ADR 0122: a seat is data the controller owns; a rename is a database update #148

Merged
jschoubben merged 1 commits from design/a-seat-is-data into main 2026-09-27 13:41:11 +00:00
Owner

Reviews ADR 0110/0121 after this session showed that renaming a seat costs a Go-slice edit, a const gitSeat change in production code, manifest churn, a controller rebuild, three compose freezes, and a builder deadlock. The seat rules (closed set, scope naming) were right; the set being compiled Go referenced by name-string was the mistake.

Decision: seats become a table the controller owns, keyed by a stable id; claims/held/production code reference the id; the name is a label resolved once at registration. A rename is then one UPDATE — no rebuild, no re-registration, no freeze — and the build machine reads the set from the mesh instead of embedding it (removing the controller/builder deadlock). Closed set and mesh-*/node-* naming unchanged; only storage/reference change. Config stays in modules, not on seats.

Outstanding renames (registry seats, the private-network scope change) should wait for this — as data, each is a write, not a coupled multi-repo deploy.

Reviews ADR 0110/0121 after this session showed that renaming a seat costs a Go-slice edit, a `const gitSeat` change in production code, manifest churn, a controller rebuild, three compose freezes, and a builder deadlock. The seat *rules* (closed set, scope naming) were right; the set being **compiled Go referenced by name-string** was the mistake. Decision: seats become a **table the controller owns**, keyed by a **stable id**; claims/held/production code reference the id; the name is a label resolved once at registration. A rename is then one `UPDATE` — no rebuild, no re-registration, no freeze — and the build machine reads the set from the mesh instead of embedding it (removing the controller/builder deadlock). Closed set and `mesh-*`/`node-*` naming unchanged; only storage/reference change. Config stays in modules, not on seats. Outstanding renames (registry seats, the private-network scope change) should wait for this — as data, each is a write, not a coupled multi-repo deploy.
jschoubben added 1 commit 2026-09-27 13:41:06 +00:00
Reviews 0110/0121 after a session where renaming seats cost three freezes, a
builder deadlock, and hand-resolved manifests. The seat rules were right; the
set being a compiled Go slice referenced by name-string everywhere was the
mistake. Seats become a table keyed by a stable id; claims/held/production code
reference the id; a rename is one UPDATE, no rebuild, no re-registration, no
freeze. The build machine reads the set from the mesh instead of embedding it,
removing the controller/builder seat coupling. Closed set and scope naming
unchanged; only storage and reference change. Outstanding renames (registry
seats, private-network scope) wait for this — as data each is a write.
jschoubben merged commit a39765c924 into main 2026-09-27 13:41:11 +00:00
jschoubben deleted branch design/a-seat-is-data 2026-09-27 13:41:11 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#148