Settles the design repository now that the self-upgrade build is on main: - Records the two decisions that shipped without a record — ADR 0077 (the controller/foundation/node vocabulary) and ADR 0078 (the store and broker are ordinary modules); accepts ADR 0075 and 0076, which shipped work rests on. - Fills issue 051's amended-design and wires ADR 0078 into 07-the-foundation. - Sweeps the repo rename (mesh-control -> mesh-controller) into the mutable docs now that the forge repo is renamed; updates the glossary note and repos.md. - Fixes the six broken links from the design-doc renames, indexes the glossary, regenerates the decisions reading order. Both checks (records.py, index.py) are green. Statuses stay honest: the build is on main and lab-proven but not deployed as the production mesh, so the to-be docs remain in-progress and the as-is layer (the hal mesh) is unchanged — graduation to implemented + as-is belongs to deployment, not merge. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
3.4 KiB
topic, status, date, deciders, reconstructed, extends
| topic | status | date | deciders | reconstructed | extends |
|---|---|---|---|---|---|
| the tiers | accepted | 2026-08-31 | jochen | false | 02-DECISIONS/0006-the-substrate-and-the-control-plane.md |
31. The control plane authenticates nobody, so identity is a module
Context
ADR 0006 left one member of the substrate conditional, and said exactly why:
| role | product | |
|---|---|---|
| identity provider | — | conditional: substrate only if the control plane delegates authentication, which is undecided |
07-the-foundation.md carried it as an open question —
whether identity is the fifth — noting it followed from a decision nobody had taken.
The decision is taken: the control plane does not delegate authentication. There is no mesh identity provider.
Nothing in the mesh's own machinery ever needed one. A node proves itself with a keypair it generated, over a broker account issued at enrolment (ADR 0004). Declarations are verified by signature. None of that touches an identity provider, and the conditional was never about machines — it was only ever about whether a person signing in to a mesh surface would be authenticated by something else.
Decision
Identity is a module, like the mail system and the forge. It runs on the mesh, not of it (ADR 0001) — a provider other modules require, which is the ordinary shape and needs nothing new to express.
So the substrate is three, and no longer conditional: a relational store, a message bus, and an image registry. Together with ADR 0028, which removed the object store, the list is settled and every member is there for the same reason — the control plane needs it and cannot ask itself for it.
A mesh that wants no identity provider runs none. That is now expressible, and was not while it sat in the substrate as a maybe.
Consequences
The last open question about substrate membership is closed. Both halves of ADR 0006's test now have an answer for every candidate, and the answer for identity is the control plane does not need it.
It does not settle how a person signs in to a mesh surface, and that is deliberately left open. What is settled is that whatever answers it is not part of what must exist before the mesh does — so it can be decided late, changed, or replaced, which is precisely what being substrate would have prevented.
It becomes a real test of the module graph. An identity provider is a module that other modules require — the object store already consumes it — so it exercises the provider chain more seriously than anything ported so far, where the provider was written alongside its consumer.
Ordering follows from it rather than from preference. Anything requiring identity has to move after it, which is a dependency the graph can state rather than something a person has to remember.