Files
hq/00-META
jschoubben 605c9fd441 Changes are pushed, not polled; and a stuck host rolls itself back
Two corrections and one new decision, all from Jochen catching things.

Pushed, not polled. I described updates as landing "on the next reconcile",
which reads as polling and is not the design. A declaration arrives as a
message on a link that is already open; the host applies it then. Polling over
an existing connection would be slower to land AND constant traffic to learn
nothing.

The timer is for drift and nothing else, and it cannot be replaced by an event
for a definitional reason: drift is change the mesh did not make -- somebody
edited a managed file, a distribution upgrade replaced a config -- so nothing
will ever publish a message about it. Only looking finds it.

Separated the heartbeat from the reconcile timer, which I had been conflating.
They point in opposite directions and answer different questions: the timer
looks at the machine and asks whether it still matches; the heartbeat reports
upward and is what makes silence mean something. A node with nothing to do
sends nothing, and without a heartbeat that is indistinguishable from a node
that stopped.

0059 -- a host that cannot start is rolled back by the service manager. I had
left this open on the grounds that recovery meant the host judging its own
health. That objection does not survive being asked properly: a keepalive is
something else judging the host. The watchdog must be local, because nothing
dials a node and a host that cannot start cannot report -- so it is the service
manager, which is already there.

The failure it prevents is sharper than "the node is down": a host that will
not start looks exactly like a machine somebody switched off, which is the one
condition this design has deliberately decided not to alarm on. So a bad
release reaches every node, each goes quiet, and the mesh reports a fleet of
sleeping laptops.

Confirmed means started and completed one reconcile -- deliberately not "the
link is up", or a laptop on a train would roll itself back. The rollback is a
script shipped by the package, not a host subcommand, because a binary that
will not start cannot be its own recovery. It rolls back once: a second failure
means the machine is the problem, not the binary.

Also refined the records checker, which produced a false positive: a proposed
record may extend another proposed one, because decisions are drafted in chains
and the alternative is marking things accepted to satisfy a check. An accepted
document resting on a proposed record still fails, and that was verified.

0057, 0058 and 0059 are all proposed.
2026-08-27 22:04:26 +02:00
..

00-META

The northern star. What the mesh is, the environment it runs in, and what changes when it works — plus the engineering practice that holds across everything Novox builds. Every research effort and design decision is checked against this folder.

File / folder Purpose
mission.md Vision, mission, and the values that decide arguments
context.md The environment — conditions, not aspirations
effect.md What is different when the work is done
how-we-build.md The rules that hold across the mesh, each one earned. The source of the mesh constitution — the governed page the mesh injects into design sessions is derived from it.
repos.md Where implementation lives, and what each repository owns
process/ The playbooks — how work moves through this repository, for engineers and agents alike

Rules

  • Markdown only.
  • Stable by nature. Changes here reflect a genuine shift in intent, not iteration. The one exception is how-we-build.md, which changes whenever a rule is earned — and only through its amendment process.
  • Research and design must be traceable back to what is written here.
  • Instance-agnostic. These documents describe the mesh as a concept. No machine names, no counts, no topology.

On the architecture overview in the code repository

The code repository carries an architecture overview predating this folder. It is a useful description of how the mesh works, and its content now lives — anonymised and checked against the implementation — in 03-DESIGN/00-as-is/. GENESIS answers why; that document answered how, which is the design layer's job.

It had also drifted from the implementation in ways worth recording, since both were found by comparing it against the code rather than by anyone noticing:

  • It described the pipeline as having a separate builder process and a build stage that packages. Neither was true after 2026-08-04; the documents stayed stale until 2026-08-06 (ADR 0014).
  • It listed the mesh as spanning a fixed number of named machines, which is exactly the content this repository cannot carry.

It also lists "symlinks, not copies" as a key design principle, and that is a genuine contradiction rather than a stale detail. The mesh's stated intent is that it creates no symlinks at all — the rule is not merely "only the installer may link", and a founding document elevating linking to a principle points the opposite way from where this is going.

What exists today is that the installer owns and reconciles every link (ADR 0011) — an as-is fact, recorded in 03-DESIGN/00-as-is/05-runtime-and-installation.md. Centralising who may link narrowed the incident class; it did not close it. The intent is to remove the mechanism, recorded as ADR 0018.

A founding document contradicting the direction of travel is precisely the failure this folder exists to prevent.