HQ held only the to-be. Every reader had to already know the system the decisions were about, and an as-is claim had nowhere to live except inside an intention. Adds 02-DESIGN/00-as-is — eleven documents written from the implementation and the operational record, not from intent, including the parts nobody would choose again. The two existing designs move under 01-to-be. Layers are declared in frontmatter and never mix: a design that ships does not move, its as-is counterpart is written, and both stand. Back-fills adr/0001-0014 for decisions taken in implementation and never recorded — the broker, the module abstraction, the mesh database, managed files, provisioning, migrations, the workspace removal, failing loudly, the constitution, application placement, linking, the employee model, the artifact, the three silos. Each marked reconstructed, dated from the history, and citing the evidence it was recovered from. The two existing records renumber to 0015 and 0016 so the ledger runs oldest first; 0017 extends 0015 to modules outside the core, principle only — the domain list is deliberately not invented here. how-we-build.md becomes the source of the mesh constitution, with a sync playbook, so the enforced copy stops being the only one that is true. Process becomes explicit: five playbooks, eight thin skills that defer to them, a repository map, and AGENTS.md with CLAUDE.md as its include. The five Observations become 04-ISSUES 001-005 where they can be owned and closed. 006 is new and uncomfortable: HQ is not indexed into the knowledge base. That claim is what decision 27 rests on, it was never checked, and the README now says so instead of repeating it. Also corrects the ADR index into something generated, the "02-DESIGN is empty" claim, the VISION.md pointer that did not survive the repo split, and a note asserting the symlink rule was contradicted — it was a misreading; the rule forbids hand-made links, the installer links by design.
2.9 KiB
status, initiated, touches, became
| status | initiated | touches | became | ||||
|---|---|---|---|---|---|---|---|
| graduated | 2026-08-22 |
|
|
002 — A mesh that runs locally
- Initiated by: jochen, 2026-08-22
- Areas touched:
install.d/,hal/meshware,hal/coordinator,hal/brain,hal/developer(dev_up),hal/sdk(env generation, feature handlers, artifact manager),test/pipeline/,test/dev-mesh/, the provisioning path inmodules/postgres/.
Summary
Phase 0 of 02-DESIGN/00-work-breakdown.md requires
a mesh that comes up in containers, runs its own pipeline, and reproduces known faults on
demand. Nothing else in the decomposition starts until it exists, because every fault the
decomposition addresses was found in production — there was nowhere else to find it.
This effort establishes what already runs in a container, what is welded to the host, and
what it would take to close the gap. It does not choose an approach: the central
question — how a containerised node executes a module service, when a module service is
defined today as a systemd unit shelling to docker compose in /services/ — is not
answered by ADR 0015 and is recorded below rather than decided.
What was established
- The two existing container harnesses are neither of them a mesh, and one of them has not been able to build since 2026-06-04.
- Node identity is already portable — a single environment variable, no host handshake.
- Four concrete host couplings block a containerised node, all with known locations.
- All three Phase 0 fixtures are reproducible; one of them is documented in the knowledge base with an open root cause and is the cheapest place to start.
Detail and evidence in analysis.md.
Questions — all settled 2026-08-22
Phase 0 is a development environment, not a fixture rig — it is what the host-borrowing dev tooling becomes.
The trigger is a real source-forge container, because the webhook relay is part of what is under test.
A node is a system container, promotable to a virtual machine per node. This answered
the question the effort was stuck on, and dissolved it rather than solving it: against a
real node with a real init, the four host couplings catalogued in analysis.md §3 are not
couplings — they are how a node works. They were obstacles only to a node modelled as an
application container.
Consequently 003-service-supervision no longer blocks
Phase 0. It remains a live architecture question, on its own timeline.
The remaining questions in analysis.md — what replaces host paths in a container, and how
faithful the lab must be — are answered in the design: nothing replaces them, because the
paths are real; and the divergences are enumerated rather than discovered.