Files
hq/03-DESIGN/01-to-be
jschoubben c570c687f6 The handover: switch off the old brain, leave the services running
The conversion method, recorded because it decides everything else and
was not written down.

The old control plane is stopped — provisioning, coordinator, syncs, the
pipeline, anything that decides or writes. The workloads it was managing
keep running, because nothing is managing them. The new mesh then takes
ownership one module at a time.

Nothing is ever unassigned in the old system. Unassigning is how it
removes things and removing is how data is lost; it is asked to stop
having opinions, never to take anything away.

Disabled rather than merely stopped, which is the part easy to get
wrong: those units are enabled, so a stop lasts until the next reboot. A
reboot mid-conversion would bring the old control plane back to
regenerate managed files underneath the new one — the one situation
where two systems really would fight over a machine.

A service left running with nothing managing it is the safe state: it
has its data, its configuration is on disk, and nothing will change
either. The risk in a conversion is in the managing, not the running.

Also records why taking ownership piecemeal is safe: the new host's
orphan removal is per-origin, so it only removes what it recorded
itself. Services it was never told about are not orphans to it.
2026-08-31 19:55:35 +02:00
..

03-DESIGN / 01-to-be

The mesh being built toward. Every statement here traces to a record in 02-DECISIONS/; nothing arrives by drafting.

A document here describes an intention. What currently runs is in 00-as-is/, and the two are never merged — when something ships, the as-is document is written and this one's status becomes implemented.

Document Covers Rests on
00-work-breakdown.md How modules move across one at a time, until the old registry can be switched off ADR 0001, ADR 0016
01-end-to-end-testing.md The lab: a real mesh a change can be run against before it reaches nodes ADR 0016, 0029
02-scenario-declaration.md What a scenario declares — the underlay, and what to place on it ADR 0016
03-scenario-lifecycle.md What happens to a scenario — raise, snapshot, restore, move, destroy ADR 0016
04-lab-installation.md Getting the lab onto a clean machine, and why it verifies capability rather than installation ADR 0010
05-the-node-host.md Tier 0 — the one thing installed by hand, and the only thing that changes a machine ADR 0005
06-the-control-plane.md Tier 2 — what the term means, and the test for what belongs in it ADR 0005
07-the-substrate.md Tier 1 — what the control plane consumes and cannot grant itself ADR 0004, 0048
08-connectivity.md One context in full — overlay, resolution, exposure, filtering, certificates ADR 0007, 0050, 0051, 0055
09-the-node-lifecycle.md How a machine becomes a node, stays one, and stops being one ADR 0004, 0051
10-delivery.md Modules, the three edges, and how a change becomes a running thing ADR 0010, 0064, 0065
11-a-board.md What a person sees of the mesh, and why it is read from what runs ADR 0008, ADR 0001
12-a-module-repository.md A module repository, and what builds it ADR 0009, ADR 0010, ADR 0005
13-credentials-and-their-rotation.md Credentials, and moving them without a consumer holding one the provider does not know about ADR 0001, ADR 0009
14-model-access.md Model access as a provision, and what a licence is bound to ADR 0024, ADR 0009
15-the-agent-session.md One mechanism started twice — a node's session and the mesh's ADR 0004, ADR 0026

Not yet written

  • The remaining six contexts. ADR 0006 settles the list at seven; connectivity is the first written in full (08) and the other six do not exist yet. The work breakdown says in what order they are needed.
  • Domain grouping outside the core. Not needed. ADR 0009 is superseded by ADR 0009: there is no domain module to group into, so there is no domain list to settle. Relationships are edges, and grouping is a tag and a query.