Building the bus: the decisions the work needed, and what it taught back #150
@@ -0,0 +1,64 @@
|
|||||||
|
---
|
||||||
|
topic: the mesh
|
||||||
|
status: accepted
|
||||||
|
date: 2026-09-27
|
||||||
|
deciders: jochen
|
||||||
|
reconstructed: false
|
||||||
|
extends: 02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md
|
||||||
|
---
|
||||||
|
|
||||||
|
# 122. The predecessor is ending, and its broker goes with it
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
[ADR 0119](0119-amqp-is-a-provision-not-the-bus.md) settled that the old broker is an ordinary
|
||||||
|
provider of the `amqp` provision rather than a compatibility module with an end date. It rejected
|
||||||
|
giving it a retirement condition, and said why: *"its clients are not only the predecessor's, so the
|
||||||
|
retirement condition describes a day that will not come."*
|
||||||
|
|
||||||
|
**The operator has said that day is coming.** The predecessor is deprecated. Some of it is still
|
||||||
|
running, and it is not being migrated — it is being left to stop. Its broker may be shut down.
|
||||||
|
|
||||||
|
That is a fact about this installation, not a change of mind about what a broker is. It is recorded
|
||||||
|
because three documents reason from the premise it overturns:
|
||||||
|
[design 25](../03-DESIGN/01-to-be/25-the-bus-on-nats.md) §5 and §9, and
|
||||||
|
[design 28](../03-DESIGN/01-to-be/28-building-the-bus.md)'s closing note that the predecessor's world
|
||||||
|
"does not need to move: its broker is the compatibility module until its last client is gone."
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
**The predecessor's broker retires when nothing requires `amqp`, by being unassigned like any other
|
||||||
|
provider.** No retirement condition, no end-date machinery, no special case — which is ADR 0119 being
|
||||||
|
paid off rather than revised. Because that record made the broker an ordinary provider, ending it
|
||||||
|
needs nothing that does not already exist: a provision with no consumers has its provider unassigned,
|
||||||
|
and the module system has done that since it existed.
|
||||||
|
|
||||||
|
**So step 5.3 has an ending.** "The mesh's own accounts removed from the deprecated broker" was
|
||||||
|
written as the last thing that could be said, because the broker itself was going to outlive the
|
||||||
|
question. It now finishes: once the mesh's own traffic has moved and the predecessor's remnants have
|
||||||
|
stopped, the module is unassigned and the port is free.
|
||||||
|
|
||||||
|
**And the transitional doubling has a date.** The build outcome is announced under both the module's
|
||||||
|
name and the role's on the old bus, so that a catalogue deployed before the rename and one deployed
|
||||||
|
after both hear it. That exists only while the old bus does, and goes with it.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
**The remote access path goes with it, and that is the one practical consequence worth planning
|
||||||
|
around.** The predecessor's own mesh communicates over that broker — so shutting it down ends the
|
||||||
|
tooling that reaches this installation's machines remotely. Work on the node after that point is done
|
||||||
|
from the node. **This matters most for the rollout**, which is the step that would otherwise be driven
|
||||||
|
from a workstation: it has to be driven locally, or driven before the broker stops.
|
||||||
|
|
||||||
|
**What is still running on it stops when it stops.** Some of the predecessor's services are live and
|
||||||
|
are not being moved. That is the operator's decision and it is recorded here so that nobody later reads
|
||||||
|
a broker with clients as an accident.
|
||||||
|
|
||||||
|
**Nothing in a served request's path is affected.** Modules serve from their own containers; the mesh's
|
||||||
|
bus carries the mesh's own traffic — declarations, reports, events, tool calls. This was checked rather
|
||||||
|
than assumed when the question came up, and it is why the operator's position (*"as long as my services
|
||||||
|
keep running"*) is a bounded risk rather than a gamble.
|
||||||
|
|
||||||
|
**One reason to keep the broker survives**: `amqp` remains a provision a module may require, and a
|
||||||
|
module that genuinely needs an AMQP broker can be given one. What retires is *this* broker's role as
|
||||||
|
the predecessor's, not the mesh's ability to provide the thing.
|
||||||
@@ -137,6 +137,7 @@ python3 00-META/checks/index.py fail if stale
|
|||||||
- **0119** — [AMQP is a provision, not the bus](0119-amqp-is-a-provision-not-the-bus.md)
|
- **0119** — [AMQP is a provision, not the bus](0119-amqp-is-a-provision-not-the-bus.md)
|
||||||
- **0120** — [The mesh bus is required, not ambient](0120-the-mesh-bus-is-required-not-ambient.md)
|
- **0120** — [The mesh bus is required, not ambient](0120-the-mesh-bus-is-required-not-ambient.md)
|
||||||
- **0121** — [A seat carries the protocol of its role](0121-a-seat-carries-the-protocol-of-its-role.md)
|
- **0121** — [A seat carries the protocol of its role](0121-a-seat-carries-the-protocol-of-its-role.md)
|
||||||
|
- **0122** — [The predecessor is ending, and its broker goes with it](0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)
|
||||||
|
|
||||||
### Its tiers, from the bottom up
|
### Its tiers, from the bottom up
|
||||||
|
|
||||||
|
|||||||
@@ -19,6 +19,7 @@ decisions:
|
|||||||
- 02-DECISIONS/0083-one-push-leaves-the-mesh-consistent.md
|
- 02-DECISIONS/0083-one-push-leaves-the-mesh-consistent.md
|
||||||
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
||||||
- 02-DECISIONS/0121-a-seat-carries-the-protocol-of-its-role.md
|
- 02-DECISIONS/0121-a-seat-carries-the-protocol-of-its-role.md
|
||||||
|
- 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md
|
||||||
---
|
---
|
||||||
|
|
||||||
# 25. The bus on NATS
|
# 25. The bus on NATS
|
||||||
@@ -311,6 +312,15 @@ foundation, never raised at genesis, installed when something wants it and absen
|
|||||||
that does not. There is no retirement condition, because the day its last client disappears is
|
that does not. There is no retirement condition, because the day its last client disappears is
|
||||||
not a day anything is waiting for.
