Name system seats by scope; let a module define its own (ADR 0121)

System seats are mesh-* (one, mesh-wide) or node-* (one per node). Renamed:
the-build-machine -> mesh-build-machine (+scope mesh), the-catalogue ->
mesh-catalog, the-dns-port -> node-dns-resolver, the-intrusion-prevention ->
node-intrusion-prevention, the-packet-filter -> node-packet-filter,
the-resolver-configuration -> node-resolver-config, the-uplink -> node-uplink.
Removed the-showcase from the set — it becomes the first module-defined seat.

A manifest may declare its own seats (DefinesSeats); a claim is a system seat,
a reserved mesh-*/node-* name the mesh does not define (refused), or a
module-defined seat valid only when the manifest declares it.

Deferred: the delivering registry seats (git, npm-package-registry,
the-artifact-store) and the-private-network (a scope + server/client model
change), per ADR 0121.
This commit is contained in:
2026-09-27 14:30:56 +02:00
parent a6d89e3f73
commit 1c56210530
5 changed files with 105 additions and 34 deletions
+8
View File
@@ -192,6 +192,14 @@ type Manifest struct {
// that every new module would force its predecessors to update.
Claims []Claim `json:"claims,omitempty"`
// DefinesSeats are the seats this module defines for itself (novox/hq ADR 0121). The control
// plane defines the system seats — `mesh-*` and `node-*` — and a module may define its own,
// named outside that namespace, to coordinate its own instances: the mesh enforces
// one-holder-per-scope for it without knowing what it means. A module's declared seat is the
// only non-system name it may then claim; a claim to a name neither the mesh nor the module
// defines is refused.
DefinesSeats []Claim `json:"seats,omitempty"`
// Capabilities the machine must have. A different field from Requires because the remedy
// differs: a missing module can be assigned, and a missing capability means the wrong
// machine.