ADR 0080: the development cycle is checked, not trusted — plus review fixes #48

Merged
jschoubben merged 2 commits from process/the-development-cycle into main 2026-09-17 20:28:22 +00:00
6 changed files with 15 additions and 10 deletions
Showing only changes of commit 94fee5d849 - Show all commits
+2 -2
View File
@@ -9,7 +9,7 @@ another — and a mesh you cannot name precisely is a mesh two people describe d
- **node** — a machine in the mesh. There are 0..n of them, and each runs the host agent. A node is
just a machine that has joined; being one implies nothing about what it runs.
- **control-node** — the one node that also holds the `the-controller` seat. There is exactly one
- **control-node** — the one node that also holds the `mesh-controller` seat. There is exactly one
per mesh. "control-node" is not a separate kind of machine — it is a node that additionally runs
the controller (and, today, the foundation). Lose it and the other nodes keep running what they
were last told; they simply cannot be told anything new.
@@ -21,7 +21,7 @@ another — and a mesh you cannot name precisely is a mesh two people describe d
- **controller** — the component that decides what each node should be, holds the mesh's records,
and tells nodes over the broker. Replaces **"control plane"** (borrowed from networking's
control-plane/data-plane, and opaque here).
- **mesh-controller** — the module that runs the controller. It **claims** the `the-controller`
- **mesh-controller** — the module that runs the controller. It **claims** the `mesh-controller`
seat at mesh scope, which is what makes it singular. Replaces the module name **`mesh-control`**.
(The git repository has been renamed `mesh-control` -> `mesh-controller` on the forge; the module,
container and image it produces are `mesh-controller`.)
+6
View File
@@ -23,6 +23,12 @@ decisions:
# The foundation
**One store, one broker — enforced, not conventional.** Each foundation module claims a
mesh-scoped seat named after its server (`mesh-store`, `mesh-broker`, `mesh-controller` —
[ADR 0079](../../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md)), so
assigning a second holder anywhere in the mesh is refused at resolution rather than silently
raising a second server.
Tier 1. Defined the same way [the controller](06-the-controller.md) is, because the same
gap applied: the word was load-bearing and unpinned.
@@ -129,8 +129,8 @@ two.
| # | module | provides | note |
|---|---|---|---|
| 1 | `postgres` | `postgres-database` | **the controller's own records and every module's.** One server, not two |
| 2 | `lavinmq` | `amqp` | the broker every node dials, and what modules are granted vhosts on |
| 1 | `postgres` | `postgres-database` | **the controller's own records and every module's.** One server, not two — it *claims* the mesh-scoped `mesh-store` seat, so a second is refused |
| 2 | `lavinmq` | `amqp` | the broker every node dials, and what modules are granted vhosts on — *claims* `mesh-broker`, one per mesh |
| 3 | `mesh-controller` | *claims* `mesh-controller` | decides what runs where |
| 4 | `distribution` | `artifact-store` | what the mesh built, pinned by digest — the module is the software (Distribution), the provision is the job |
| 5 | `builder` | — | turns source into artifacts |
@@ -2,10 +2,9 @@
status: resolved
opened: 2026-09-16
located-in:
- mesh-controller/cmd/mesh-controller/modules.go
- mesh-controller/cmd/mesh-controller/build.go
- mesh-catalog/modules/lavinmq/module.json
fixed-by: mesh-controller multi-node/broker-reaches-over-overlay; mesh-catalog fix/broker-declares-amqps-port
- mesh-controller
- mesh-catalog
fixed-by: mesh-controller PR 27 (5718add); mesh-catalog PR 24 (a24362b)
amended-design:
---
@@ -1,7 +1,7 @@
---
status: resolved
opened: 2026-09-17
located-in: [mesh-controller, mesh-host]
located-in: [mesh-controller, mesh-catalog]
fixed-by: mesh-catalog + mesh-controller (the foundation modules claim mesh-scoped seats)
amended-design: 02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md
---
@@ -6,7 +6,7 @@ fixed-by:
amended-design:
---
# 059 — A provisioner runtime crash-loops until the overlay is up
# 058 — A provisioner runtime crash-loops until the overlay is up
## Symptom