088, 089, 120, 128 and 130 each name a commit that is on main and cites them — the forge's address following a moved port, a route naming its endpoint, a provisioner asking the backend what is there, the hosts file written into a marked block, and undeclaring giving a unit back the state it was found in. Each says it was closed by reading commits rather than by a run, so nobody reads a green that was never measured. 129 stays located on purpose: ca-trust is merged and no machine holds it, so the symptom it opened on is still true everywhere.
46 lines
2.7 KiB
Markdown
46 lines
2.7 KiB
Markdown
# Diagnosis
|
|
|
|
*2026-09-29.*
|
|
|
|
## What was ruled out
|
|
|
|
**That something already carries the root and it is only misplaced.** It does not. The authority
|
|
serves its root at a path beside its ACME directory, and the one thing that fetches it — the route
|
|
proxy — puts it in a directory of its own and hands it to one program. Nothing has ever written
|
|
into a machine's trust store. Measured on three converged machines: the anchors present are the
|
|
predecessor's authority and a developer tool's local root, and on the machines where the
|
|
predecessor's was deliberately removed, every internal name fails verification.
|
|
|
|
**That the private network could carry it, the way it carries the registry's trust.** That is what
|
|
the report proposed, and it was rejected on consideration rather than on difficulty
|
|
([ADR 0147](../../02-DECISIONS/0147-a-module-anchors-the-meshs-authority.md), option 1): being on
|
|
the network is what makes the registry *reachable* and is therefore the right trigger there, while
|
|
trusting an authority is a separate fact from being able to reach it. The anchor's directory and
|
|
the command that refreshes the extracted bundles are also one operating system's difference, which
|
|
is the host's half of the mesh and not the controller's.
|
|
|
|
**That it needs a new host resource type.** It does not, today. A file and a service say the whole
|
|
of it, which the packet filter already proves. The primitive becomes the right answer when a second
|
|
operating system is in play, and not before.
|
|
|
|
## Where it belongs
|
|
|
|
A module in the catalogue: it requires `internal-acme-ca`, fetches the root over the mesh's own
|
|
network, installs it as a trust anchor, refreshes the machine's bundles, and — because being
|
|
unassigned stops its unit, and stopping the unit is what undoes it — takes both away again.
|
|
|
|
The owner is therefore `mesh-catalog`, module `ca-trust`, and nothing in the control plane.
|
|
|
|
## The module exists, and this stays open until a machine holds it
|
|
|
|
*2026-09-29.* `ca-trust` is in the catalogue and merged
|
|
([ADR 0147](../../02-DECISIONS/0147-a-module-anchors-the-meshs-authority.md)), and what it renders
|
|
is checked in the control plane's own suite: the script fetches from the authority it was bound to,
|
|
and the unit runs it both ways.
|
|
|
|
**No machine has been assigned it, and nothing has verified a name because of it.** The bed written
|
|
for that cannot run ([issue 146](../146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/00-report.md)),
|
|
and the live mesh has not been given the module. So the symptom this record opened on — every
|
|
internal name failing verification on every machine — is still true everywhere, and the record stays
|
|
`located` until it is not. Closing it on a module that exists would be closing it on an intention.
|