribution is blocked until gitea actually serves an OCI registry — today it serves none, and distribution holds every image in the mesh.

Refines ADR 0110. System seats are named for scope — `mesh-*` (one holder mesh-wide, on a named node) or `node-*` (one per node); the control plane defines only system seats, and a module may define its own outside the closed set (showcase is the first). Folds in the seat review: - `the-build-machine` → `mesh-build-machine` (**scope fix** — one builder in the mesh) - `the-private-network` → `mesh-private-network` (**model change** — one server on the hub + client modules; drops per-node VPN choice) - `the-showcase` → **removed**, becomes module-defined - `node-dns-resolver` / `node-resolver-config` (kept distinct), `node-packet-filter`, `node-intrusion-prevention`, `node-uplink` - registry seats (`artifact-store`, `npm`, `git` → `mesh-*`) **decided but gated** on consolidating registries onto gitea Records the two things that make this a project, not a rename: the held-seat renames are a coordinated controller+catalogue+held-state migration (delivering seats risk a mesh-wide outage), and **retiring `distribution` is blocked** until gitea actually serves an OCI registry — today it serves none, and distribution holds every image in the mesh.
jschoubben added 1 commit 2026-09-27 12:15:16 +00:00
The control plane's seats grew a second naming style (the-*) beside mesh-*,
and the closed set was the only place any seat could be defined. This settles
both: system seats are mesh-* (one, mesh-wide) or node-* (one per node), named
for scope; a module may define its own seat outside the closed set. Folds in
the seat review: mesh-build-machine (scope fix), mesh-private-network (one
server + client modules, dropping per-node VPN choice), showcase becomes the
first module-defined seat, node-uplink, and the node-* renames — plus the
registry consolidation onto gitea, which reshapes the registry seats and gates
retiring distribution/verdaccio. Records why the renames are a coordinated
migration and why distribution cannot be removed until gitea serves images.
jschoubben merged commit 5a9917f802 into main 2026-09-27 12:15:22 +00:00
jschoubben deleted branch design/system-seats-are-named-by-scope 2026-09-27 12:15:22 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#145