zsh and systemd: the first two modules of the operator's machine (hq to-be 37) #224

Open
mesh-admin wants to merge 2 commits from feat/the-operators-machine into main
Contributor

The first two modules of novox/hq to-be 37, under ADR 0173–0177. Depends on hq #293, mesh-controller (the seat and the name/user placeholders) and mesh-host (user-scoped units) PRs of the same branch name.

zsh — a package; the mesh's default ~/.zshrc as a block inside the account's file (into: block, path ${machine:account-home}/.zshrc, owner ${machine:account}), so the operator's own lines around it survive every push (ADR 0174 as the host realises it); a user shape that makes zsh the account's login shell; the login-shell seat declared with its one verb; a tools bundle with execute under the seat's name and zsh_config under the module's (ADR 0176). No container, no process.

systemd — claims node-service-manager and serves its eight verbs over both scopes, reaching the account's manager as systemctl --user --machine=<account>@ when the runtime is not that account; one own tool, systemd_failed (ADR 0177). No container, no process.

Both pass module check against a controller carrying the seat, and their tools type-check against the SDK. Neither can serve yet: their tools wait on the node tools runtime (ADR 0175), which is the next piece — the bundles build and the manifests register ahead of it. Two things the manifests cannot say and the controller does not yet do: the user shape applies wherever zsh is assigned rather than only where it holds the seat, and the runtime learns the account from MESH_OPERATOR_ACCOUNT, which nothing sets yet.

Do not assign until the runtime exists and the operator account is stated on the nodes.

The first two modules of novox/hq to-be 37, under ADR 0173–0177. Depends on hq #293, mesh-controller (the seat and the `name`/`user` placeholders) and mesh-host (user-scoped units) PRs of the same branch name. **`zsh`** — a package; the mesh's default `~/.zshrc` as a block inside the account's file (`into: block`, path `${machine:account-home}/.zshrc`, owner `${machine:account}`), so the operator's own lines around it survive every push (ADR 0174 as the host realises it); a `user` shape that makes zsh the account's login shell; the `login-shell` seat declared with its one verb; a tools bundle with `execute` under the seat's name and `zsh_config` under the module's (ADR 0176). No container, no process. **`systemd`** — claims `node-service-manager` and serves its eight verbs over both scopes, reaching the account's manager as `systemctl --user --machine=<account>@` when the runtime is not that account; one own tool, `systemd_failed` (ADR 0177). No container, no process. **Both** pass `module check` against a controller carrying the seat, and their tools type-check against the SDK. Neither can serve yet: their tools wait on the node tools runtime (ADR 0175), which is the next piece — the bundles build and the manifests register ahead of it. Two things the manifests cannot say and the controller does not yet do: the `user` shape applies wherever `zsh` is assigned rather than only where it holds the seat, and the runtime learns the account from `MESH_OPERATOR_ACCOUNT`, which nothing sets yet. **Do not assign** until the runtime exists and the operator account is stated on the nodes.
mesh-admin added 2 commits 2026-10-02 14:48:45 +00:00
The first module of the operator's environment (novox/hq to-be 37 §1, ADR 0173,
0176). A package, the mesh's default configuration as a block inside the
account's ~/.zshrc so the operator's own lines around it survive every push
(ADR 0174 as the host's `into: block` realises it), a `user` shape that makes
zsh the account's login shell, the `login-shell` seat declared with its one
verb, and a tools bundle: `execute` under the seat's name, `zsh_config` under
the module's. No container, no process: the tools are served by the node tools
runtime (ADR 0175), which does not exist yet — the bundle builds and the
manifest registers ahead of it. `module check` passes; the tools type-check
against the SDK.

Two things the manifest cannot yet say, left for the controller: the `user`
shape applies wherever the module is assigned, not only where it holds the
seat; and the runtime learns the account from MESH_OPERATOR_ACCOUNT, which
nothing sets yet.
The holder of the seat the controller seeds under novox/hq ADR 0177. Eight
verbs under the seat's name — units, status, start, stop, restart, enable,
disable, journal — each taking an optional scope, "system" by default or
"user" for the operator account's own manager, reached as
`systemctl --user --machine=<account>@` when the runtime is not that account.
One tool of its own, systemd_failed, for every failed unit in both scopes.
A package, a claim and a bundle; no container, no process: served by the node
tools runtime (ADR 0175) once it exists. `module check` passes against a
controller that carries the seat; the tools type-check against the SDK.
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/the-operators-machine:feat/the-operators-machine
git checkout feat/the-operators-machine
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#224