Issues 203 and 206: an assignment issues its credential; the controller owns a worker's shape; the build seat's holder follows the controller #233

Merged
mesh-admin merged 4 commits from fix/issues-203-206 into main 2026-10-03 09:49:54 +00:00
Contributor

Three commits, each with tests, fixing hq issues 203 and 206 (diagnoses in hq #310).

203 (a3e8a41): assign of a module declaring own-secrets.broker mints and seals its bus credential in the same act, idempotently (re-assign never rotates); when the bus is unknown it says module issue first. push/plan refuse to send a module whose bus user is unminted, naming the verb and the issue, and never seal a random placeholder for broker. None of the 41 live unminted users declare a broker secret, so no live push starts refusing. A container or process that reads an own secret gets <module>.needs-<secret> in restart-on automatically.

206 (76a8b8d, 28853a2): EnsureConsumer re-makes a consumer whose push/pull type differs from the derived shape, on work-queue streams only (acked work is gone, pending is redelivered; proven on a real bus); on history-keeping streams it says so and leaves it (issue 156). The plan gains a worker-of edge: every module claiming the build seat follows mesh-controller, so the controller that defines the worker rolls before the machine that binds it — the one documented exception to "built-by is not an order" (ADR 0162).

Not coded: detecting credentials sealed before claims existed — a sealed credential cannot be read back and carries no shape marker; the cure is module issue again.

go build, go vet, gofmt clean; go test ./... green per package with Postgres and NATS (broker and link tests interfere with each other's streams when run in parallel on one bus — pre-existing).

Three commits, each with tests, fixing hq issues 203 and 206 (diagnoses in hq #310). **203** (`a3e8a41`): `assign` of a module declaring `own-secrets.broker` mints and seals its bus credential in the same act, idempotently (re-assign never rotates); when the bus is unknown it says `module issue` first. `push`/`plan` refuse to send a module whose bus user is unminted, naming the verb and the issue, and never seal a random placeholder for `broker`. None of the 41 live unminted users declare a broker secret, so no live push starts refusing. A container or `process` that reads an own secret gets `<module>.needs-<secret>` in `restart-on` automatically. **206** (`76a8b8d`, `28853a2`): `EnsureConsumer` re-makes a consumer whose push/pull type differs from the derived shape, on work-queue streams only (acked work is gone, pending is redelivered; proven on a real bus); on history-keeping streams it says so and leaves it (issue 156). The plan gains a `worker-of` edge: every module claiming the build seat follows `mesh-controller`, so the controller that defines the worker rolls before the machine that binds it — the one documented exception to "built-by is not an order" (ADR 0162). Not coded: detecting credentials sealed before `claims` existed — a sealed credential cannot be read back and carries no shape marker; the cure is `module issue` again. `go build`, `go vet`, `gofmt` clean; `go test ./...` green per package with Postgres and NATS (broker and link tests interfere with each other's streams when run in parallel on one bus — pre-existing).
mesh-admin added 3 commits 2026-10-03 02:06:07 +00:00
`assign` recorded a module and `push` sealed a random own secret where its bus credential belongs;
the process crash-looped until a person ran `module issue` and pushed again, and the only warning was
one line in a list printed on every push. Now assigning a module that declares a broker secret issues
the credential in the same act — kept when one exists, so re-assigning rotates nothing — and when the
bus cannot be reached from here the assignment says which verb to run. A push never seals a
placeholder in a credential's place: a module whose bus user is unminted is refused by name, with the
verb. The control plane's own user is the installer's, seeded at genesis, which the test now says.

And what reads one of a module's own secrets is restarted when it changes — composed for a container
or daemon that names the secret's path in its volumes, environment or env-files, so a manifest need
not say it: the build machine ran on an hour-old credential because its manifest restarted it on its
environment file alone (issue 206). A scheduled or run-once process is left alone; it reads afresh.
A holder built for a pull worker cannot bind a push one — `cannot pull subscribe to push based
consumer` — and on 2026-10-03 the build machine rolled before the controller that would have
redefined its worker, restarted on that for an hour, and nothing could build the controller that
would have ended it. The server cannot change a consumer's type in place, so the assertion re-makes
one of the wrong type: on a work queue nothing is lost, because what was acknowledged is gone from the
stream and what was not is delivered again from the start. On a stream that keeps its history it is
said and left, since a re-made consumer replays what this one acknowledged (issue 156), and that is a
person's call. Proven against a real bus: a push worker with one ask acknowledged and two pending is
re-made as pull, a pull subscription binds, and takes exactly the two.
A plan is ordered by artifacts and says nothing about what must be running before what (ADR 0162);
on 2026-10-03 that put the build machine in tier 0 and the controller in tier 1, and the new build
machine could not bind the worker the old controller had defined. One running order enters the
graph, named as its own edge: a module claiming the build seat follows the control plane, and the
built-by edge from the control plane to that holder yields to it — the controller is built by
whichever build machine is running, as the runtime image always was. The edge orders a plan and
never widens it, like built-by.
jschoubben added 1 commit 2026-10-03 09:07:31 +00:00
Left for a hand, the hand re-made it with the server's default — everything the stream holds — and
on 2026-10-03 that replayed every build ask since 1 October into the catalogue. Re-made with
deliver-new instead: nothing acknowledged comes back; what was in flight is said and asked again.
jschoubben force-pushed fix/issues-203-206 from 60e8d01ac0 to c294949f2a 2026-10-03 09:07:31 +00:00 Compare
mesh-admin merged commit eae0577567 into main 2026-10-03 09:49:54 +00:00
mesh-admin deleted branch fix/issues-203-206 2026-10-03 09:49:54 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#233