jschoubben 71f8012c5b The control plane as an ordinary module
novox/hq ADR 0067 pivots genesis through a temporary control plane and then
reinstalls the control plane as an ordinary module pinned to a digest the mesh's
own registry assigned. That record notes the one thing missing: a control-plane
module manifest, which did not exist.

It could not be written honestly before now. The control plane read its store
connection from MESH_STORE_<CONTEXT>, that connection string carries a password,
and a manifest can put a sealed value into a file's `content` but has nothing
that substitutes into a container's `env`. So the manifest could carry the
password in the clear, or omit the setting. mesh-control now also accepts
MESH_STORE_<CONTEXT>_FILE, which is how every other module here is given secret
material, and the manifest follows.

What the substrate bundle gives the control-plane container today, and where
each part has gone:

  MESH_STORE_INVENTORY   own-secret `inventory`, mounted, named by _FILE
  MESH_STORE_IDENTITY    own-secret `identity`,  mounted, named by _FILE
  MESH_STORE_LICENCES    own-secret `licences`,  mounted, named by _FILE
  MESH_BROKER_AMQP       own-secret `broker`, through an env-file hole
  MESH_BROKER_MANAGEMENT own-secret `broker-management`, likewise
  MESH_BROKER_ADDRESS    ${machine:at}:5671 in that same env-file
  MESH_BROKER_CERTIFICATE  plain env; the path is not a secret
  network host, args ["serve"], the broker's TLS volume  unchanged

The two broker URLs go through an env-file rather than a file of their own
because mesh-control has no MESH_BROKER_AMQP_FILE. That is the same fault one
layer over, and the same remedy would fix it; it is out of this change's scope
and is written down rather than papered over.

None of these values is in the manifest. Each is an own-secret the operator
supplies with `secret accept` — the mesh cannot invent a connection string — and
the container restarts when any of them changes.

The module claims `the-control-plane` at mesh scope, which the bundle has no way
to say: two control planes writing one inventory is a fault worth refusing at
assignment. It carries no `listens`, because `serve` dials the broker and binds
nothing. The image is the catalogue's placeholder digest for a mesh-built image,
which the installer replaces with what the registry assigned.

Checked with the real parser: all 67 manifests through catalogue.ParseManifest
and every module's CheckIdentity against all four node names — 0 problems — and
this manifest rendered through Resolution.Declaration, so the ${secret:…} names,
${machine:at}, the restart-on ids and the image pin are exercised rather than
merely parsed. Slug `control`: mesh_shanks_control is 19 of the 20 an S3 access
key keeps.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-10 23:43:07 +02:00

mesh-catalog

The Novox Mesh catalogue. The modules the mesh builds, provisions and runs — as manifests, one per module under modules/.

This is data, not a control-plane concern. The manifests describe what a module is: what it provides, what it requires, the seats it claims, the resources the host applies for it. The engine that reads them — parsing, eligibility resolution, sealing, declaration emission — lives in the control plane (novox/mesh-control, internal/catalogue), which consumes this repository as a build source. The host (novox/mesh-host) applies the declarations the control plane emits. Neither is here.

What a module is, and is not

A module is one thing the mesh can run, named once, described completely by its manifest. A manifest names its image (pinned by digest), the resources the host owns for it (directories, files, the container, the private network it joins), what it requires from a provider and what it provides to consumers, and the sealed secrets it needs filled on the machine.

  • Core mesh components are not modules. The node host, the substrate, the control-plane contexts and the surfaces are the mesh itself; they ship as their own repositories (mesh-host, mesh-substrate, mesh-control, mesh-surfaces, mesh-sdk), not from here.
  • Standalone applications are not here either. A larger application lives in its own repository with its manifest at the root, registered with the mesh as a build source (novox/hq ADR 0010). This repository holds the modules the mesh maintains as its shared catalogue; an application the mesh merely hosts keeps its manifest beside its own code.

So there is one home for the catalogue the mesh owns, and every application that runs on the mesh rather than being of it carries its own — both reach the pipeline the same way, as a registered source.

Layout

modules/<name>.json      one manifest per module

Flat, because the catalogue's shape carries no meaning: a module is found by its name and described by its manifest, and what relates two modules — a shared seat, a claim, a provider/consumer edge — is data inside the manifests, not a directory the tree encodes (novox/hq, the domain-grouping question closed in favour of seats, claims and tags).

The manifest contract

The shape a manifest must satisfy is owned by the control plane's catalogue engine and is what validates a manifest before a machine ever sees it — a stray key, a consumer contributing the wrong provision field, an image that nothing builds. That validation belongs with this repository and is being re-homed here from mesh-control; until it is, the pipeline is the gate — it builds each module and refuses a manifest it cannot resolve.

Where the reasoning lives

Design and decisions are in novox/hq:

  • 02-DECISIONS/0002-everything-is-a-module.md — one unit, no second mechanism
  • 02-DECISIONS/0010-applications-live-in-their-own-repository.md — why applications are not here
  • 02-DECISIONS/0030-the-repository-structure.md — the repositories, and the open tier-4 question this repository answers
  • 03-DESIGN/00-as-is/10-module-catalogue.md — the catalogue's shape, and what it records
S
Description
Novox Mesh — the catalogue. Module manifests the mesh builds, provisions and runs. Data, not a control-plane concern.
Readme
1.4 MiB
Languages
TypeScript 89.4%
Dockerfile 9.6%
Shell 1%