Files
hq/02-DECISIONS/0025-hq-is-the-source-of-the-constitution.md
T
jschoubben 77f3a4cea7 Consolidate: 65 decision records to 23
Every remaining cluster merged. Each was one design that had been split across
several records because it was worked out over days rather than at once.

  the node host          8 -> 1    applies not decides, depends on nothing,
                                   per operating system, root service, the
                                   launcher, episodic, what a declaration is,
                                   actions from the bundle only
  a node and how it joins 4 -> 1   what a node is, joining, the link as
                                   security boundary, the enrolment token
  modules and the graph   7 -> 1   everything is a module, no domain modules,
                                   three edges, provisioning, the core library
  substrate and control   6 -> 1   the test, seven contexts, one control plane,
    plane                          the authority is not a database, the named
                                   products, the pinned bundle
  connectivity            3 -> 1   a route is a grant, reachability declared,
                                   filter rules
  delivery                5 -> 1   reconciliation not a pipeline, artifacts,
                                   the three silos, a failed step, the verdict
  the lab                 5 -> 1   (earlier)
  how this repository     10 -> 1  (earlier)
    works

Nothing was dropped. Each consolidated record carries the reasoning of the ones
it absorbs -- the measurements, the incidents, the alternatives rejected --
because that reasoning is the only reason to keep a record at all. What is gone
is the fragmentation: eight files to read to understand tier 0, when tier 0 is
one component.

The four superseded records went too. They existed to point at their
successors, and the successors now contain what they said.

The checker made this safe. Each merge left dangling links -- 38 files after
the host merge alone -- and it named every one. Nothing was found by reading,
and a manual pass would certainly have missed some, including references inside
AGENTS.md which every session loads.
2026-08-28 20:03:24 +02:00

3.1 KiB

status, date, deciders, reconstructed
status date deciders reconstructed
accepted 2026-08-23 jochen false

25. HQ is the source of the mesh constitution

Context

ADR 0009 established a canonical rule set, injected into every eligible design session and checked before output is accepted. It lives in the knowledge base, where the orchestrator reads it.

HQ separately carried a document stating overlapping rules with the reasoning that earned each one. Two texts, one enforced and one not.

That arrangement has a predictable outcome and it is not a tie. The enforced copy wins by default, because it is the one that blocks work. The reasoned copy quietly stops being true, and the rules survive without the incidents that justify them — at which point a rule reads as arbitrary, and an arbitrary rule is the kind people route around.

Considered options

  1. The knowledge-base page is the source; HQ points at it. Rejected, though it is the honest description of what was already happening. It leaves the reasoning downstream of the rule, and the reasoning is the part that makes a rule survive a challenge.
  2. Accept the overlap and let both stand. Rejected: two authorities is no authority, and the drift is silent.
  3. HQ is the source; the governed page is derived and published from it. Chosen.

Decision

00-META/how-we-build.md is the source. The governed page the mesh injects is derived from it — the rules without the reasoning — and is never edited directly.

Publishing is a playbook step, not a manual act, and it ends with reading the page back and verifying the change is present. A publish that reported success and did nothing is exactly the failure class this mesh keeps producing (ADR 0058).

Section numbering is stable, because the orchestrator and the review fragments cite sections by number.

Consequences

  • One source, many surfaces — the same argument HQ's separation already rests on (ADR 0019), applied to the rules themselves.
  • Each rule keeps the incident that earned it, in a place that is reviewed as a diff.
  • An edit to the derived page survives until the next sync and then vanishes. The playbook says so, and nothing mechanically prevents it.
  • The sync is manual and is the weak point. An unsynced rule is a rule the mesh does not enforce, whatever the source says — so the playbook requires the failure to be stated rather than passed over. This is the same class of gap as 04-ISSUES/006, and it is worth watching for the same reason.
  • The document grew from four rules to seven sections, because it now has to carry everything the mesh enforces rather than only what someone thought to write down.

References