Name the two modules after their software: nftables and distribution

A module's identity is the software it is (ADR 0040). Two were named after the
job instead, and the job already had a name.

firewall installs the nftables package and runs nftables.service. The seat it
claims is the-packet-filter, which is correctly named for the role. Calling the
module firewall named neither the software nor the provision, and promised that
any firewall could sit there — the false genericity the naming rule forbids.

registry runs Distribution, the OCI reference implementation, and provides
artifact-store. So registry was a third name for a thing that already had two,
which is how one word ended up meaning the module, the software and the concept
in the same paragraph.

The capability stays firewall, and correctly: a capability IS a functionality, so
a node having one and fail2ban requiring one are both right. Only the module
moves.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-15 20:51:00 +02:00
parent bf1f67a485
commit 71bbc7dab0
12 changed files with 3 additions and 3 deletions
+51
View File
@@ -0,0 +1,51 @@
// registry's events. The tool runtime imports this once the broker is bound.
//
// Emits (novox/hq ADR 0041/0042):
// module.registry.image.pushed — a new image (repo:tag) was published to the registry
//
// This is a genuinely useful signal: a build finished and its image is now pullable, so anything
// on the mesh that redeploys, mirrors or announces releases can react without polling the registry
// itself. It is discovered by diffing the catalog and each repo's tags — the registry has no push
// webhook of its own, so the module watches for it.
//
// The polling is deliberately unhurried: a new image a minute late is still the event, whereas
// hammering the registry's catalog for immediacy nobody asked for is not.
import { emit } from "@novox/mesh-sdk/events";
import { RegistryClient } from "./client.js";
const registry = RegistryClient.fromEnv();
// Every repo:tag we have already accounted for. Primed silently on the first look so a registry
// that was already full when this started does not announce its whole history as freshly pushed.
const seen = new Set<string>();
let primed = false;
async function pollCatalog(): Promise<void> {
const repos = await registry.listRepositories();
for (const repo of repos) {
let tags: string[];
try {
tags = await registry.listTags(repo);
} catch {
continue; // a repo can vanish between catalog and tag read — skip it, catch it next tick
}
for (const tag of tags) {
const id = `${repo}:${tag}`;
if (!seen.has(id)) {
if (primed) await emit("module.registry.image.pushed", { repo, tag });
seen.add(id);
}
}
}
primed = true;
}
const tick = (fn: () => Promise<void>, everyMs: number): void => {
const run = (): void => void fn().catch((err) => console.error(`[registry] ${err}`));
setInterval(run, everyMs);
run();
};
tick(pollCatalog, 60_000);
console.log("[registry] watching the catalog for newly pushed images");