ADR 0131: everything on the mesh speaks to the broker seat, and AMQP is not a provision #152

Merged
jschoubben merged 1 commits from decision/0131-everything-speaks-to-the-broker-seat into main 2026-09-27 21:06:02 +00:00
Owner

The decision taken during tonight's outage, written up. It supersedes ADR 0127.

The protocol had leaked into the seat's contract: to hold mesh-broker a module had to provide amqp, so the module that will carry the bus on NATS could not hold the seat that names the bus, while the module being retired could. Modules now depend on the seat and reach the bus through the sdk. No manifest provides or requires amqp. The old broker's module and the two modules that required it leave the catalogue. The AMQP transport is deleted once every node reports on the new bus.

Design 28's step 5 is rewritten under it. The seat handover becomes its own task, built first — a seat the control plane dereferences cannot be empty in between, and that emptiness was the outage. The cost note carries what was measured tonight instead of what was assumed.

0128 and 0130 extended 0127; each now rests on 0131 with a dated note and nothing they decided changes. Every other citation of 0127 names its replacement in the same paragraph. records.py still fails on 0120/0112, which predates this branch.

The decision taken during tonight's outage, written up. It supersedes ADR 0127. The protocol had leaked into the seat's contract: to hold `mesh-broker` a module had to provide `amqp`, so the module that will carry the bus on NATS could not hold the seat that names the bus, while the module being retired could. Modules now depend on the seat and reach the bus through the sdk. No manifest provides or requires `amqp`. The old broker's module and the two modules that required it leave the catalogue. The AMQP transport is deleted once every node reports on the new bus. Design 28's step 5 is rewritten under it. The seat handover becomes its own task, built first — a seat the control plane dereferences cannot be empty in between, and that emptiness was the outage. The cost note carries what was measured tonight instead of what was assumed. 0128 and 0130 extended 0127; each now rests on 0131 with a dated note and nothing they decided changes. Every other citation of 0127 names its replacement in the same paragraph. `records.py` still fails on 0120/0112, which predates this branch.
jschoubben added 1 commit 2026-09-27 21:03:22 +00:00
Taken during the outage of 2026-09-27, when the protocol leaked into the seat's
contract: to hold mesh-broker a module had to provide amqp, so the module that
will carry the bus could not hold the seat that names the bus, while the module
being retired could. Supersedes 0127. Modules depend on the seat and reach the
bus through the sdk; no manifest provides or requires amqp; the old broker's
module and the two modules that required it leave the catalogue; the AMQP
transport is deleted once every node reports on the new bus.

Design 28 step 5 rewritten under it: the seat handover becomes its own task and
is built first, because the seat the control plane dereferences cannot be empty
in between — that emptiness was the outage. The cost note now carries what was
measured rather than what was assumed.

0128 and 0130 extended 0127; each now rests on 0131 with a dated note and
changes nothing it decided. Every other citation of 0127 names its replacement.
records.py still fails on 0120/0112, which predates this branch.
jschoubben merged commit 95d8253f71 into main 2026-09-27 21:06:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#152