Proxy configuration beside insecure, not a fifth policy — ADR 0108 closed that set at four, and both of these tune how a request is carried rather than deciding what a name admits. A registry is the case that needs it: image layers arrive as single requests of gigabytes and a proxy's own default refuses them long before the workload is reached. Absent is no limit, which is what every route already got. A limit that is not a whole positive number of bytes takes the route with it, named in the log like a port that is not one — serving it without the limit would carry exactly what the module said not to carry. Enforced on the declared length where there is one, and while reading for a chunked body, which declares none: without the second, a limit is advice.
examples
Things that run, kept here because a contract is easier to read as working code than as prose.
Nothing here is part of the control plane. The control plane decides and never touches a machine (README); everything in this directory runs on a machine and touches it. These are reference implementations of contracts the control plane defines, and a real one ships with the module that ships the software it configures.
postgres-provisioner |
the last step of a credential: reads what the mesh delivered and makes PostgreSQL accept it |
Running the provisioner
--watch reconciles now and again whenever what the mesh delivered changes. That is what lets it
be a module: an ordinary long-running service the host supervises, rather than something that has
to be invoked after every declaration by a timer or a unit wired to a file.
It polls rather than watching the filesystem, because the host writes atomically — the file is replaced, so a watch on the path stops seeing anything after the first replacement. A watcher that silently stops working is worse than a poll.
Credentials are compared by digest and never by content. This runs for as long as the machine is up, and a secret does not belong in a long-lived variable when a hash answers the same question.