|
not a day anything is waiting for.
|
||||||
|
|
||||||
|
**Revised 2026-09-27** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)):
|
||||||
|
**that day is coming.** The predecessor is deprecated — some of it still running, none of it being
|
||||||
|
migrated, left to stop rather than moved — so the broker retires once nothing requires `amqp`. Still no
|
||||||
|
retirement *condition* and no end-date machinery: a provision with no consumers has its provider
|
||||||
|
unassigned, which is the ordinary mechanism and is ADR 0119 being paid off rather than revised. What
|
||||||
|
also goes with it is the tooling that reaches this installation's machines remotely, because the
|
||||||
|
predecessor's own mesh talks over that broker — so the rollout is driven from the node, or before the
|
||||||
|
broker stops.
|
||||||
|
|
||||||
What is deprecated is AMQP as **the mesh's transport**, which is this whole document. The rule
|
What is deprecated is AMQP as **the mesh's transport**, which is this whole document. The rule
|
||||||
that remains is about direction rather than software: *inter-module communication goes over the
|
that remains is about direction rather than software: *inter-module communication goes over the
|
||||||
bus.* A module may hold a broker, a database or a cache for itself; it may not use one as a
|
bus.* A module may hold a broker, a database or a cache for itself; it may not use one as a
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ decisions:
|
|||||||
- 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
|
- 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
|
||||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||||
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
||||||
|
- 02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md
|
||||||
---
|
---
|
||||||
|
|
||||||
# 28. Building the bus
|
# 28. Building the bus
|
||||||
@@ -657,8 +658,20 @@ reserves them for after the move, and a flow built ahead of its design would be
|
|||||||
> *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That
|
> *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That
|
||||||
> is worth knowing before rather than after, and it is why the operator's "as long as my services
|
> is worth knowing before rather than after, and it is why the operator's "as long as my services
|
||||||
> keep running" is a reasonable position rather than a gamble.
|
> keep running" is a reasonable position rather than a gamble.
|
||||||
- [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing
|
- [ ] 5.3 the mesh's own accounts removed from the deprecated broker, and then the broker itself:
|
||||||
of the mesh speaks to it, and an account nothing uses is one nobody rotates
|
after the rollout nothing of the mesh speaks to it, and an account nothing uses is one nobody
|
||||||
|
rotates. **It finishes now** ([ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md)):
|
||||||
|
the predecessor is deprecated rather than kept, so once its remnants have stopped the module is
|
||||||
|
unassigned and the port is free. No retirement machinery — a provision with no consumers has its
|
||||||
|
provider unassigned, which is ADR 0119 being paid off rather than revised.
|
||||||
|
|
||||||
|
Retiring with it: the build outcome's second announcement under the module's own name, which
|
||||||
|
exists only so a catalogue deployed before the rename and one deployed after both hear it.
|
||||||
|
|
||||||
|
> **The remote tooling goes with it too.** The predecessor's own mesh talks over that broker, so
|
||||||
|
> shutting it down ends the path that reaches this installation's machines from a workstation.
|
||||||
|
> The rollout has to be driven from the node, or driven before the broker stops — which is a
|
||||||
|
> sequencing constraint on 5.2 and not an afterthought.
|
||||||
|
|
||||||
> **5.4 is gone, and was wrong from ADR 0119 onward.** It read "the deprecated broker retires
|
> **5.4 is gone, and was wrong from ADR 0119 onward.** It read "the deprecated broker retires
|
||||||
> when its condition holds — no client connected for the period the operator sets", which is
|
> when its condition holds — no client connected for the period the operator sets", which is
|
||||||
@@ -685,8 +698,10 @@ itself moves once, at the end, on one day.
|
|||||||
- **Observation** — research 017's, after the move, by its own design.
|
- **Observation** — research 017's, after the move, by its own design.
|
||||||
- **Leaf nodes** — design 25 §11 keeps this out of scope and says so; a leaf per machine is a later
|
- **Leaf nodes** — design 25 §11 keeps this out of scope and says so; a leaf per machine is a later
|
||||||
question, noted so it is not forgotten.
|
question, noted so it is not forgotten.
|
||||||
- **The predecessor's world.** It is AMQP, it cannot move, and it does not need to: its broker is
|
- **The predecessor's world.** It is AMQP and it is not moving —
|
||||||
the compatibility module until its last client is gone.
|
[ADR 0122](../../02-DECISIONS/0122-the-predecessor-is-ending-and-its-broker-goes-with-it.md): it is
|
||||||
|
deprecated, some of it is still running, and it is being left to stop rather than migrated. Its
|
||||||
|
broker goes with it, unassigned like any provider whose provision nothing requires.
|
||||||
|
|
||||||
## How this list is kept true
|
## How this list is kept true
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user