Converted from the arrangement being replaced, in its shapes rather than theirs. The registry is the manifest the lab already proved, promoted: names its image by digest and is never built (04-ISSUES/029), provides the artifact store, claims it once per machine. Redis is the third provision after a database and a bucket, and the first whose tenancy is a pattern in a shared keyspace rather than a namespace something else enforces. Its provisioner mirrors the postgres one's contract line for line — the manifest, the sealed per-consumer files, the mark, the withdrawal of orphans — and speaks RESP directly: five commands are needed, and a client library large enough to hide them would be most of the program's size. A prefix Redis would read as a pattern is refused, because the grant must mean what the manifest said; grants are persisted with ACL SAVE, or said loudly, because a cache that forgets its tenants on restart reports success until then. Umami asks the mesh for its database and a generated app secret, and carries no state of its own — the arrangement being replaced ran a bundled second postgres beside it. Grafana keeps its dashboards in a declared directory with the image's own owner. Both listen on 3000, as does the forge — which is the mesh's port assignment earning its keep. Traefik is deliberately not converted: the mesh's route provider is mesh-route-proxy, which speaks route grants natively, and a traefik that consumed them would be an adapter nobody has written pretending to be a conversion. All images pinned by real digests, resolved on this workstation today.
examples
Things that run, kept here because a contract is easier to read as working code than as prose.
Nothing here is part of the control plane. The control plane decides and never touches a machine (README); everything in this directory runs on a machine and touches it. These are reference implementations of contracts the control plane defines, and a real one ships with the module that ships the software it configures.
postgres-provisioner |
the last step of a credential: reads what the mesh delivered and makes PostgreSQL accept it |
Running the provisioner
--watch reconciles now and again whenever what the mesh delivered changes. That is what lets it
be a module: an ordinary long-running service the host supervises, rather than something that has
to be invoked after every declaration by a timer or a unit wired to a file.
It polls rather than watching the filesystem, because the host writes atomically — the file is replaced, so a watch on the path stops seeing anything after the first replacement. A watcher that silently stops working is worse than a poll.
Credentials are compared by digest and never by content. This runs for as long as the machine is up, and a secret does not belong in a long-lived variable when a hash answers the same question.