Building the bus: the decisions the work needed, and what it taught back #150

Merged
jschoubben merged 45 commits from feat/nats-genesis into main 2026-09-27 17:06:40 +00:00
4 changed files with 94 additions and 4 deletions
Showing only changes of commit 9ef9830dcf - Show all commits
@@ -0,0 +1,64 @@
---
topic: the mesh
status: accepted
date: 2026-09-27
deciders: jochen
reconstructed: false
extends: 02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md
---
# 122. The predecessor is ending, and its broker goes with it
## Context
[ADR 0119](0119-amqp-is-a-provision-not-the-bus.md) settled that the old broker is an ordinary
provider of the `amqp` provision rather than a compatibility module with an end date. It rejected
giving it a retirement condition, and said why: *"its clients are not only the predecessor's, so the
retirement condition describes a day that will not come."*
**The operator has said that day is coming.** The predecessor is deprecated. Some of it is still
running, and it is not being migrated — it is being left to stop. Its broker may be shut down.
That is a fact about this installation, not a change of mind about what a broker is. It is recorded
because three documents reason from the premise it overturns:
[design 25](../03-DESIGN/01-to-be/25-the-bus-on-nats.md) §5 and §9, and
[design 28](../03-DESIGN/01-to-be/28-building-the-bus.md)'s closing note that the predecessor's world
"does not need to move: its broker is the compatibility module until its last client is gone."
## Decision
**The predecessor's broker retires when nothing requires `amqp`, by being unassigned like any other
provider.** No retirement condition, no end-date machinery, no special case — which is ADR 0119 being
paid off rather than revised. Because that record made the broker an ordinary provider, ending it
needs nothing that does not already exist: a provision with no consumers has its provider unassigned,
and the module system has done that since it existed.
**So step 5.3 has an ending.** "The mesh's own accounts removed from the deprecated broker" was
written as the last thing that could be said, because the broker itself was going to outlive the
question. It now finishes: once the mesh's own traffic has moved and the predecessor's remnants have
stopped, the module is unassigned and the port is free.
**And the transitional doubling has a date.** The build outcome is announced under both the module's
name and the role's on the old bus, so that a catalogue deployed before the rename and one deployed
after both hear it. That exists only while the old bus does, and goes with it.
## Consequences
**The remote access path goes with it, and that is the one practical consequence worth planning
around.** The predecessor's own mesh communicates over that broker — so shutting it down ends the
tooling that reaches this installation's machines remotely. Work on the node after that point is done
from the node. **This matters most for the rollout**, which is the step that would otherwise be driven
from a workstation: it has to be driven locally, or driven before the broker stops.
**What is still running on it stops when it stops.** Some of the predecessor's services are live and
are not being moved. That is the operator's decision and it is recorded here so that nobody later reads
a broker with clients as an accident.
**Nothing in a served request's path is affected.** Modules serve from their own containers; the mesh's
bus carries the mesh's own traffic — declarations, reports, events, tool calls. This was checked rather
than assumed when the question came up, and it is why the operator's position (*"as long as my services
keep running"*) is a bounded risk rather than a gamble.
**One reason to keep the broker survives**: `amqp` remains a provision a module may require, and a
module that genuinely needs an AMQP broker can be given one. What retires is *this* broker's role as
the predecessor's, not the mesh's ability to provide the thing.
+1
View File
@@ -137,6 +137,7 @@ python3 00-META/checks/index.py fail if stale
- **0119** — [AMQP is a provision, not the bus](0119-amqp-is-a-provision-not-the-bus.md)
- **0120** — [The mesh bus is required, not ambient](0120-the-mesh-bus-is-required-not-ambient.md)
- **0121** — [A seat carries the protocol of its role](0121-a-seat-carries-the-protocol-of-its-role.md)
- **0122** — [The predecessor is ending, and its broker goes with it](0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)
### Its tiers, from the bottom up
+10
View File
@@ -19,6 +19,7 @@ decisions:
- 02-DECISIONS/0083-one-push-leaves-the-mesh-consistent.md
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
- 02-DECISIONS/0121-a-seat-carries-the-protocol-of-its-role.md
- 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md
---
# 25. The bus on NATS
@@ -311,6 +312,15 @@ foundation, never raised at genesis, installed when something wants it and absen
that does not. There is no retirement condition, because the day its last client disappears is
not a day anything is waiting for.
**Revised 2026-09-27** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)):
**that day is coming.** The predecessor is deprecated — some of it still running, none of it being
migrated, left to stop rather than moved — so the broker retires once nothing requires `amqp`. Still no
retirement *condition* and no end-date machinery: a provision with no consumers has its provider
unassigned, which is the ordinary mechanism and is ADR 0119 being paid off rather than revised. What
also goes with it is the tooling that reaches this installation's machines remotely, because the
predecessor's own mesh talks over that broker — so the rollout is driven from the node, or before the
broker stops.
What is deprecated is AMQP as **the mesh's transport**, which is this whole document. The rule
that remains is about direction rather than software: *inter-module communication goes over the
bus.* A module may hold a broker, a database or a cache for itself; it may not use one as a
+19 -4
View File
@@ -15,6 +15,7 @@ decisions:
- 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
- 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md
---
# 28. Building the bus
@@ -657,8 +658,20 @@ reserves them for after the move, and a flow built ahead of its design would be
> *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That
> is worth knowing before rather than after, and it is why the operator's "as long as my services
> keep running" is a reasonable position rather than a gamble.
- [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing
of the mesh speaks to it, and an account nothing uses is one nobody rotates
- [ ] 5.3 the mesh's own accounts removed from the deprecated broker, and then the broker itself:
after the rollout nothing of the mesh speaks to it, and an account nothing uses is one nobody
rotates. **It finishes now** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)):
the predecessor is deprecated rather than kept, so once its remnants have stopped the module is
unassigned and the port is free. No retirement machinery — a provision with no consumers has its
provider unassigned, which is ADR 0119 being paid off rather than revised.
Retiring with it: the build outcome's second announcement under the module's own name, which
exists only so a catalogue deployed before the rename and one deployed after both hear it.
> **The remote tooling goes with it too.** The predecessor's own mesh talks over that broker, so
> shutting it down ends the path that reaches this installation's machines from a workstation.
> The rollout has to be driven from the node, or driven before the broker stops — which is a
> sequencing constraint on 5.2 and not an afterthought.
> **5.4 is gone, and was wrong from ADR 0119 onward.** It read "the deprecated broker retires
> when its condition holds — no client connected for the period the operator sets", which is
@@ -685,8 +698,10 @@ itself moves once, at the end, on one day.
- **Observation** — research 017's, after the move, by its own design.
- **Leaf nodes** — design 25 §11 keeps this out of scope and says so; a leaf per machine is a later
question, noted so it is not forgotten.
- **The predecessor's world.** It is AMQP, it cannot move, and it does not need to: its broker is
the compatibility module until its last client is gone.
- **The predecessor's world.** It is AMQP and it is not moving —
[ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md): it is
deprecated, some of it is still running, and it is being left to stop rather than migrated. Its
broker goes with it, unassigned like any provider whose provision nothing requires.
## How this list is kept true