61 lines
2.8 KiB
Markdown
61 lines
2.8 KiB
Markdown
---
|
|
topic: the tiers
|
|
status: accepted
|
|
date: 2026-09-21
|
|
deciders: jochen
|
|
reconstructed: false
|
|
extends: 02-DECISIONS/0047-a-module-runs-its-code-as-its-own-process-with-its-own-account.md
|
|
---
|
|
|
|
# 95. The control plane is the way to ask a module
|
|
|
|
## Context
|
|
|
|
A module serves tools over the broker under an account scoped to what it emits, consumes and
|
|
serves ([ADR 0047](0047-a-module-runs-its-code-as-its-own-process-with-its-own-account.md)). A
|
|
tool call is a request and a reply: the caller creates a reply queue and publishes to the serving
|
|
module's request key, and no module's scope grants either — nor should it, since a module that
|
|
only publishes events has no business declaring queues. So a module could serve tools and nothing
|
|
in the mesh could call them
|
|
([issue 049](../04-ISSUES/049-a-module-can-serve-tools-and-nothing-can-call-them/00-report.md)):
|
|
not an operator at a terminal, not an agent acting for one.
|
|
|
|
## Considered Options
|
|
|
|
1. **Calling is a grant**: a module declares it may be asked, and a consumer is issued an
|
|
account that may create a reply queue and publish to that module's request key. Deferred: a
|
|
module-to-module call is the only caller that resembles what the mesh mints today, and none
|
|
asks for one yet.
|
|
2. **The control plane is the way in.** Adopted. It holds a connection that may already, so a
|
|
person or an agent asks through it, and every question passes one process — which is where
|
|
an audit of who asked what belongs.
|
|
|
|
## Decision
|
|
|
|
`mesh-controller ask <module> <tool> [json]` publishes the request on the tool exchange under
|
|
`<module>.<tool>`, with a private reply queue bound under its own name, waits for the answer
|
|
whose correlation matches, and prints it as the module gave it. A tool that answered with an
|
|
error has answered: the answer is printed and the exit status says so. A module that never
|
|
answers is said to have not answered, with where to look.
|
|
|
|
A module declares nothing about being asked: serving a tool is being askable through the control
|
|
plane. A module-to-module call, if one is wanted, is a grant like any other and a later decision.
|
|
|
|
## Consequences
|
|
|
|
Anything with the control plane in reach can ask any module anything it serves. What got
|
|
harder: nothing outside the control plane can, and the control plane's connection is one more
|
|
thing on the path of every question — a cost accepted for the audit it buys.
|
|
|
|
## How it is checked
|
|
|
|
A tools-only bed asks a served tool through the control plane and asserts an answer arrived —
|
|
an error, since the lab has no upstream and no token, which is an answer where a timeout would
|
|
not be.
|
|
|
|
## References
|
|
|
|
- [issue 049](../04-ISSUES/049-a-module-can-serve-tools-and-nothing-can-call-them/00-report.md)
|
|
- [ADR 0047](0047-a-module-runs-its-code-as-its-own-process-with-its-own-account.md)
|
|
- [`03-DESIGN/01-to-be/19-the-module-protocol.md`](../03-DESIGN/01-to-be/19-the-module-protocol.md)
|