Files
hq/01-RESEARCH/008-delivery-coordinator/00-overview.md
T
jschoubben daf3e17c32 self-hosting, provisioning and delivery efforts, and the dotfiles origin
The identity provider is settled as not-substrate: the mesh does not
require one, tier 2 authenticates natively, and it is a hosted service
like any other. Four substrate services, not five. The tier test's second
step gains the verb that matters — can the control plane START without it,
not function fully without it.

That verb answers the forge and the registries. They are not substrate and
they are not duplicated: the control plane starts and manages nodes
without a forge, it just cannot change itself. One gitea module, tier 4,
and the mesh's own instance is distinguished by what it is bound to rather
than by being a different module — the same answer as postgres, from the
same test. It also buys a property worth having: if the forge dies the
mesh keeps running.

Delivery needing them is not an upward dependency, resolved the way the
constitution already says to: tier 2 declares requirements, tier 4
provides implementations, the binding is data. The mechanism is
provisioning, and the new idea is that the control plane is itself a
consumer.

Self-hosting therefore becomes a state the mesh REACHES, not a
precondition. A first node comes up from pinned external artifacts and
re-binds to internal providers once they exist. Today's mesh assumes the
second state from the first moment, which is why the first-node path needs
a script that papers over an impossibility and is the least-exercised code
in the system. Made explicit, the transition is also reversible.

Research 007 and 008 opened for the two areas flagged as important and
complex, scoped from the weaknesses the as-is layer already documents
rather than started blank.

And the origin: this began as a dotfiles repository. The first two days
adopt dotfiles, add per-node overrides, and introduce service symlinking
with an ignore file. The flat one-directory-per-tool catalogue, linking
over copying, adoption of already-configured machines, per-node overrides
and the desktop modules are all inherited rather than chosen for a mesh.
That is the single most useful fact for anyone changing the catalogue, it
strengthens ADR 0018 — the case for links was never made for a mesh — and
it explains research 005's silent fifty: dotfiles-era entries for one tool
never shared a domain because they never had one.
2026-08-23 20:55:14 +02:00

3.3 KiB

status, initiated, touches, became
status initiated touches became
active 2026-08-23
03-DESIGN/00-as-is/04-delivery.md
02-DECISIONS/0014-build-publish-and-deploy-are-three-silos.md
02-DECISIONS/0013-an-artifact-is-build-output.md
01-RESEARCH/006-mesh-from-scratch/code-skeleton.md

008 — The coordinator: a change checked in becomes a deployed state

What is being investigated

The mesh's own continuous delivery: a change is committed, and the mesh ends up in the state that change describes — across every node the change touches, with a verdict that says whether it worked.

The coordinator is what orchestrates that, and it is the mesh's most consequential machinery: everything reaches every node through it.

Why now

The as-is record (03-DESIGN/00-as-is/04-delivery.md) names problems that are structural rather than incidental:

  • A green pipeline proves transport, not effect. The stages report that a message was dispatched and accepted, which is not the same as the thing running, correct, or present. This is the mesh's single most consistent failure shape.
  • Detection is the most fragile input. A merge that creates no pipeline, with nothing saying so, is the characteristic bad outcome — and it has happened for reasons unrelated to the change.
  • The fan-out point is asymmetric. The build node has already passed two silos when work fans out, and code that knew only about the first parked it forever while every other node deployed cleanly.
  • There is no end-to-end coverage. The harness has not built since 2026-06-04 (04-ISSUES/005).

Research 006 adds a requirement the current design does not have: the coordinator must work before the mesh is self-hosting, when source and artifacts come from outside, and keep working across the transition to self-hosted providers.

The questions

Question Why it matters
What is a deployed state, and how does the mesh know it is in one? Everything follows from this. If a stage reports transport, "deployed" is a claim nobody checked. A desired-state model with reconciliation gives a different answer from a job-completion model.
Does the coordinator dispatch stages, or converge nodes on a declaration? The current model is a state machine over stages. The alternative is that a node is told what should be true and reports what is. The second makes drift visible; the first cannot see it.
How does a change become a pipeline, reliably? Detection has failed for reasons unrelated to the change, silently.
What produces a verdict, and what is it a verdict about? Ties to the lab (ADR 0016) and to a module carrying its own assertions.
How does delivery work before self-hosting, and across the transition? From research 006: source and artifacts start external and are re-bound to internal providers. The coordinator has to be indifferent to which.
Does the three-silo split survive the artifact/part split? ADR 0014 is cardinality-driven, and research 006 renames the thing the cardinality is about.