A tools bundle is given its words, composed per machine; what they name is the account's to read (hq ADR 0192) #236

Merged
mesh-admin merged 1 commits from feat/0192-a-bundles-env into main 2026-10-03 13:32:39 +00:00
Contributor

hq ADR 0192, design 38 WP4b.

  • build.artifacts[].env on a bundle: words and values with ${dir:…} and ${port:…} only. Refused when a value carries any other reference (a secret's content, a binding), when a word is one the runtime sets for itself, and on any artifact that is not a bundle.
  • Composed per machine like a container's environment and handed to the runtime as MESH_TOOL_ENV ({"<module>": {"<word>": "<value>"}}), in the unit, so a change to any module's words restarts it. Two bundles of one module disagreeing on a word is refused.
  • Every file and directory of the module a word names, or that holds one, is owned by the account the runtime runs as, where it says no owner. The tool containers ran as root; node-tools runs as the operator account, and a root-owned 0600 secret or 0700 directory is one it cannot read. Nothing changes on a machine with no account.

Tests: words resolved to this machine's paths and ports; only the named files and directories re-owned; no re-owning without an account; a change to the words changes the process; refusals for ${secret:…}, ${bound:…}, a runtime word, env on an image. The ownership test fails with the pass switched off. Full suite passes from the worktree beside the current catalogue.

No module declares env yet, so declarations are unchanged until the first converted module lands. (Note: ~/projects/novox/mesh-catalog, the reference clone beside the main controller checkout, is stale; its fail2ban predates the claim's verbs and fails the catalogue check there.)

hq ADR 0192, design 38 WP4b. - `build.artifacts[].env` on a bundle: words and values with `${dir:…}` and `${port:…}` only. Refused when a value carries any other reference (a secret's content, a binding), when a word is one the runtime sets for itself, and on any artifact that is not a bundle. - Composed per machine like a container's environment and handed to the runtime as `MESH_TOOL_ENV` (`{"<module>": {"<word>": "<value>"}}`), in the unit, so a change to any module's words restarts it. Two bundles of one module disagreeing on a word is refused. - Every file and directory of the module a word names, or that holds one, is owned by the account the runtime runs as, where it says no owner. The tool containers ran as root; node-tools runs as the operator account, and a root-owned 0600 secret or 0700 directory is one it cannot read. Nothing changes on a machine with no account. Tests: words resolved to this machine's paths and ports; only the named files and directories re-owned; no re-owning without an account; a change to the words changes the process; refusals for `${secret:…}`, `${bound:…}`, a runtime word, `env` on an image. The ownership test fails with the pass switched off. Full suite passes from the worktree beside the current catalogue. No module declares `env` yet, so declarations are unchanged until the first converted module lands. (Note: `~/projects/novox/mesh-catalog`, the reference clone beside the main controller checkout, is stale; its fail2ban predates the claim's verbs and fails the catalogue check there.)
mesh-admin added 1 commit 2026-10-03 13:32:26 +00:00
build.artifacts[].env on a bundle: words and values written with ${dir:…} and ${port:…} only,
refused when a value carries any other reference (a secret's content, a binding) or names a word
the runtime sets for itself, and on any artifact that is not a bundle. Resolved per machine like a
container's environment and handed to the runtime as MESH_TOOL_ENV, module by module, in the unit
so a change restarts it. Every file and directory of the module a word names, or that holds one, is
owned by the account the runtime runs as where it says no owner, since a tool reads as that account.
mesh-admin merged commit 4f009fff83 into main 2026-10-03 13:32:39 +00:00
mesh-admin deleted branch feat/0192-a-bundles-env 2026-10-03 13:32:39 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#236