papa-hq reads 01 research -> 03 decision -> 02 design. The order is a scar, not a choice: 02-DESIGN existed from its initial commit, and when adr/ was finally promoted on 2026-07-13 it took the next free number rather than its place in the sequence. By then design was too settled to renumber. hal-hq was three commits old, so it is not. adr/ becomes 02-DECISIONS and 02-DESIGN becomes 03-DESIGN, and following the folder numbers now walks the process in the order it happens: research produces a decision, the decision authorises a design. 00-GENESIS becomes 00-META, matching papa's rename from the same restructure. Every path reference rewritten across documents, frontmatter, playbooks and skills. All links resolve; all 58 frontmatter blocks parse and their path fields still point at files that exist.
2.1 KiB
2.1 KiB
status, updated
| status | updated |
|---|---|
| canonical | 2026-08-22 |
Engineering Context
The conditions the mesh is built for. Properties, not an inventory — no node here is named, and nothing should be designed around a particular one existing.
Mandatory
- Nodes are heterogeneous. Desktops, laptops and servers, with different hardware, different operating systems and wildly different uptime. A design that assumes uniform nodes does not survive contact.
- Some nodes are mobile and frequently absent. They sleep, change networks and lose addressability. A node being unreachable is ordinary operation, never an incident.
- At least one node must be stably addressable. Central components — transport, registry, artifact storage — can only live where they can always be reached. That is a property some node must have, not an identity a particular node holds.
- Human agents are few — often one — and usually asleep. There is no team, no rota, no second reviewer. Anything requiring a human to notice it will be noticed late.
- Nodes are personal. A human agent works on the same node the mesh runs on. The mesh is a guest there and must not make a node worse to use.
Default
- Self-hosted throughout. Transport, state, artifacts and memory run on nodes the mesh owns, not a managed service.
- A hosted model provider supplies the thinking for non-human agents, drawn from a shared pool of subscriptions — which is why budget pacing is a first-class concern.
- Long-lived user services rather than an orchestrator. No cluster scheduler, no cloud control plane.
Defaults, not mandates. A second model provider is anticipated by design; nothing in the domain may assume one vendor's credential lifecycle.
Deviations
- No enterprise identity. No directory, no SSO. Identity is mesh-internal.
- Public exposure is minimal. Only nodes that must terminate public traffic do so.
- Agents share a pool of provider subscriptions rather than holding billing relationships of their own. A consequence of personal-scale infrastructure, and the reason spend must be paced rather than merely billed.