Jochen: a normal application has 3-5 ADRs, maybe 10 for a large one, and we are at 65. Fair, and the cause is mine -- I recorded every FINDING as a decision rather than every fork in the road. Two merges, both cases where one decision had been split across many records because it was taken over several days rather than at once. 0019 absorbs ten records about how this repository works: what it is and that it is public, the folder flow, the two design layers, the issue front door, status in frontmatter, playbooks, the naming rule, the product name. Those were never ten decisions -- they were one, seen from ten angles as the repository took shape. 0016 absorbs the five about the lab: a node is a virtual machine, a router is scenery, a scenario declares the underlay, a scenario is a closed address space, and the two scenario classes. Same pattern -- one design, split by the order it was worked out in. The consolidated 0019 also raises the bar for what earns a record, since that is what produced 65: a record is warranted when there is a genuine fork -- a direction reversed, an alternative that will be proposed again, something contested. A finding is not a decision, and a bug is certainly not. Everything else belongs in the design document where the reasoning is actually read. The checker earned its place here. Deleting nine records left 13 dangling links across the repository and it named every one, including in AGENTS.md. Nothing was found by reading. Remaining clusters worth the same treatment: the host (8 records), delivery (5), modules (6), connectivity (4), substrate and control plane (4). That would be 52 down to roughly 30.
3.3 KiB
status, initiated, touches, became
| status | initiated | touches | became | |||||||
|---|---|---|---|---|---|---|---|---|---|---|
| graduated | 2026-08-22 |
|
|
004 — Reproducing the mesh network in a lab
- Initiated by: jochen, 2026-08-22 — "the most difficult part of our VM setup will be the networking part"
- Areas touched:
modules/wireguard,modules/dnsmasq-app,modules/traefik,modules/mesh-ca,node_accessors,nodes.site/nodes.underlay_addr.
Summary
The network is entirely generated from mesh-DB rows by module hooks. install.d performs
no network configuration whatsoever — no WireGuard, no DNS, no firewall. That makes a faithful
lab primarily a data problem rather than a networking problem, and means the lab exercises
the real code path instead of a reimplementation of it.
One constraint decides whether the lab works at all: the WireGuard endpoint rule tests the
underlay address against an RFC1918 regex to decide reachability. A simulated public segment
addressed from RFC1918 space silently prevents the mesh from forming — no endpoint is written
for the hub, so nothing can ever initiate. The simulated public segment must therefore use
TEST-NET-3 (203.0.113.0/24).
With that one substitution the lab reproduces the production topology exactly, including the case that is hardest to get right: a node that is publicly named but sits behind NAT, whose endpoint the hub can only learn from a handshake.
Detail in analysis.md.
Settled
The lab issues its own certificates. Public names are certified by an ACME server on the
lab's wan segment; .internal names keep the mesh CA. The lab preserves production's two-CA
split rather than collapsing it, because a single-CA lab would hide any bug living in that
split. It also makes the router's port forward load-bearing — HTTP-01 must reach the
published-but-NATed node on port 80, so a broken forward becomes a reproducible certificate
failure instead of a mystery.
Requires one change: caServer is not set on the reverse proxy today, so it defaults to the
public authority's production endpoint. It must become configurable, defaulting to
production so real nodes are unaffected.
Open
Closed 2026-08-25. The lab is stood up. The topology this effort described raises, and the substitution it turned on — a simulated public segment addressed from documentation space rather than RFC1918 — is enforced by the declaration validator before anything is raised rather than left as a thing to remember.
The certificate conclusion above is carried by
01-end-to-end-testing.md, which
specifies the lab's own ACME issuer on the public segment. It is designed and not built —
implementation state is a third axis, and the effort graduates on its conclusions, not on
their delivery.
One item leaves this effort without a home and is recorded here so it is not lost: the reverse
proxy does not set caServer, so it defaults to the public authority's production endpoint.
That is a fact about what runs today, not about the lab.