Files
hq/03-DESIGN/01-to-be
jschoubben 004057d85c A node's identity is a keypair it generates. This was never open.
I have been treating "what a node presents to prove it is that node" as an
undecided design question for weeks, and blocking on it. It was decided.
08-connectivity says of the overlay keys: each node generates its own keypair,
the private key never leaves the machine, the public key is published to the
mesh -- and says explicitly that this IS ADR 0004's "a node holds its own
identity", applied. Nobody had applied it to the thing 0004 is actually about.

What caused it was a word. The lifecycle said a joining node receives its own
durable identity, which reads as the mesh issuing something, and then the
question is what. The mesh issues nothing. A node arrives holding its identity;
what it receives is being known. That line now says what happens: it presents
the one-time secret and its own public key, which the mesh records.

The rule above it then holds literally rather than aspirationally. The mesh
stores a public key, so a copy of the mesh's database grants nothing, and
compromise of a node really is compromise of only that node.

Also recorded, since it was asked directly: same principle as SSH, own key, not
the machine's SSH host key. Host keys are regenerated by reinstalls and image
clones, which would silently un-enrol a node; their lifecycle belongs to sshd
rather than the mesh; and a partial host has no SSH daemon at all, so an
identity scheme resting on one excludes a supported kind of node.

The good half of that idea is kept: the mesh knows every node, so it can
distribute host keys the way it distributes authorised keys, and node-to-node
SSH stops depending on trust-on-first-use.
2026-08-29 15:21:36 +02:00
..

03-DESIGN / 01-to-be

The mesh being built toward. Every statement here traces to a record in 02-DECISIONS/; nothing arrives by drafting.

A document here describes an intention. What currently runs is in 00-as-is/, and the two are never merged — when something ships, the as-is document is written and this one's status becomes implemented.

Document Covers Rests on
00-work-breakdown.md How the decomposition gets built, in what order, and where a human must look ADR 0001
01-end-to-end-testing.md The lab: a real mesh a change can be run against before it reaches nodes ADR 0016, 0029
02-scenario-declaration.md What a scenario declares — the underlay, and what to place on it ADR 0016
03-scenario-lifecycle.md What happens to a scenario — raise, snapshot, restore, move, destroy ADR 0016
04-lab-installation.md Getting the lab onto a clean machine, and why it verifies capability rather than installation ADR 0010
05-the-node-host.md Tier 0 — the one thing installed by hand, and the only thing that changes a machine ADR 0005
06-the-control-plane.md Tier 2 — what the term means, and the test for what belongs in it ADR 0005
07-the-substrate.md Tier 1 — what the control plane consumes and cannot grant itself ADR 0004, 0048
08-connectivity.md One context in full — overlay, resolution, exposure, filtering, certificates ADR 0007, 0050, 0051, 0055
09-the-node-lifecycle.md How a machine becomes a node, stays one, and stops being one ADR 0004, 0051
10-delivery.md Modules, the three edges, and how a change becomes a running thing ADR 0010, 0064, 0065

Not yet written

  • The remaining six contexts. ADR 0006 settles the list at seven; connectivity is the first written in full (08) and the other six do not exist yet. The work breakdown says in what order they are needed.
  • Domain grouping outside the core. Not needed. ADR 0009 is superseded by ADR 0009: there is no domain module to group into, so there is no domain list to settle. Relationships are edges, and grouping is a tag and a query.