Networking is a module, and a domain module is how you avoid choosing

Connectivity was code beside the module system doing the module system's
job: every machine with an address was on the private network and there
was no way to keep one off.

A manifest can now say its resources are computed by the control plane,
which is what a peer list needs — it is derived from every machine at
once, so nothing could be written in advance. The network is a module
from there on: assigned, resolved, settled, and absent from a machine
nobody gave it to.

Three modules rather than one, because WireGuard is one VPN of several:

  mesh-wireguard   provides private-network, mesh-addressing
                   claims the-private-network, one per node
  mesh-names       provides name-resolution, requires mesh-addressing
  networking       requires both, and ships no files of its own

The last is the point. Most people want the network up and do not want
to choose a VPN, so `assign networking` takes the only answer to each
requirement silently. The day the catalogue holds a second one there are
two answers, the resolver refuses and names them, and choosing is
assigning the one you want. No flavor field, nothing to configure.

Names left the WireGuard declaration for their own module. They would be
identical over a different private network, and bundling them made one
module out of two things.

Three faults the walk found:

- choosing tailscale still installed WireGuard, dragged back in by the
  names needing the mesh's own addresses. Caught now by a claim: running
  two VPNs is fine, being *the* mesh network is singular.
- a requirement wanted by two modules was reported twice, identically.
- "this mesh has no hub" was reported when the real cause was that a
  node could not be resolved at all. It now names the node and the why.

And a test that asserts the manifests actually shipped, after the claim
went missing from the real one while every test stayed green.
This commit is contained in:
2026-08-29 23:19:32 +02:00
parent 65ade756f2
commit 44d134ba25
12 changed files with 940 additions and 53 deletions
+6 -13
View File
@@ -34,7 +34,7 @@ type Resource map[string]any
// Three resources and nothing clever: the tools, the configuration, and the interface running. A
// person can read it, which is the point — this is the first thing a node is ever told, and if it
// is wrong the node is unreachable and the mistake has to be findable by eye.
func Declaration(node Node, peers []Peer, everyone []Node, keyPath string) ([]byte, error) {
func Declaration(node Node, peers []Peer, keyPath string) ([]byte, error) {
if node.Address == "" {
return nil, fmt.Errorf("%s has no address on the overlay, so there is nothing to configure",
node.Name)
@@ -78,18 +78,11 @@ func Declaration(node Node, peers []Peer, everyone []Node, keyPath string) ([]by
},
}
// And the names, which come from the same graph and arrive in the same declaration. Separate
// steps in the design and one delivery in practice: a node that had the peers and not the
// names, or the reverse, would be half on the network for as long as that lasted.
names, err := Hosts(everyone, node.Name)
if err != nil {
return nil, err
}
resources = append(resources, Resource{
"id": "mesh-names", "type": "file", "path": HostsPath,
"mode": "0644", "content": names,
})
// The names used to be appended here, on the argument that a node with peers and no names is
// half on the network. True, and the wrong place to fix it: names would be identical over a
// different private network, so bundling them with WireGuard made one module out of two
// things. They are their own module now, requiring this one — which is what keeps them
// arriving together without pretending they are the same concern.
return json.Marshal(map[string]any{"declaration": 1, "resources": resources})
}