Files

2.0 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
resolved 2026-09-21
mesh-host internal/declaration
mesh-controller internal/catalogue
mesh-catalog modules/route-proxy
ADR 0099; mesh-host and mesh-controller multiple-fixes (a run-once step may name what it reads and runs again when it changed); mesh-catalog multiple-fixes (the proxy's gate names the binding, the server names the gate) 03-DESIGN/01-to-be/08-connectivity.md, 03-DESIGN/01-to-be/20-writing-a-module.md

077 — A fact fetched at first start is fetched once per declaration

Symptom

A consumer fetches a fact its provider made at first start through a run-once step (ADR 0098): the route proxy fetches the certificate authority's root before it starts. The host runs a run-once step once per declaration digest. When the authority is re-initialised — its state wiped, or the module moved to another node, where it makes a new root — the proxy's declaration is unchanged, so the step does not run again. The proxy keeps the old root, refuses the new authority's certificates, and its own healing path, keyed on the root it holds, never fires.

Observed by reading the apply loop and the proxy, not from an incident. No bed re-keys an authority.

Why it matters beyond the instance

Any fact a provider makes at first start has the same shape: the consumer's declaration does not change when the provider's fact does. A run-once step cannot say "again when the provider changed", and a restart trigger is not allowed on a run-once step (ADR 0053), so there is no declarative remedy today.

What would close it

Either the run-once marker includes something of the provider's — the provider's declaration digest, or an epoch the mesh raises when a provider is re-issued or moved — or the gate is not run-once but a validator that runs before every start of the service and is cheap when nothing changed. Decided, then proven by a bed that re-keys the authority and watches the proxy trust the new root.