Files
hq/03-DESIGN/01-to-be
jschoubben 3ab11c96ef Say what the host process is: a root service, installed as a package
The design described what the host does and never what it is at runtime. The
words daemon, long-running, interval, poll and heartbeat appeared nowhere in it
or in the relevant decisions. What exists is a command that runs and exits;
what the design needs is a process holding a link. Nobody had written down that
those differ, so several questions had no answer.

0057 settles them. It runs on every node -- the host is what makes a machine
managed, so a machine without one is not a node. Root, because no useful subset
of the job is unprivileged. A systemd unit, because something must survive a
reboot to hold the link.

It never manages its own unit. The temptation is obvious and it ends with a
host stopping itself half way through an apply, leaving a machine with nothing
running to fix it. The installation owns the host; the host owns everything
else.

Installed as a package, with a tarball as the floor. The package carries the
unit file, the state directory and an upgrade path, which a bare binary does
not. But the mesh's package repository is hosted on the mesh, so any route that
needs the mesh to install the thing that joins the mesh is a circle -- the
tarball is the path that must never acquire a dependency.

Reconciles on start, on a declaration, on a timer and on reconnect. The timer
is the one easy to leave out, and without it `owned` reports what the host
applied rather than what is there -- ADR 0035 violated by omission.

The records checker caught this commit on its first attempt: 05 listed 0057 in
its frontmatter while 0057 is still proposed, and a to-be document may not rest
on an unaccepted record. The section now says so in the body instead.
2026-08-27 21:06:00 +02:00
..

03-DESIGN / 01-to-be

The mesh being built toward. Every statement here traces to a record in 02-DECISIONS/; nothing arrives by drafting.

A document here describes an intention. What currently runs is in 00-as-is/, and the two are never merged — when something ships, the as-is document is written and this one's status becomes implemented.

Document Covers Rests on
00-work-breakdown.md How the decomposition gets built, in what order, and where a human must look ADR 0015
01-end-to-end-testing.md The lab: a real mesh a change can be run against before it reaches nodes ADR 0016, 0029
02-scenario-declaration.md What a scenario declares — the underlay, and what to place on it ADR 0031
03-scenario-lifecycle.md What happens to a scenario — raise, snapshot, restore, move, destroy ADR 0032
04-lab-installation.md Getting the lab onto a clean machine, and why it verifies capability rather than installation ADR 0008
05-the-node-host.md Tier 0 — the one thing installed by hand, and the only thing that changes a machine ADR 0037
06-the-control-plane.md Tier 2 — what the term means, and the test for what belongs in it ADR 0037
07-the-substrate.md Tier 1 — what the control plane consumes and cannot grant itself ADR 0038, 0048
08-connectivity.md One context in full — overlay, resolution, exposure, filtering, certificates ADR 0049, 0050, 0051, 0055

Not yet written

  • The remaining six contexts. ADR 0055 settles the list at seven; connectivity is the first written in full (08) and the other six do not exist yet. The work breakdown says in what order they are needed.
  • Domain grouping outside the core. Not needed. ADR 0017 is superseded by ADR 0044: there is no domain module to group into, so there is no domain list to settle. Relationships are edges, and grouping is a tag and a query.