Files
hq/04-ISSUES/213-the-controller-is-a-go-program-run-in-a-container/00-report.md
T

2.4 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-10-03
mesh-controller
mesh-catalog

213 — The controller is a Go program, and it still runs in a container

What was observed

2026-10-03. The controller — the program that holds the mesh-controller seat and answers its verbs (status, nodes, push, assign …), composes every machine's declaration and plans the builds — runs on its machine as a container built from an image:

mesh-controller   Up …        (docker ps on the machine that runs it)

It is written in Go and compiles to one static binary, as the node host does. The host is delivered as a bundle and run as a process; the node's tool runtime now is too (ADR 0193). The controller is the one piece of the mesh's own Go code still shipped as an image.

Why it matters beyond this instance

ADR 0188 §1 says a module's own code is bundles, never an image, and §3 that a bundle that is a service is a process the host runs. The controller breaks the rule it is the mechanism of: the registration gate that will refuse an image of a module's own code has to exempt the controller, or refuse it. It also costs what an image costs — a container runtime on its machine as a hard requirement, eight mounts standing in for files a process would simply read, an image rebuild for a binary change — and every restart of it is a container recreation, which is how the controller restarts in the middle of a plan today.

What a fix has to settle

  • The controller's module declares a Go bundle (system, binary) and a process running it (./<binary>, mesh-host #81), with its credential and store connection as files and words, not container mounts and a container network name.
  • What the container gives it now that a process would not: it runs on the host's network already, as an unprivileged user (65534), with eight mounts. Each mount named and replaced by a path, and the user by an account the host declares.
  • The handover: the controller restarting itself as a process, on the one machine that runs it, without a window where nothing answers the mesh's verbs.

Located only by owner; the move is a change of the controller's module and its deployment, not of its code.