Building the bus: the decisions the work needed, and what it taught back #150
@@ -631,8 +631,32 @@ reserves them for after the move, and a flow built ahead of its design would be
|
||||
- [ ] 5.1 the cutover bed: a mesh on AMQP with a predecessor stand-in on the deprecated broker
|
||||
moves its bus in one rollout, every node reporting on NATS afterwards, the stand-in's own
|
||||
client still connected throughout
|
||||
- [ ] 5.2 the rollout: accounts composed, then the controller, every host and every runtime
|
||||
together; every node confirmed heard before AMQP stops
|
||||
- [~] 5.2 the rollout: accounts composed, then the controller, every host and every runtime
|
||||
together; every node confirmed heard before AMQP stops.
|
||||
|
||||
**The readiness half is in and is the half worth having.** The move takes every node at once, so
|
||||
there is nothing to inspect afterwards and no half to roll back — either the mesh was ready or it
|
||||
was not. `rollout check` answers that from records, with one dial: is a bus answering, does a
|
||||
machine hold the seat, has it been sent the composed user list, does every machine and every
|
||||
module that speaks have a credential. Each missing thing names its own next step, because "not
|
||||
ready" that cannot be acted on is not an answer at the point where the next step is irreversible.
|
||||
|
||||
**A machine with no credential is what must stop it.** It keeps running, cannot come back, and
|
||||
afterwards there is no bus to tell it anything over.
|
||||
|
||||
The move itself is deliberately not written yet, and the command says so rather than pretending:
|
||||
it waits on the check having been run against a real mesh. Writing the irreversible half before
|
||||
the question it depends on has ever been asked of something real is how the plan's own rule about
|
||||
beds gets broken by another route.
|
||||
|
||||
> **What this costs if it goes wrong, measured rather than assumed.** On the installation this is
|
||||
> for, the old broker is also what a whole automation layer outside the mesh connects to — so it
|
||||
> stays, as an ordinary provider of `amqp` ([ADR 0119](../../02-DECISIONS/0119-amqp-is-a-provision-not-the-bus.md)),
|
||||
> and this step is not its retirement. Nothing in a served request's path goes over the mesh's own
|
||||
> bus: modules serve from their own containers. What a failed move costs is the mesh's ability to
|
||||
> *change* anything — pushes, tool calls, new provisioning — until it is finished or undone. That
|
||||
> is worth knowing before rather than after, and it is why the operator's "as long as my services
|
||||
> keep running" is a reasonable position rather than a gamble.
|
||||
- [ ] 5.3 the mesh's own accounts removed from the deprecated broker: after the rollout nothing
|
||||
of the mesh speaks to it, and an account nothing uses is one nobody rotates
|
||||
|
||||
|
||||
Reference in New Issue
Block a user