Commit Graph
801 Commits
Author SHA1 Message Date
jschoubben 1a03caf8a5 The store collects nightly again (hq ADR 0189)
Withdrawn 2026-10-04 to unblock novox: while-stopped named the module-local
id and the host refuses a declaration naming a container it does not have,
whole. mesh-controller#259 fixed the namespacing and it has been live since,
so the window composes as distribution.store and the host will take it.

Unchanged from before: plain garbage-collect at 03:30 with the server held
still. The store is at 40G and nothing reclaims it until this runs.
2026-10-05 14:33:14 +02:00
mesh-admin 54ba97f901 Merge pull request 'claude-code: register the agent's configuration at three scopes, served as the nox-mesh plugin (hq ADR 0216)' (#52) from feat/nox-mesh-plugin into main 2026-10-05 12:30:10 +00:00
jochen 92f78db970 claude-code: act on the review of the nox-mesh plugin
Refuse paths with empty, dot or parent segments and a file that is also a
directory; take an item only when its key says what it is; write the view
under its lock; expand nodes all and check node names; merge the plugin's
entries into the operator's own; render every file past one that fails;
in the home, never take over the person's file, never write through a
symbolic link, keep a deleted file deleted, keep the kind's directory; and
refuse settings that would deny the console or the marketplace.
2026-10-05 14:29:53 +02:00
jochen 1d8f1ceff8 claude-code: drop what was removed while away, render one at a time, refuse an empty settings set
Review of the nox-mesh plugin: a watch hands over what is there, not what
went, so the view is pruned to the state's keys before it starts; the
watches and the tools render one at a time, as the home's record is read
and written whole; the register answer names how an item is offered.
2026-10-05 14:25:10 +02:00
jschoubben 83bd2afe66 Merge pull request 'restic: restore a single kept file, not only a directory' (#56) from fix/restore-a-file into main 2026-10-05 12:22:17 +00:00
jschoubben 46e3a5a6b7 restic: restore a single kept file, not only a directory
The first restore of an arr app refused its settings file with "not a directory": restic restores
a snapshot's subfolder, not a file. A file is restored with its full path into a scratch directory
beside the target, moved into place, and the scratch removed.
2026-10-05 14:05:52 +02:00
jschoubben d67e786bf9 Merge pull request 'restic: declare sqlite, the tool SQLite stores are copied with' (#55) from feat/arr-backups into main 2026-10-05 11:49:35 +00:00
jschoubben 7786507d45 restic: declare sqlite, the tool SQLite stores are copied with
The arr apps keep SQLite databases; a consistent copy of a live one is sqlite3's .backup. Declared
once, by the holder that runs the copies, rather than by each app.
2026-10-05 13:39:55 +02:00
jschoubben a70227a40a Merge pull request 'restic: ask as root whether a directory is there' (#54) from fix/backup-sees-as-root into main 2026-10-05 10:38:25 +00:00
jschoubben 08c7a79f79 restic: ask as root whether a directory is there
The first run on the control node called postgres's dumps missing: the holder looked as the
runtime's account, which cannot see inside a store's 0700 data directory. Every other act already
runs as root; the existence checks do too now.
2026-10-05 12:31:07 +02:00
jschoubben d9120c6848 Merge pull request 'fail2ban: its tools in Go' (#53) from feat/fail2ban-in-go into main 2026-10-05 10:24:17 +00:00
jschoubben 96ee0d7ad6 Merge pull request 'Back up every store: the restic module and the stores' contributions (hq ADR 0214, to-be 43)' (#49) from feat/node-backup into main 2026-10-05 10:13:48 +00:00
jschoubben d43de93e49 fail2ban: its tools in Go
Go is the default for module code. One binary, fail2ban-tools, serving the node-intrusion-prevention
seat's four verbs and fail2ban_settings over the SDK, with the same parsing and the same tests; read
back against the control node's live daemon.
2026-10-05 12:01:25 +02:00
jschoubben 3a88bca21a restic: the holder in Go
Go is the default for new module code; the holder is one binary like the licence manager, serving
the seat's verbs over the SDK and running the nights beside them. Same behaviour and tests.
2026-10-05 11:58:18 +02:00
jochen dd1035a27d claude-code: register the agent's configuration at three scopes, served as the nox-mesh plugin
Skills, subagents, commands and hooks had no machine-wide place, so they were
copied into homes by hand and drifted. Each is now registered once through the
module's tools, kept in its config state, and written per node: the plugin in
the managed directory, settings and instructions in the managed files, or the
account's own directory, touching only what the module placed. hq ADR 0216.
