--- status: active initiated: 2026-08-23 touches: - 03-DESIGN/00-as-is/04-delivery.md - 02-DECISIONS/0014-build-publish-and-deploy-are-three-silos.md - 02-DECISIONS/0013-an-artifact-is-build-output.md - 01-RESEARCH/006-mesh-from-scratch/code-skeleton.md became: [] --- # 008 — The coordinator: a change checked in becomes a deployed state ## What is being investigated The mesh's own continuous delivery: a change is committed, and the mesh ends up in the state that change describes — across every node the change touches, with a verdict that says whether it worked. The coordinator is what orchestrates that, and it is the mesh's most consequential machinery: everything reaches every node through it. ## Why now The as-is record ([`03-DESIGN/00-as-is/04-delivery.md`](../../03-DESIGN/00-as-is/04-delivery.md)) names problems that are structural rather than incidental: - **A green pipeline proves transport, not effect.** The stages report that a message was dispatched and accepted, which is not the same as the thing running, correct, or present. This is the mesh's single most consistent failure shape. - **Detection is the most fragile input.** A merge that creates no pipeline, with nothing saying so, is the characteristic bad outcome — and it has happened for reasons unrelated to the change. - **The fan-out point is asymmetric.** The build node has already passed two silos when work fans out, and code that knew only about the first parked it forever while every other node deployed cleanly. - **There is no end-to-end coverage.** The harness has not built since 2026-06-04 ([`04-ISSUES/005`](../../04-ISSUES/005-pipeline-test-harness-unbuildable/00-report.md)). Research 006 adds a requirement the current design does not have: the coordinator must work **before the mesh is self-hosting**, when source and artifacts come from outside, and keep working across the transition to self-hosted providers. ## The questions | Question | Why it matters | |---|---| | What is a **deployed state**, and how does the mesh know it is in one? | Everything follows from this. If a stage reports transport, "deployed" is a claim nobody checked. A desired-state model with reconciliation gives a different answer from a job-completion model. | | Does the coordinator dispatch **stages**, or converge nodes on a **declaration**? | The current model is a state machine over stages. The alternative is that a node is told what should be true and reports what is. The second makes drift visible; the first cannot see it. | | How does a change **become** a pipeline, reliably? | Detection has failed for reasons unrelated to the change, silently. | | What produces a **verdict**, and what is it a verdict about? | Ties to the lab ([ADR 0016](../../02-DECISIONS/0016-a-lab-node-is-a-virtual-machine.md)) and to a module carrying its own assertions. | | How does delivery work **before self-hosting**, and across the transition? | From research 006: source and artifacts start external and are re-bound to internal providers. The coordinator has to be indifferent to which. | | Does the **three-silo** split survive the artifact/part split? | [ADR 0014](../../02-DECISIONS/0014-build-publish-and-deploy-are-three-silos.md) is cardinality-driven, and research 006 renames the thing the cardinality is about. |