The modules the mesh runs were under examples/modules/, which framed the real catalogue as illustrations of a control-plane package. They are neither examples nor the control plane's — they are the mesh's own catalogue, and they now live in their own repository (novox/mesh-catalog), consumed as a build source like any other. The engine that reads them stays here (internal/catalogue): the control plane owns the manifest contract; the data does not belong beside it. Removed with them: modules_test.go and parseall_test.go, which validated the example manifests against the parser. That validation logically follows the catalogue to mesh-catalog, but it imports internal/catalogue, so re-homing it needs the parser exported from internal/ first — a deliberate follow-up, not done here. Until then the pipeline is the gate, and internal/catalogue's own inline tests still cover the parser. Answers novox/hq ADR 0030's open tier-4 question — where the catalogue lives — in favour of one flat mesh-catalog repository. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
examples
Things that run, kept here because a contract is easier to read as working code than as prose.
Nothing here is part of the control plane. The control plane decides and never touches a machine (README); everything in this directory runs on a machine and touches it. These are reference implementations of contracts the control plane defines, and a real one ships with the module that ships the software it configures.
postgres-provisioner |
the last step of a credential: reads what the mesh delivered and makes PostgreSQL accept it |
Running the provisioner
--watch reconciles now and again whenever what the mesh delivered changes. That is what lets it
be a module: an ordinary long-running service the host supervises, rather than something that has
to be invoked after every declaration by a timer or a unit wired to a file.
It polls rather than watching the filesystem, because the host writes atomically — the file is replaced, so a watch on the path stops seeing anything after the first replacement. A watcher that silently stops working is worse than a poll.
Credentials are compared by digest and never by content. This runs for as long as the machine is up, and a secret does not belong in a long-lived variable when a hash answers the same question.