2026-10-05 11:57:35 +02:00
mesh-admin 37bb53ab95 Merge pull request 'xdg: the account's folders and the machine's default applications' (#50) from feat/xdg-module into main 2026-10-05 09:53:30 +00:00
mesh-admin 45f27eb300 Merge pull request 'dbus: hold node-message-bus, and never restart the bus live (hq ADR 0215)' (#51) from feat/dbus-module into main 2026-10-05 09:52:32 +00:00
jochen 7b5e1d3362 dbus: hold node-message-bus, and never restart the bus live (hq ADR 0215)
A live restart of the system bus during an upgrade hung every login on a
workstation until a reboot. The module owns the bus's packages, declares
the bus running with no restart or reload trigger, publishes only curated
events (health, services, denials; never traffic) and serves tools to look
at both buses.
2026-10-05 11:50:52 +02:00
jochen 785d32407b xdg: own the account's folders and the machine's default applications
The workstations' XDG conventions had no owner: xdg-user-dirs-update rewrote
the folders file at every login, both machines' default-application lists
named an editor neither has, and the laptop kept two dead links of the
retired predecessor. The module adopts the operator's folders (three as
settings, as the machines differ), disables the update so it cannot undo the
mesh's file, and writes the machine's own mimeapps list, the last one read,
so the person's choices in their own list always win. Autostart is listed,
not owned: each entry is its application's module's.
2026-10-05 11:50:34 +02:00
mesh-admin 170b3296e9 Merge pull request 'nextcloud-client and blueman: the two tray apps as modules, each with one start' (#48) from feat/nextcloud-client-and-blueman into main 2026-10-05 09:48:43 +00:00
jschoubben 32cd92baeb Back up every store: the restic module holds node-backup, the stores contribute their dumps
ADR 0214 / to-be 43. restic keeps one repository per machine and takes a nightly snapshot per
module — 14 daily, 8 weekly, 6 monthly — and restores beside the live data, never over it. postgres,
mssql and mongodb contribute a consistent dump; minio, influxdb, the vault, mailu, gitea and
nextcloud the directories that hold their data.
2026-10-05 11:47:59 +02:00
jochen 9582208984 Add nextcloud-client and blueman: the two tray apps get an owner and tools, each with one start
Both are official packages already on both workstations, started once by dex from an XDG
autostart entry (the client's own, the package's). The modules declare the package, add no
second start, own none of the apps' files, and give the mesh status, log, restart and check.
2026-10-05 11:47:38 +02:00
mesh-admin 4224ac7252 Merge pull request 'i3: other modules' lines are contributions to node-display-session (hq ADR 0212)' (#47) from feat/i3-fragments-as-contributions into main 2026-10-05 08:11:45 +00:00
jochen 1d4de00603 i3: other modules' lines are contributions to node-display-session (hq ADR 0212)
rofi, clipmenu, feh, i3status-rust and the laptop's model module wrote files into i3's config.d,
naming no dependency on the window manager. They now contribute their lines; i3 places them under a
line naming each module, and config.d is the operator's alone. The catalogue-wide test composes the
contributions as the controller does and checks the whole with i3 -C.
2026-10-05 10:11:27 +02:00
mesh-admin 7047198146 Merge pull request 'power: a lock problem is no longer said once the lock is held' (#46) from fix/power-clears-a-solved-problem into main 2026-10-05 08:03:44 +00:00
jochen 815a55a9fd power: a lock problem is no longer said once the lock is held 2026-10-05 10:03:30 +02:00
mesh-admin a3c8086d52 Merge pull request 'Apply a binding that differs, and never repeat a generation a node passed (hq issue 243)' (#45) from fix/a-reset-generation-silences-no-node into main 2026-10-05 08:01:12 +00:00
jochen b91b4c427d Apply a binding that differs, and never repeat a generation a node passed
A licence store rebuilt after issue 241 counted generations from one again,
and nodes that apply only a higher number discarded the login move and the
rotations unseen. Nodes now apply any binding other than the one applied;
the manager moves its sequence past every generation a node reports. hq
issue 243.
2026-10-05 09:59:19 +02:00
jschoubben 316576f1da Merge pull request 'A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)' (#44) from fix/a-withdrawn-consumer-keeps-its-data into main 2026-10-04 23:45:16 +00:00
jschoubben 1fb7ca3d72 A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)
mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket,
mailu disables the mailbox, gitea prohibits the login instead of purging the user and their
repositories, umami keeps the website. Each provider's create already enables what this locks.
