2.0 KiB
status, initiated, touches, became
| status | initiated | touches | became | ||||||
|---|---|---|---|---|---|---|---|---|---|
| active | 2026-10-03 |
|
020 — What a bundled tool is given
What is being investigated
How a module's tools, once they are a bundle the node's runtime loads (ADR 0175, ADR 0188), learn the things their container used to be handed: where the module's configuration file is, where its token or password is, which port the service listens on, where a provision's address is written. A container is given these as an environment and mounts, composed by the mesh per module per machine. A bundle has no environment of its own: the runtime's process carries four words for every bundle it loads, and nothing per module (design 38 WP4).
Why
Two holders moved on 2026-10-03 — the packet filter and the intrusion prevention — and both could, because neither needs anything but a fixed path and root. Of the thirty-three modules whose tools still run as containers on the runtime's image, thirty-one are not like that: their environment names a configuration file, a credential file, a service address, a grants directory. Moving them one by one without a rule for this would give the mesh thirty-one answers to one question. The measurement and the options are in 01.
What it touches
The runtime (which hands a bundle what it is given), the composer (which resolves ${dir:…} and
${port:…} for a container today and would for a bundle), the manifest (where a bundle would say
what it needs), and design 38, which records the gap and must say the rule once there is one.