Resync hq ADR references 0044-0054 -> 0039-0049 after the hq record reconciliation

This commit is contained in:
2026-09-05 12:47:13 +02:00
parent 5541949b59
commit 87c193b202
12 changed files with 28 additions and 28 deletions
+2 -2
View File
@@ -61,7 +61,7 @@ type Grant struct {
Values map[string]any
// Slug is the consumer module's identity slug, if it declared one — carried on the grant so the
// provider side derives the same login the consumer does, even across nodes where the consumer's
// manifest is not in view (novox/hq ADR 0054). Empty means "use the module name".
// manifest is not in view (novox/hq ADR 0049). Empty means "use the module name".
Slug string
// At is where the consuming machine is on the private network, empty if it is not on one.
//
@@ -143,7 +143,7 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
// Once, from every module's listens -- not per module. A module receiving only its own ports
// would write a rule set that closed every other module on the machine. Each module's per-node
// exposure settings override its listens' source first (novox/hq ADR 0051).
// exposure settings override its listens' source first (novox/hq ADR 0046).
exposure := map[string]map[int]string{}
for _, m := range r.Modules {
e, err := Exposure(m, with.Settings[m.Module])
+3 -3
View File
@@ -73,7 +73,7 @@ func (r Resolution) Filtering(computed map[string]Generator, ports map[string]ma
}
// The source, with any per-node exposure setting applied. The override names the port
// the module declares, so it travels with that port to wherever the machine publishes
// it (novox/hq ADR 0051): the same module is internal on one node and public on another.
// it (novox/hq ADR 0046): the same module is internal on one node and public on another.
from := l.From
if override, set := exposure[m.Module][l.Port]; set {
from = override
@@ -108,7 +108,7 @@ func (r Resolution) Filtering(computed map[string]Generator, ports map[string]ma
return widest(out), nil
}
// ExposeSetting is the settings key that overrides a listen's source per node (novox/hq ADR 0051):
// ExposeSetting is the settings key that overrides a listen's source per node (novox/hq ADR 0046):
//
// {"expose": {"5432": "anywhere"}}
//
@@ -122,7 +122,7 @@ const ExposeSetting = "expose"
// It refuses an override for a port the module does not listen on, or to a source that is not a
// real one — an exposure setting that reaches no port, or names a source nothing enforces, is the
// "reads as a restriction and is none" fault this whole mechanism exists to prevent (novox/hq
// ADR 0048/0050). A module with no `expose` setting yields nothing and keeps its manifest defaults.
// ADR 0043/0045). A module with no `expose` setting yields nothing and keeps its manifest defaults.
func Exposure(m Manifest, layers []Layer) (map[int]string, error) {
listened := make(map[int]bool, len(m.Listens))
for _, l := range m.Listens {
+2 -2
View File
@@ -580,7 +580,7 @@ func named(r Resolution) []string {
}
// A port's source is a per-node setting, not a manifest constant: the same module is internal on
// one machine and public on another (novox/hq ADR 0051). postgres listens from the mesh by default;
// one machine and public on another (novox/hq ADR 0046). postgres listens from the mesh by default;
// a setting on one node exposes it to anywhere, and the rule set follows.
func TestExposureSettingOverridesAListensSource(t *testing.T) {
postgres := Manifest{Module: "postgres", Version: "1",
@@ -605,7 +605,7 @@ func TestExposureSettingOverridesAListensSource(t *testing.T) {
}
// Exposure refuses a setting that names a port the module does not listen on, or a source that is
// not a real one — a setting reaching nothing is worse than none (novox/hq ADR 0048/0051).
