Files
hq/04-ISSUES
jochen d169f9d8cd ADR 0112 and issue 118: address the review
- Secrets follow ADR 0085 as amended: a module's own secret is a provision the controller mints and
  the vault records. The previous commit had that backwards. Whether the vault should generate
  instead is recorded as an open question, not decided.
- A directory's contract is owner and mode only. The persistence flag was the keep flag ADR 0030
  refused; a directory is kept while it holds anything, and disposable data is a named volume (0107).
- An operator's shared data stays an access (ADR 0051), which rejected an operator-owned directory.
  Only where its path is written moves to the assignment.
- The records it changes on acceptance are named: 0051, 0091, 0046 (settings keyed by instance),
  0084 (a provider is a node and an instance), and the glossary, which gains its new words only
  when the record is accepted.
- How it is checked covers every stated rule. Container-side paths are no longer flagged by the
  host-path rule, and code fallbacks are covered.
- Provisions are what other modules provide. A seat's occupant is not listed as one, and the vault
  is not described as selectable per assignment.
- 'Control plane' becomes 'controller'. The provider count is ten of eleven, not eleven of twelve.
2026-09-25 22:21:39 +02:00
..

04-ISSUES

The front door for "something is wrong" at the level of the mesh's design or governance. Diagnosis happens here, where the whole mesh is in view; the fix lands in the owning code repository.

What belongs here

Belongs here Belongs in the knowledge base
The design permits a failure to be silent How to fix one occurrence of it
A documented rule is enforced by nothing A command that works around it
A stated invariant is false in practice A node-specific quirk
The owner is unknown and finding it needs the whole mesh in view Symptom → fix, once the answer is known

The knowledge base already holds the operational record and is indexed on symptoms. This folder is not a second copy of it. An issue here is a question HQ must answer; an entry there is an incident someone must clear. An issue whose answer is a general lesson belongs in both.

Structure

NNN-short-name/
  00-report.md      the symptom as observed, with the evidence; status in frontmatter
  01-diagnosis.md   the investigation trail, dated, including what was ruled out

Frontmatter, on 00-report.md

---
status: open | diagnosing | located | resolved | wontfix
opened: YYYY-MM-DD
located-in: []       # owning repo(s) or module(s), filled by diagnosis
fixed-by:            # pull request or commit reference, filled at resolution
amended-design:      # design doc path, when the root cause was a design gap
---

Rules

  • Anyone may open an issue. No localisation is required to report one.
  • The full flow is playbook 00-META/process/03-issues.md.
  • Closed issues are never deleted — they are the mesh's symptom-to-component memory.
  • wontfix is legitimate and requires a sentence saying why.