Merge main: the trunk renamed the seats and made them data
Both branches changed the seat set from the same starting point, so every number collided and every `mesh-*` name existed twice. The trunk's numbers and names win: this branch's records became 0129/0130 and its migrations 0037/0038, and the hardcoded rename map gave way to the trunk's `seat_alias` table — a rename is a row now (ADR 0122), not a recompile. Three of my checks were wrong and the merge is what showed it: A seat with an empty protocol is a marker, not an incomplete declaration. Most node-scoped seats are markers — which module is this machine's packet filter — and refusing one refused most of the set, the showcase module included. A mistyped field name is already refused by the parser, so an empty protocol was written as one deliberately. A claim on a seat this manifest does not declare is not the parser's to judge. A module may hold a seat another module declared; that is the whole reason ADR 0126 has callers name the seat and not its provider. Whether the seat exists is a fact about the catalogue, so the refusal is at registration, where every declaration is in view. And a seat may share a name with the provision it delivers. `git`, the npm registry and the artifact store still do, because renaming a delivering seat cascades to every consumer requiring it, with a window where a holder stops resolving mid-flight. The trunk deferred exactly those three on purpose. Full suite green against a real NATS and store.
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
-- A carried peer may be named before it enrols (novox/hq issue 112).
|
||||
--
|
||||
-- The tunnel the hub took over routes to machines the predecessor knows by name and the mesh
|
||||
-- knows only by address. A name the predecessor answers for must keep resolving until the
|
||||
-- machine behind it is a node — so the operator may state which machine a carried address is,
|
||||
-- and everything derived from "the machines the mesh knows" (a container's hosts, the hosts
|
||||
-- fact, the resolver) answers for it in the meantime. The mesh records the statement as the
|
||||
-- operator's, unverified: enrolment is what verifies it, and enrolling under a different name
|
||||
-- than the one stated is refused rather than silently renamed.
|
||||
alter table tunnel_peer add column named text;
|
||||
@@ -0,0 +1,17 @@
|
||||
-- The seats are data the control plane owns, not a slice compiled into it (novox/hq ADR 0122).
|
||||
--
|
||||
-- Until this, the closed set 0110 defines lived only as a Go slice, referenced by name everywhere,
|
||||
-- so renaming a seat or adding one meant a controller rebuild and a mesh-wide, freeze-prone deploy.
|
||||
-- The set is now a table: one row per seat, seeded from the binary's defaults the first time the
|
||||
-- control plane comes up, and thereafter the live copy the control plane reads and an operator can
|
||||
-- change. A rename becomes an update here rather than a release.
|
||||
--
|
||||
-- The name is the key for now, because claims and held records still reference a seat by name; the
|
||||
-- move to a stable id that a rename does not touch is the next step (ADR 0122). `delivers` is empty
|
||||
-- for a seat that answers for no provision, matching the compiled default.
|
||||
create table seat (
|
||||
name text primary key,
|
||||
scope text not null,
|
||||
delivers text not null default '',
|
||||
decided text not null
|
||||
);
|
||||
@@ -0,0 +1,12 @@
|
||||
-- A seat keeps its former names, so a rename breaks nothing (novox/hq ADR 0122).
|
||||
--
|
||||
-- Phase 1 made the seat set data, but a rename still broke every reference to the old name — a
|
||||
-- manifest's claim, a held record, the git-seat lookup — because they name the seat and the name
|
||||
-- had changed. This is the stable identity ADR 0122 asked for, realised the simple way: a seat's
|
||||
-- canonical name changes, and its old name becomes an alias that resolves to it forever. Nothing
|
||||
-- downstream has to change — a manifest goes on claiming the old name, the build machine goes on
|
||||
-- validating it — and a rename is one operation: set the new name, remember the old.
|
||||
create table seat_alias (
|
||||
alias text primary key, -- a former name of a seat
|
||||
seat text not null -- the seat's current canonical name it resolves to
|
||||
);
|
||||
@@ -0,0 +1,13 @@
|
||||
-- A node has an operator account: the human login on it (novox/hq to-be 29).
|
||||
--
|
||||
-- The mesh modelled the machine but not the person on it — `jochens` on novox, `ace` on ace,
|
||||
-- `jochen` on shanks and g14. That name decides who a file under a home is owned by and which
|
||||
-- account `ssh <node>` logs in as; it was silently lost when the predecessor's per-node `user:`
|
||||
-- was not carried over, and `ssh ace` failed to `ace` because nothing here said so.
|
||||
--
|
||||
-- Empty rather than null and defaulted, because "no operator account known yet" is a real state
|
||||
-- (a freshly enrolled machine, a headless box). The home is stored too rather than always assumed
|
||||
-- to be /home/<account>, because root's is /root and a machine may put a home elsewhere; empty
|
||||
-- means "derive it" (/root for root, /home/<account> otherwise), so the common case needs no entry.
|
||||
alter table node add column account text not null default '';
|
||||
alter table node add column account_home text not null default '';
|
||||
Reference in New Issue
Block a user