Rename mesh-control -> mesh-controller, substrate -> foundation

One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 18:40:40 +02:00
parent 366840fc0d
commit c3b88b9148
77 changed files with 157 additions and 157 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ import (
// **Why it must hold.** The refresh token is sealed to the manager node — at adoption and after each
// rotation — by the manager MODULE, in TypeScript (mesh-catalog anthropic-manager/sealedbox.ts). The
// HOST then unseals it with Go's box.OpenAnonymous (mesh-host identity.SealingKey.Unseal) to mount the
// cleartext, and mesh-control seals every other credential with box.SealAnonymous (secrets.Seal). If
// cleartext, and mesh-controller seals every other credential with box.SealAnonymous (secrets.Seal). If
// the TS seal and the Go box disagreed by a byte, the host would refuse the refresh token as a value
// it cannot open — silently, as a manager that never gets its credential. So this is load-bearing, and
// it is pinned here rather than trusted.
+1 -1
View File
@@ -1,5 +1,5 @@
{
"_comment": "Produced by mesh-catalog anthropic-manager sealedbox.ts (crypto_box_seal). Proves that value the module seals to a node's public key opens under Go box.OpenAnonymous — the host's Unseal and mesh-control secrets.Seal/Open. Regenerate with the module's compiled seal().",
"_comment": "Produced by mesh-catalog anthropic-manager sealedbox.ts (crypto_box_seal). Proves that value the module seals to a node's public key opens under Go box.OpenAnonymous — the host's Unseal and mesh-controller secrets.Seal/Open. Regenerate with the module's compiled seal().",
"managerPublicKey": "rJZ9OSnuCcU5MNi8iV0EK8c5nYN+Cx5A+q+miIIIoUc=",
"managerPrivateKey": "wGHx9hpbO1pyvLiw8oGwi31LBce3HscDiGhXpNU+wl4=",
"plaintext": "rt-a-refresh-token-only-the-manager-may-read",