-- What the mesh needs in order to compute a private network. -- -- novox/hq 08-connectivity. Three declared inputs and one reported key. All four are facts about -- a node that only the mesh can hold, because computing the graph needs every node at once — -- which is the definition of control-plane work. -- The node's public key on the overlay. Reported by the node, which generated the pair and kept -- the private half. So the control plane computes a graph it cannot itself impersonate. alter table node add column overlay_key text; -- Where the node can be dialled, or null for nowhere. -- -- DECLARED, never inferred from the address. The address is evidence of reachability and is not -- the fact: carrier-grade NAT looks public and is not, a routable address behind a closed -- firewall looks public and is not, and the regular expression that used to decide this got the -- lab wrong as well (novox/hq ADR 0007). alter table node add column endpoint text; -- Where the machine physically is, or null if it roams. -- -- Two nodes at one site peer directly; everything else routes through the hub. A node with no -- site is hub-only, and that is not a simplification — WireGuard has no failover, so a more -- specific route to a dead endpoint blackholes rather than falling back. One path is better than -- two when one of them can swallow traffic silently. alter table node add column site text; -- Whether this node is the hub. DECLARED, never derived from an address prefix: an election -- decided by the first four characters of an address fails silently, cannot be queried, and makes -- renumbering an outage. alter table node add column is_hub boolean not null default false; -- At most one hub. Partial, so it constrains the true ones and says nothing about the rest. create unique index node_one_hub on node ((is_hub)) where is_hub; -- The node's address on the overlay, assigned by the mesh. A node computes nothing about the -- network it is joining: it generates a keypair, publishes the public half, and receives the rest. alter table node add column overlay_address inet; create unique index node_overlay_address on node (overlay_address) where overlay_address is not null;