The mesh keeps a copy of what each node owns

novox/hq 09-the-node-lifecycle asks for this and it was missing: the host
reports what it owns and the mesh keeps the last report. A backup, never a
source -- nothing decides anything from it, and a node that disagrees with it
wins, because the node is the one that can see the machine.

Its point is the orphans. A node that loses its state file currently strands
whatever it applied: nothing on the machine knows those resources were the
mesh's doing, so nothing removes them. With this, a rebuilt node receives both
the declaration and the record of what it previously owned.

Never reported and reported nothing are kept apart, and that is the whole care
in it. A node that applied nothing holds nothing; a node that has never spoken
is unknown -- and handing back an empty list for the second would tell a
rebuilding node it owns nothing and have it remove whatever it found.

The age comes back with the answer rather than being left for the caller to go
and find. An answer about a machine is worth much less without one, and this
repository has already been bitten by a cache with no age on it.

A refusal or a partial failure moves last_seen and nothing else: neither is an
account of what the machine holds, and recording one as though it were would
tell a rebuilding node to remove what it still has.
This commit is contained in:
2026-08-29 16:51:54 +02:00
parent 0e116d2d65
commit f563ababa1
6 changed files with 194 additions and 5 deletions
@@ -0,0 +1,18 @@
-- The last thing a node said it owns.
--
-- novox/hq 09-the-node-lifecycle: the host reports what it owns and the mesh keeps the last
-- report. **This is a backup, never a source.** The host never reads it to decide anything; it is
-- handed back only when a node has lost its own store, and a node that disagrees with it wins,
-- because the node is the one that can see the machine.
--
-- Its point is the orphans. A node that loses its state file currently strands whatever it had
-- applied: nothing on the machine knows those resources were ever the mesh's doing, so nothing
-- removes them. With this, a rebuilt node receives both the declaration and the record of what it
-- previously owned, and can take away what is no longer declared.
alter table node add column owned jsonb;
-- When that report arrived. Separate from last_seen, which moves on any word from the node at
-- all: a node can be plainly alive for weeks without applying anything, and reading one as the
-- other would make a quiet node look like a stale one.
alter table node add column owned_reported timestamptz;