Files
hq/00-META
jschoubben 1b5308c9cc Review of the to-be layer: check what the documents claim against what runs
First pass of a design review, done by reading documents against code
and against a raised mesh rather than against each other. Every error
below was invisible to a proofread.

**Statuses were stale, and nothing checked them.** Ten to-be documents
said `designed` while naming working, lab-proven code — several with a
*What was built* or *Raised, and observed* section. Added a
`status-vs-code` check: naming a file is a claim that the file
implements this, so a document that points at one has stopped being
merely designed. It failed on all ten before it passed, per the rule
this folder sets for its own checks.

**The bundle carries three images, not two.** 07 reasoned about which
substrate services go in and overlooked that the control plane is in
there too — it is what the substrate exists to start, and there is
nothing to fetch it with yet. Counted, not deduced.

**The bootstrap uses four shapes, not six.** It listed `file` and
`directory`, which substrate-first-node.lock never asks for. The claim
that mattered — nothing is blocked on the host — was true either way,
which is why the wrong count survived.

**The eight capabilities were documented nowhere.** Implemented in
internal/profile/detectors.go and enumerated in no document, including
the one about the host that detects them. A vocabulary modules write
against, readable only by reading the code. Now written down, with the
seat/graphical-session distinction that is wrong in both directions if
collapsed.

**MinIO swept out of the to-be layer** per 0028.

The gate now fails on one thing left deliberately: ADR 0024 is
`proposed` while two documents rest on it and the feature it decides is
built and lab-proven. Accepting a decision is not mine to do.
2026-08-31 17:20:47 +02:00
..

00-META

The northern star. What the mesh is, the environment it runs in, and what changes when it works — plus the engineering practice that holds across everything Novox builds. Every research effort and design decision is checked against this folder.

File / folder Purpose
mission.md Vision, mission, and the values that decide arguments
context.md The environment — conditions, not aspirations
effect.md What is different when the work is done
how-we-build.md The rules that hold across the mesh, each one earned. The source of the mesh constitution — the governed page the mesh injects into design sessions is derived from it.
repos.md Where implementation lives, and what each repository owns
process/ The playbooks — how work moves through this repository, for engineers and agents alike

Rules

  • Markdown only.
  • Stable by nature. Changes here reflect a genuine shift in intent, not iteration. The one exception is how-we-build.md, which changes whenever a rule is earned — and only through its amendment process.
  • Research and design must be traceable back to what is written here.
  • Instance-agnostic. These documents describe the mesh as a concept. No machine names, no counts, no topology.

On the architecture overview in the code repository

The code repository carries an architecture overview predating this folder. It is a useful description of how the mesh works, and its content now lives — anonymised and checked against the implementation — in 03-DESIGN/00-as-is/. GENESIS answers why; that document answered how, which is the design layer's job.

It had also drifted from the implementation in ways worth recording, since both were found by comparing it against the code rather than by anyone noticing:

  • It described the pipeline as having a separate builder process and a build stage that packages. Neither was true after 2026-08-04; the documents stayed stale until 2026-08-06 (ADR 0010).
  • It listed the mesh as spanning a fixed number of named machines, which is exactly the content this repository cannot carry.

It also lists "symlinks, not copies" as a key design principle, and that is a genuine contradiction rather than a stale detail. The mesh's stated intent is that it creates no symlinks at all — the rule is not merely "only the installer may link", and a founding document elevating linking to a principle points the opposite way from where this is going.

What exists today is that the installer owns and reconciles every link (ADR 0012) — an as-is fact, recorded in 03-DESIGN/00-as-is/05-runtime-and-installation.md. Centralising who may link narrowed the incident class; it did not close it. The intent is to remove the mechanism, recorded as ADR 0012.

A founding document contradicting the direction of travel is precisely the failure this folder exists to prevent.