Controller side of novox/hq to-be 37 (the operator's machine). Depends on hq #293 for the records; mesh-host and mesh-catalog PRs of the same branch name ride alongside.
node-service-manager joins the mesh's own seats under ADR 0177: node-scoped, serving eight verbs — units, status, start, stop, restart, enable, disable, journal — each with a schema that takes an optional scope, system or the operator account's user manager. Sixteen seats now; the closed-set count test is updated and names the record. The holder (the systemd module in the catalogue PR) runs nothing of its own; its verbs will be served by the node tools runtime (ADR 0175, not yet built).
${machine:account} resolves in name and user as it already did in path, owner and content: the shell module makes the operator's account its holder's login shell through the user shape (ADR 0176), and a user-scoped unit runs as that account (ADR 0177). A machine with no account refuses by name, as before.
Tests: the two placeholders resolve and refuse; the seat's verbs, scope and schemas. Full suite green.
Note for the live mesh: no node record carries an operator account yet (all four are empty). node account <node> <login> sets it; until then no home-scoped module composes anywhere.
Controller side of novox/hq to-be 37 (the operator's machine). Depends on hq #293 for the records; mesh-host and mesh-catalog PRs of the same branch name ride alongside.
**`node-service-manager`** joins the mesh's own seats under ADR 0177: node-scoped, serving eight verbs — `units`, `status`, `start`, `stop`, `restart`, `enable`, `disable`, `journal` — each with a schema that takes an optional `scope`, `system` or the operator account's `user` manager. Sixteen seats now; the closed-set count test is updated and names the record. The holder (the `systemd` module in the catalogue PR) runs nothing of its own; its verbs will be served by the node tools runtime (ADR 0175, not yet built).
**`${machine:account}` resolves in `name` and `user`** as it already did in `path`, `owner` and `content`: the shell module makes the operator's account its holder's login shell through the `user` shape (ADR 0176), and a user-scoped unit runs as that account (ADR 0177). A machine with no account refuses by name, as before.
**Tests:** the two placeholders resolve and refuse; the seat's verbs, scope and schemas. Full suite green.
**Note for the live mesh:** no node record carries an operator account yet (all four are empty). `node account <node> <login>` sets it; until then no home-scoped module composes anywhere.
node-service-manager joins the mesh's own seats, node-scoped, serving eight
verbs — units, status, start, stop, restart, enable, disable, journal — each
with a schema that takes an optional scope, "system" or the operator
account's "user" manager. Sixteen seats now; the count test says so and names
the record.
${machine:account} resolves in a resource's `name` and `user` as it already
did in path, owner and content: the shell module makes the operator's account
its holder's login shell through the `user` shape, and the desktop's watchers
run as that account through a user-scoped unit (host change alongside).
Neither can name the person. A machine with no account refuses by name.
Beside the named verbs, `command` takes a command line as the controller's
own shell would — `node account g14 jochen`, `node show ace`, `module list` —
splits it as a shell does (quotes group, backslash escapes, nothing expanded)
and runs it in this binary like every other verb. The named verbs keep their
schemas; this is the whole binary, added because the operator decided any
node may call any tool (hq ADR 0175) and a verb per command was the only
thing keeping the rest behind a shell on the control node. ADR 0154 carries
the dated note. Tests: a plain line, quoted words, an empty line and an
unclosed quote refused.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Controller side of novox/hq to-be 37 (the operator's machine). Depends on hq #293 for the records; mesh-host and mesh-catalog PRs of the same branch name ride alongside.
node-service-managerjoins the mesh's own seats under ADR 0177: node-scoped, serving eight verbs —units,status,start,stop,restart,enable,disable,journal— each with a schema that takes an optionalscope,systemor the operator account'susermanager. Sixteen seats now; the closed-set count test is updated and names the record. The holder (thesystemdmodule in the catalogue PR) runs nothing of its own; its verbs will be served by the node tools runtime (ADR 0175, not yet built).${machine:account}resolves innameanduseras it already did inpath,ownerandcontent: the shell module makes the operator's account its holder's login shell through theusershape (ADR 0176), and a user-scoped unit runs as that account (ADR 0177). A machine with no account refuses by name, as before.Tests: the two placeholders resolve and refuse; the seat's verbs, scope and schemas. Full suite green.
Note for the live mesh: no node record carries an operator account yet (all four are empty).
node account <node> <login>sets it; until then no home-scoped module composes anywhere.node-service-manager joins the mesh's own seats, node-scoped, serving eight verbs — units, status, start, stop, restart, enable, disable, journal — each with a schema that takes an optional scope, "system" or the operator account's "user" manager. Sixteen seats now; the count test says so and names the record. ${machine:account} resolves in a resource's `name` and `user` as it already did in path, owner and content: the shell module makes the operator's account its holder's login shell through the `user` shape, and the desktop's watchers run as that account through a user-scoped unit (host change alongside). Neither can name the person. A machine with no account refuses by name.