// not a real one — a setting reaching nothing is worse than none (novox/hq ADR 0043/0046).
func TestExposureRefusesAPortNotListenedOnAndABadSource(t *testing.T) {
postgres := Manifest{Module: "postgres", Listens: []Listening{{Port: 5432, From: FromMesh}}}
layer := func(port, source string) []Layer {
+3 -3
View File
@@ -35,7 +35,7 @@ var identityUnusable = regexp.MustCompile(`[^a-z0-9_]+`)
const IdentityPrefix = "mesh_"
// IdentitySource is the name the mesh derives a consumer's identity from: the module's slug when it
// has declared one, otherwise its name (novox/hq ADR 0054). A module with a name short enough to fit
// has declared one, otherwise its name (novox/hq ADR 0049). A module with a name short enough to fit
// the tightest backend needs no slug; one whose name would overflow declares a short legible one.
func IdentitySource(slug, name string) string {
if slug != "" {
@@ -59,7 +59,7 @@ func ConsumerIdentity(node, module string) string {
// identityLimit is the shortest identifier limit among the systems these names reach: an S3 access
// key's 20 (novox/hq 04-ISSUES/010). PostgreSQL keeps 63 and MinIO 20, so 20 is the one that binds —
// the comment used to name PostgreSQL and was wrong. A name over it is refused, with the remedy a
// short slug (ADR 0054), not silently cut to fit.
// short slug (ADR 0049), not silently cut to fit.
const identityLimit = 20
// CheckIdentity refuses an identity that would not fit the tightest backend a consumer reaches.
@@ -68,7 +68,7 @@ const identityLimit = 20
// the statement succeeds, so two consumers agreeing for the first N bytes would become one login
// (04-ISSUES/022) — and S3 refuses outright. Refused here, at the mesh, because the mesh chose the
// name and is the only thing that can choose another. The remedy is a first-class one: give the
// module a short `slug` (ADR 0054), or shorten the machine's name.
// module a short `slug` (ADR 0049), or shorten the machine's name.
func CheckIdentity(node, module string) error {
got := ConsumerIdentity(node, module)
if len(got) <= identityLimit {
+1 -1
View File
@@ -6,7 +6,7 @@ import "testing"
func TestASlugIsPreferredOverTheModuleName(t *testing.T) {
// A module that declared a slug is identified by it, so a long name can be made to fit the
// tightest backend without a hash (novox/hq ADR 0054).
// tightest backend without a hash (novox/hq ADR 0049).
if got := IdentitySource("kc", "keycloak"); got != "kc" {
t.Errorf("the slug was not preferred: %q", got)
}
+3 -3
View File
@@ -120,7 +120,7 @@ type Manifest struct {
Version string `json:"version,omitempty"`
// Slug is a short identifier the mesh uses in place of the module name when it derives a
// consumer's login (novox/hq ADR 0054). Optional: a module with a short name needs none. It
// consumer's login (novox/hq ADR 0049). Optional: a module with a short name needs none. It
// exists because `mesh_<node>_<module>` must fit the tightest backend a consumer reaches — an S3
// access key is 20 characters — and a long module name would overflow it. A person choosing
// `kc` for keycloak keeps the identity legible where a hash would not.
@@ -135,7 +135,7 @@ type Manifest struct {
// Emits are the event types this module publishes onto the broker — dotted topic keys, e.g.
// "module.umami.site.created". Declared so the mesh knows the event graph; events are
// provisioning's lighter sibling — 1:many and broadcast, no credential (novox/hq ADR 0046).
// provisioning's lighter sibling — 1:many and broadcast, no credential (novox/hq ADR 0041).
Emits []string `json:"emits,omitempty"`
// Consumes are the event patterns this module subscribes to — topic patterns over module,
@@ -474,7 +474,7 @@ func ParseManifest(raw []byte) (Manifest, error) {
problems = append(problems, fmt.Sprintf(
"%q is not a usable module name: lower-case letters, digits, dashes and dots", m.Module))
}
// A slug is a short identifier the mesh derives a login from (novox/hq ADR 0054). The same
// A slug is a short identifier the mesh derives a login from (novox/hq ADR 0049). The same
// charset as a name; its length is checked against a backend's limit at assignment, where the
// node it joins is known — a slug that is fine on one machine's short name can overflow another's.
if m.Slug != "" && !name.MatchString(m.Slug) {
+1 -1
View File
@@ -172,7 +172,7 @@ func UnusedSettings(m Manifest, layers []Layer) []string {
for _, layer := range layers {
for key := range layer.Values {
// `expose` is a real destination for a module that listens: it overrides a port's
// source (novox/hq ADR 0051), validated in Exposure, so it is not stray here.
// source (novox/hq ADR 0046), validated in Exposure, so it is not stray here.
if key == ExposeSetting && len(m.Listens) > 0 {
continue
}