Settles the design repository now that the self-upgrade build is on main: - Records the two decisions that shipped without a record — ADR 0077 (the controller/foundation/node vocabulary) and ADR 0078 (the store and broker are ordinary modules); accepts ADR 0075 and 0076, which shipped work rests on. - Fills issue 051's amended-design and wires ADR 0078 into 07-the-foundation. - Sweeps the repo rename (mesh-control -> mesh-controller) into the mutable docs now that the forge repo is renamed; updates the glossary note and repos.md. - Fixes the six broken links from the design-doc renames, indexes the glossary, regenerates the decisions reading order. Both checks (records.py, index.py) are green. Statuses stay honest: the build is on main and lab-proven but not deployed as the production mesh, so the to-be docs remain in-progress and the as-is layer (the hal mesh) is unchanged — graduation to implemented + as-is belongs to deployment, not merge. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
73 lines
3.4 KiB
Markdown
73 lines
3.4 KiB
Markdown
---
|
|
topic: the tiers
|
|
status: accepted
|
|
date: 2026-08-31
|
|
deciders: jochen
|
|
reconstructed: false
|
|
extends: 02-DECISIONS/0006-the-substrate-and-the-control-plane.md
|
|
---
|
|
|
|
# 31. The control plane authenticates nobody, so identity is a module
|
|
|
|
## Context
|
|
|
|
[ADR 0006](0006-the-substrate-and-the-control-plane.md) left one member of the substrate
|
|
conditional, and said exactly why:
|
|
|
|
| role | product | |
|
|
|---|---|---|
|
|
| identity provider | — | **conditional**: substrate only if the control plane delegates authentication, which is undecided |
|
|
|
|
[`07-the-foundation.md`](../03-DESIGN/01-to-be/07-the-foundation.md) carried it as an open question —
|
|
*whether identity is the fifth* — noting it followed from a decision nobody had taken.
|
|
|
|
**The decision is taken: the control plane does not delegate authentication.** There is no mesh
|
|
identity provider.
|
|
|
|
**Nothing in the mesh's own machinery ever needed one.** A node proves itself with a keypair it
|
|
generated, over a broker account issued at enrolment
|
|
([ADR 0004](0004-a-node-and-how-it-joins.md)). Declarations are verified by signature. None of
|
|
that touches an identity provider, and the conditional was never about machines — it was only ever
|
|
about whether a *person* signing in to a mesh surface would be authenticated by something else.
|
|
|
|
## Decision
|
|
|
|
**Identity is a module**, like the mail system and the forge. It runs *on* the mesh, not *of* it
|
|
([ADR 0001](0001-mesh-brokers-nodes-host-agents-think.md)) — a provider other modules require,
|
|
which is the ordinary shape and needs nothing new to express.
|
|
|
|
**So the substrate is three, and no longer conditional**: a relational store, a message bus, and
|
|
an image registry. Together with
|
|
[ADR 0028](0028-the-substrate-supplies-the-control-plane-and-nothing-else.md), which removed the
|
|
object store, the list is settled and every member is there for the same reason — the control
|
|
plane needs it and cannot ask itself for it.
|
|
|
|
**A mesh that wants no identity provider runs none.** That is now expressible, and was not while
|
|
it sat in the substrate as a maybe.
|
|
|
|
## Consequences
|
|
|
|
**The last open question about substrate membership is closed.** Both halves of ADR 0006's test
|
|
now have an answer for every candidate, and the answer for identity is *the control plane does not
|
|
need it*.
|
|
|
|
**It does not settle how a person signs in to a mesh surface**, and that is deliberately left
|
|
open. What is settled is that whatever answers it is not part of what must exist before the mesh
|
|
does — so it can be decided late, changed, or replaced, which is precisely what being substrate
|
|
would have prevented.
|
|
|
|
**It becomes a real test of the module graph.** An identity provider is a module that *other
|
|
modules require* — the object store already consumes it — so it exercises the provider chain more
|
|
seriously than anything ported so far, where the provider was written alongside its consumer.
|
|
|
|
**Ordering follows from it rather than from preference.** Anything requiring identity has to move
|
|
after it, which is a dependency the graph can state rather than something a person has to
|
|
remember.
|
|
|
|
## References
|
|
|
|
- [ADR 0006](0006-the-substrate-and-the-control-plane.md) — the conditional this closes
|
|
- [ADR 0028](0028-the-substrate-supplies-the-control-plane-and-nothing-else.md) — the other member
|
|
removed, and the test applied properly
|
|
- [ADR 0004](0004-a-node-and-how-it-joins.md) — how a node proves itself, which needs none of this
|