Building the bus: the decisions the work needed, and what it taught back #150

Merged
jschoubben merged 45 commits from feat/nats-genesis into main 2026-09-27 17:06:40 +00:00
Showing only changes of commit bfefb1dbdb - Show all commits
+23 -2
View File
@@ -534,8 +534,29 @@ it, and the beds that need a mesh living on NATS can finally run.
The outcome carries the module name, because only the manifest says what was built and one The outcome carries the module name, because only the manifest says what was built and one
message now has three readers. A failed build names none: it produced no module version, and message now has three readers. A failed build names none: it produced no module version, and
the catalogue would otherwise place something that was never made. the catalogue would otherwise place something that was never made.
- [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — - [~] 4.3 an installation completes over the bus, with the same outcome as the path it replaces —
**unblocked, same** **the installer can raise it**: a foundation template that stands up the server, writes the
server's own settings and the mesh's first user list beside them, and starts a controller
reaching the new bus. What remains is running it, which is 4.1's bed.
**The mesh composes its own user list, and at genesis there is no mesh to compose one.** So the
installer carries the first — the controller's account at a well-known bootstrap password,
exactly as the store is reached at `postgres:bootstrap` and the old bus at `guest:guest`, and
rotated with them. From the controller's first composition onward the file is the controller's.
That surfaced a gap reading would not have found: the controller's own account exists before
there is a controller to mint one, so nothing recorded a hash for it and its first composition
would have left the writer out of the file it was writing — a bus nothing can connect to,
produced by the thing connected to it. It records a hash of the credential it is using, and only
when none is recorded, so a restart cannot put the bootstrap password back over a rotated one.
**The carried list and the derived one are checked against each other**, because they are two
statements of one fact and a mesh cannot be raised twice to find out they disagreed. A template
granting less than the controller derives produces a mesh that comes up, connects, and is
refused on its first act, with an authorisation error naming a subject rather than the template
that forgot it. The check earned itself at once: the composer was granting a role's whole event
branch *and* the one event it follows, and the wider grant wins — so only the submitting half of
a role is granted now, and what comes back is named exactly.
- [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no - [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no
seat, so their authority is a list of tools (or `*` for an administrator) and nothing else. seat, so their authority is a list of tools (or `*` for an administrator) and nothing else.
Held to four properties, each a way of being wrong that would not announce itself: nothing Held to four properties, each a way of being wrong that would not announce itself: nothing