Files
hq/01-RESEARCH/027-the-system-layer-as-modules/00-overview.md
T

3.1 KiB

status, initiated, touches, became
status initiated touches became
active 2026-10-04
02-DECISIONS/0165-container-runtime-is-what-a-machine-can-run-and-a-running-runtime-is-its-holders-health.md
02-DECISIONS/0166-the-container-runtime-is-a-node-seat-and-the-host-creates-containers-through-its-holder.md
02-DECISIONS/0203-the-accounts-environment-is-one-modules-and-every-module-contributes-to-it.md
02-DECISIONS/0205-software-the-distribution-does-not-package-ships-as-a-pinned-archive-of-the-module.md
03-DESIGN/01-to-be/37-the-operators-machine.md
03-DESIGN/01-to-be/38-building-the-operators-machine.md

027 — The system layer as modules

What is investigated

What runs on the machines below the operator's home and outside the mesh's own services, and which of it should be modules. That covers:

  • the container runtime and its tools;
  • privilege (sudo);
  • the package manager and the software it cannot install;
  • time, locale, the kernel and boot;
  • log rotation;
  • the machine-specific daemons the workstations and servers carry: printing, bluetooth, VPN clients, virtualisation, storage, sharing.

Why

The operator asked for the system level beside the graphical session. In particular:

  • a docker module (decided in principle by the proposed ADRs 0165 and 0166, never built);
  • a docker-compose module for development work, assigned only to the two workstations.

Measured in 01: on four machines, almost nothing at this level is owned by a module. The pieces differ by machine for no recorded reason. Three findings are security matters on their own.

How it is approached

Adopting is also improving (the operator, 2026-10-04). A module is not a copy of what a machine does today. Making it is the moment to fix what is broken, drop what is dead, choose the better tool and remove the leftovers. Every module's design lists its improvements over today. Every module also serves tools, many of them, for reading, acting and diagnosing; a module that only places a package and a file is unfinished. The tools are catalogued in 026/05.

What it touches

  • The container runtime seat (ADRs 0165 and 0166, both proposed).
  • The host's package shape, which installs from the distribution's official repositories only, while the workstations carry 67 and 114 packages from elsewhere.
  • How a secret reaches the account's environment. ADR 0203 forbids it in the contributed environment, but a predecessor file supplies such secrets today.
  • The facts the mesh assumes and never declares, above all that the operator account escalates without a prompt.

Documents