catalogue: run-once is a step the host runs to completion (ADR 0052)

A container may be marked `run-once: true` — a step the host runs to completion,
gating whatever the declaration places after it. The control plane's part is
small: the field is carried to the host unchanged (containers pass through as
maps), and the step keeps its author-order position ahead of the container it
gates, because the gate is declaration order, not a resolved dependency
(ADR 0005).

The manifest parser refuses a run-once that is not a boolean and the pair
run-once + restart-on (contradictory lifecycles) — near the manifest rather than
far away on the machine, the same lesson the action ban records. Three unit
tests; go build ./... and go test ./... green.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 23:57:33 +02:00
parent 6bb9434298
commit f96c247c5f
2 changed files with 124 additions and 0 deletions
+31
View File
@@ -723,6 +723,37 @@ func ParseManifest(raw []byte) (Manifest, error) {
"program that reads what the mesh delivered and reconciles",
m.Module, r["id"]))
}
// **A run-once container is a step the host runs to completion** (novox/hq ADR 0052). It is a
// boolean modifier on the container shape — the host runs the container, requires it to exit 0,
// and starts whatever the declaration places after it only once it has. Two things are refused
// here rather than only on the machine, for the same near-versus-far reason the action ban
// above records: a value that is not a boolean, and the pair run-once + restart-on, which asks
// for two contradictory lifecycles — restart-on brings a *running* container back, and a
// run-once step does not stay running.
for _, r := range m.Resources {
if fmt.Sprint(r["type"]) != "container" {
continue
}
raw, present := r["run-once"]
if !present {
continue
}
once, ok := raw.(bool)
if !ok {
problems = append(problems, fmt.Sprintf(
"%s declares run-once on %v as a %T; run-once is true or false",
m.Module, r["id"], raw))
continue
}
if once {
if _, hasRestart := r["restart-on"]; hasRestart {
problems = append(problems, fmt.Sprintf(
"%s declares %v as run-once and with restart-on; a run-once step runs to "+
"completion rather than staying running to be restarted (novox/hq ADR 0052)",
m.Module, r["id"]))
}
}
}
for name, where := range m.OwnSecrets {
if !strings.HasPrefix(where, "/") {
problems = append(problems, fmt.Sprintf(