088, 089, 120, 128 and 130 each name a commit that is on main and cites them — the forge's address following a moved port, a route naming its endpoint, a provisioner asking the backend what is there, the hosts file written into a marked block, and undeclaring giving a unit back the state it was found in. Each says it was closed by reading commits rather than by a run, so nobody reads a green that was never measured. 129 stays located on purpose: ca-trust is merged and no machine holds it, so the symptom it opened on is still true everywhere.
2.7 KiB
Diagnosis
2026-09-29.
What was ruled out
That something already carries the root and it is only misplaced. It does not. The authority serves its root at a path beside its ACME directory, and the one thing that fetches it — the route proxy — puts it in a directory of its own and hands it to one program. Nothing has ever written into a machine's trust store. Measured on three converged machines: the anchors present are the predecessor's authority and a developer tool's local root, and on the machines where the predecessor's was deliberately removed, every internal name fails verification.
That the private network could carry it, the way it carries the registry's trust. That is what the report proposed, and it was rejected on consideration rather than on difficulty (ADR 0147, option 1): being on the network is what makes the registry reachable and is therefore the right trigger there, while trusting an authority is a separate fact from being able to reach it. The anchor's directory and the command that refreshes the extracted bundles are also one operating system's difference, which is the host's half of the mesh and not the controller's.
That it needs a new host resource type. It does not, today. A file and a service say the whole of it, which the packet filter already proves. The primitive becomes the right answer when a second operating system is in play, and not before.
Where it belongs
A module in the catalogue: it requires internal-acme-ca, fetches the root over the mesh's own
network, installs it as a trust anchor, refreshes the machine's bundles, and — because being
unassigned stops its unit, and stopping the unit is what undoes it — takes both away again.
The owner is therefore mesh-catalog, module ca-trust, and nothing in the control plane.
The module exists, and this stays open until a machine holds it
2026-09-29. ca-trust is in the catalogue and merged
(ADR 0147), and what it renders
is checked in the control plane's own suite: the script fetches from the authority it was bound to,
and the unit runs it both ways.
No machine has been assigned it, and nothing has verified a name because of it. The bed written
for that cannot run (issue 146),
and the live mesh has not been given the module. So the symptom this record opened on — every
internal name failing verification on every machine — is still true everywhere, and the record stays
located until it is not. Closing it on a module that exists would be closing it on an intention.