38 lines
2.0 KiB
Markdown
38 lines
2.0 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-09-21
|
|
located-in: [mesh-host internal/declaration, mesh-controller internal/catalogue, mesh-catalog modules/route-proxy]
|
|
fixed-by: ADR 0099; mesh-host and mesh-controller multiple-fixes (a run-once step may name what it reads and runs again when it changed); mesh-catalog multiple-fixes (the proxy's gate names the binding, the server names the gate)
|
|
amended-design: 03-DESIGN/01-to-be/08-connectivity.md, 03-DESIGN/01-to-be/20-writing-a-module.md
|
|
---
|
|
|
|
# 077 — A fact fetched at first start is fetched once per declaration
|
|
|
|
## Symptom
|
|
|
|
A consumer fetches a fact its provider made at first start through a run-once step
|
|
([ADR 0098](../../02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md)):
|
|
the route proxy fetches the certificate authority's root before it starts. The host runs a
|
|
run-once step once per declaration digest. When the authority is re-initialised — its state
|
|
wiped, or the module moved to another node, where it makes a new root — the proxy's declaration
|
|
is unchanged, so the step does not run again. The proxy keeps the old root, refuses the new
|
|
authority's certificates, and its own healing path, keyed on the root it holds, never fires.
|
|
|
|
Observed by reading the apply loop and the proxy, not from an incident. No bed re-keys an
|
|
authority.
|
|
|
|
## Why it matters beyond the instance
|
|
|
|
Any fact a provider makes at first start has the same shape: the consumer's declaration does not
|
|
change when the provider's fact does. A run-once step cannot say "again when the provider
|
|
changed", and a restart trigger is not allowed on a run-once step (ADR 0053), so there is no
|
|
declarative remedy today.
|
|
|
|
## What would close it
|
|
|
|
Either the run-once marker includes something of the provider's — the provider's declaration
|
|
digest, or an epoch the mesh raises when a provider is re-issued or moved — or the gate is not
|
|
run-once but a validator that runs before every start of the service and is cheap when nothing
|
|
changed. Decided, then proven by a bed that re-keys the authority and watches the proxy trust the
|
|
new root.
|