Building the bus: the decisions the work needed, and what it taught back #150

Merged
jschoubben merged 45 commits from feat/nats-genesis into main 2026-09-27 17:06:40 +00:00
Showing only changes of commit 4f93d304d7 - Show all commits
+10 -3
View File
@@ -360,9 +360,16 @@ it, and the beds that need a mesh living on NATS can finally run.
- [ ] 4.2 a build source's change reaches the builder over the bus, and the build that follows is
the one the change asked for
- [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces
- [ ] 4.4 a person's client: the account, the client that speaks the bus, and the tool surface over
it (design 25 §7) — a module's tool invoked from another node and from a person, refused from
an account that may not
- [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no
seat, so their authority is a list of tools (or `*` for an administrator) and nothing else.
Held to four properties, each a way of being wrong that would not announce itself: nothing
but tools, so a person cannot claim a module said something; no ack subject, because
authority over a consumer that does not exist is authority nobody audits; no ability to
answer, because a person who can answer a request is impersonating a module on a bus where
anyone may serve a tool; and two people do not share an inbox.
Still to build: the client program itself — the command line and the MCP surface over it.
It needs nothing from the consume side, so it is not blocked by step 3.
- [ ] 4.5 reports and catch-up: a node that was unreachable catches up rather than losing them
**Done when.** Each converted flow is proved against the behaviour it replaced, and the full genesis