The service manager is a node seat with the unit verbs, and a user shape names the account (hq ADR 0176, 0177) #218

Merged
mesh-admin merged 2 commits from feat/the-operators-machine into main 2026-10-02 14:58:51 +00:00
Contributor

Controller side of novox/hq to-be 37 (the operator's machine). Depends on hq #293 for the records; mesh-host and mesh-catalog PRs of the same branch name ride alongside.

node-service-manager joins the mesh's own seats under ADR 0177: node-scoped, serving eight verbs — units, status, start, stop, restart, enable, disable, journal — each with a schema that takes an optional scope, system or the operator account's user manager. Sixteen seats now; the closed-set count test is updated and names the record. The holder (the systemd module in the catalogue PR) runs nothing of its own; its verbs will be served by the node tools runtime (ADR 0175, not yet built).

${machine:account} resolves in name and user as it already did in path, owner and content: the shell module makes the operator's account its holder's login shell through the user shape (ADR 0176), and a user-scoped unit runs as that account (ADR 0177). A machine with no account refuses by name, as before.

Tests: the two placeholders resolve and refuse; the seat's verbs, scope and schemas. Full suite green.

Note for the live mesh: no node record carries an operator account yet (all four are empty). node account <node> <login> sets it; until then no home-scoped module composes anywhere.

Controller side of novox/hq to-be 37 (the operator's machine). Depends on hq #293 for the records; mesh-host and mesh-catalog PRs of the same branch name ride alongside. **`node-service-manager`** joins the mesh's own seats under ADR 0177: node-scoped, serving eight verbs — `units`, `status`, `start`, `stop`, `restart`, `enable`, `disable`, `journal` — each with a schema that takes an optional `scope`, `system` or the operator account's `user` manager. Sixteen seats now; the closed-set count test is updated and names the record. The holder (the `systemd` module in the catalogue PR) runs nothing of its own; its verbs will be served by the node tools runtime (ADR 0175, not yet built). **`${machine:account}` resolves in `name` and `user`** as it already did in `path`, `owner` and `content`: the shell module makes the operator's account its holder's login shell through the `user` shape (ADR 0176), and a user-scoped unit runs as that account (ADR 0177). A machine with no account refuses by name, as before. **Tests:** the two placeholders resolve and refuse; the seat's verbs, scope and schemas. Full suite green. **Note for the live mesh:** no node record carries an operator account yet (all four are empty). `node account <node> <login>` sets it; until then no home-scoped module composes anywhere.
mesh-admin added 1 commit 2026-10-02 14:48:45 +00:00
node-service-manager joins the mesh's own seats, node-scoped, serving eight
verbs — units, status, start, stop, restart, enable, disable, journal — each
with a schema that takes an optional scope, "system" or the operator
account's "user" manager. Sixteen seats now; the count test says so and names
the record.

${machine:account} resolves in a resource's `name` and `user` as it already
did in path, owner and content: the shell module makes the operator's account
its holder's login shell through the `user` shape, and the desktop's watchers
run as that account through a user-scoped unit (host change alongside).
Neither can name the person. A machine with no account refuses by name.
jschoubben added 1 commit 2026-10-02 14:53:29 +00:00
Beside the named verbs, `command` takes a command line as the controller's
own shell would — `node account g14 jochen`, `node show ace`, `module list` —
splits it as a shell does (quotes group, backslash escapes, nothing expanded)
and runs it in this binary like every other verb. The named verbs keep their
schemas; this is the whole binary, added because the operator decided any
node may call any tool (hq ADR 0175) and a verb per command was the only
thing keeping the rest behind a shell on the control node. ADR 0154 carries
the dated note. Tests: a plain line, quoted words, an empty line and an
unclosed quote refused.
mesh-admin merged commit d134c89a7c into main 2026-10-02 14:58:51 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#218