2026-10-05 00:34:40 +02:00
jschoubben 190d711a2a postgres: a withdrawn consumer keeps its database; retiring renames, never drops (hq issue 241) 2026-10-05 00:33:12 +02:00
mesh-admin 9275a9e295 Merge pull request 'power: polkit is the module's package' (#289) from fix/power-needs-polkit into main 2026-10-04 15:53:42 +00:00
jochen d26eb1d9a6 power: polkit is the module's package; without it logind refused the watcher its delay lock on a server 2026-10-04 17:53:31 +02:00
mesh-admin 6c73848ba1 Merge pull request 'power: the watcher checks its lock is logind's, and takes it again when it is not' (#288) from fix/power-watcher-verifies-its-lock into main 2026-10-04 15:49:31 +00:00
jochen 94d0caa09c power: the watcher checks its lock is logind's, and takes it again when it is not
On one server the watcher reported a lock that logind did not list. A descriptor that is not an
inhibitor reference is never wrapped (0 would be the bundle's stdin, its channel to the runtime), and
every poll checks the lock is still held, taking it again and saying why when it is not.
2026-10-04 17:49:19 +02:00
mesh-admin 5f8869b165 Merge pull request 'power: the supply rule matches only the charger' (#287) from fix/power-supply-rule-only-the-charger into main 2026-10-04 15:44:46 +00:00
jochen 91f69d1dd3 power: the supply rule matches only the charger; the battery's level changes started the unit every second 2026-10-04 17:44:30 +02:00
mesh-admin 1ace62b969 Merge pull request 'claude-code: let the operator set the agent's managed settings' (#286) from feat/claude-code-agent-settings into main 2026-10-04 15:34:08 +00:00
jochen 8067e91409 Let the operator set the agent's managed settings through claude-code
managed-settings.json carried only the mesh's fixed keys, so permissions and
auto-mode rules could only be set by hand per machine, outside the mesh.
A managed_settings setting is laid under the mesh's keys, which still win.
2026-10-04 17:31:20 +02:00
mesh-admin bd22b53672 Merge pull request 'power: the sleep hooks are wanted by the sleep targets, not declared as services' (#285) from fix/power-sleep-hooks-wanted-by-the-targets into main 2026-10-04 15:22:48 +00:00
jochen ac1a6fca38 power: the sleep hooks are wanted by the sleep targets, not declared as services
The host reads a one-shot that is not running as having run, so a before-sleep or after-wake unit
declared stopped failed on its first apply; drop-ins on the sleep targets pull them in instead.
2026-10-04 17:22:35 +02:00
mesh-admin fee36954e5 Merge pull request 'power: a machine's power as a module holding node-power (hq ADR 0211)' (#284) from feat/power-module into main 2026-10-04 15:19:44 +00:00
jochen 6315556152 power: a machine's power as a module holding node-power; the laptop's resume and lid move onto it (hq ADR 0211)
Code around sleep was written into the service manager's sleep units by the module that needed it,
and the mesh could not tell a sleeping machine from a lost one. power runs every module's code for
the six moments, each piece bounded, owns logind's power handling from its settings, and says
booted, sleeping, woke, shutting-down and the power source on the bus, sleeping under logind's
delay lock before the machine sleeps.
2026-10-04 17:19:27 +02:00
jochen 791d0f62ce WIP: power module (in progress) 2026-10-04 17:14:44 +02:00
mesh-admin a831087a02 Merge pull request 'screen-lock: recognise i3lock-color by its version scheme' (#283) from fix/screen-lock-detects-the-colour-build into main 2026-10-04 15:07:50 +00:00
jochen ba96c59c50 screen-lock: recognise the colour build by its version scheme; its version line never says color 2026-10-04 17:07:40 +02:00
mesh-admin 5443223842 Merge pull request 'screen-lock: keep the operator's lock screen (i3lock-color: blur, ring, clock)' (#282) from fix/screen-lock-keeps-the-operators-look into main 2026-10-04 15:06:10 +00:00
jochen 3c832f3f06 screen-lock: the operator's lock screen is kept, i3lock-color with its blur, ring and clock
The first version swapped the colour build for the distribution's plain i3lock and locked to black;
adopting means keeping what the operator had. Plain i3lock remains the fallback, with a blurred
screenshot of its own.
2026-10-04 17:05:58 +02:00
jschoubben 7aaf784bb5 Merge pull request 'Remove the catalogue's photos: the app's own repository defines it' (#278) from fix/photos-lives-in-its-own-repository into main 2026-10-04 15:05:31 +00:00
mesh-admin 8b97cc9b41 Merge pull request 'Bind the bus's monitoring inside its container, published on the machine's loopback alone' (#281) from fix/nats-monitoring-on-the-machines-loopback into main 2026-10-04 14:53:24 +00:00