48 lines
2.6 KiB
Markdown
48 lines
2.6 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-09-23
|
|
located-in: [mesh-controller cmd/mesh-controller/network.go (the placing command), internal/inventory/migrations/0004-the-overlay.sql (one hub)]
|
|
fixed-by: nothing to build — ADR 0161 rule 2; the second hub was already refused by name, and the private network's seat waits for ADR 0121's server and client modules
|
|
amended-design: [03-DESIGN/01-to-be/26-the-seats.md]
|
|
---
|
|
|
|
# 105 — The hub of the private network is a placement, not a seat
|
|
|
|
## What was observed
|
|
|
|
Reading the registry of a one-node mesh, 2026-09-23. The private network claims a seat,
|
|
`the-private-network`, scoped to the **node** — because every node has an interface and a
|
|
mesh-scoped seat would refuse the second machine. The fact that matters, *which node is the hub the
|
|
others rendezvous at*, is a placement record (`overlay place <node> hub`) and no seat at all.
|
|
|
|
## Why it matters beyond this instance
|
|
|
|
The four foundation seats all say the same thing: *there is exactly one of me in this mesh*
|
|
([ADR 0079](../../02-DECISIONS/0079-the-foundation-seats-are-named-after-their-servers.md)). "There is
|
|
exactly one hub" is that shape. As a placement it is refused by nothing: two nodes can be placed as
|
|
hub, and the mesh would compute a graph with two rendezvous points and say nothing.
|
|
|
|
It also confuses the reading. Asked "who provides the private network", the registry answers with
|
|
a node-scoped seat held by every node, which is true and not what was asked.
|
|
|
|
## Open questions
|
|
|
|
- Should the hub be a mesh-scoped seat — `the-hub`, or the network's own name — claimed by the
|
|
node that is placed there, refused elsewhere?
|
|
- Does the per-node seat still say anything once the hub is a seat, or is it the interface's
|
|
presence restated?
|
|
- What else in the mesh is "exactly one" and recorded as a placement rather than a seat?
|
|
|
|
## Resolved, 2026-10-01
|
|
|
|
Read against the code: the store has kept one hub since the overlay's first migration (a unique
|
|
index), and `overlay place <node> --hub` refuses a second naming the first. What this report saw as
|
|
silent is not. [ADR 0161](../../02-DECISIONS/0161-what-deserves-a-seat.md), rule 2, answers the
|
|
question that remained: a singular fact about machines is a placement with a capacity of one,
|
|
refused by name and named in the listing — never a seat, because a seat is held by a module
|
|
assignment and the private network is the host's own until
|
|
[ADR 0121](../../02-DECISIONS/0121-a-system-seat-is-named-for-its-scope-and-modules-define-their-own.md)'s
|
|
server and client modules exist. That seat stands, deferred with the split it needs.
|
|
|
|
*How it is checked:* the overlay command's test for a second hub, and the index.
|