Stage 2 — the bundle a host carries
novox/hq ADR 0038: one behaviour, two sources of declaration. This is the source that does not need a mesh — the first node's path. The bundle is embedded in the binary rather than shipped beside it, because "copy it onto a machine and run it is the whole installation" stops being true the moment a second file has to arrive with it. `make host BUNDLE=...` builds a host carrying one; `mesh-host reconcile` applies it; `mesh-host bundle` shows it. A default build carries nothing and REFUSES to reconcile, saying why. A host that applied nothing and reported success would look exactly like one that raised a first node, and the difference would surface later as a mesh that never came up with nothing to point at. Proved on a sealed machine: no route out, no name resolution, one binary copied on, and it configured itself from what it carried. Idempotent on the second run. One bug found by running rather than reasoning, and it is a shape worth naming: `mesh-host bundle` validated the carried bundle through a path that strips comments, while `reconcile` handed the raw bytes to the parser. So the command whose whole job is to check the bundle said yes, and the command that uses it said no. Two paths to one artefact, disagreeing. There is one path now, and a test asserts that what validates is what is applied. What this does NOT prove is stated in the README rather than left implied: the claim under stage 2 is that one host can raise the substrate alone, and the substrate is four container services. There is no container type, because a container needs an image and where images come from is open; what belongs in a substrate is not known, because the closure for a one-node mesh is what research 011 and 012 exist to answer; and the machine used to test this cannot install a container runtime through a sealed network. The mechanism is finished. The claim is not, and shipping a host that claimed a substrate it has never raised would be the fault this whole project is about. 65 tests.
This commit is contained in:
@@ -28,7 +28,9 @@ connects to nothing and listens on nothing — what it applies comes from a file
|
||||
```
|
||||
mesh-host profile what this machine can be asked to do
|
||||
mesh-host inventory what this machine is, and what it holds
|
||||
mesh-host apply FILE make this machine match a declaration
|
||||
mesh-host apply FILE make this machine match a declaration from a file
|
||||
mesh-host reconcile make this machine match the declaration this host carries
|
||||
mesh-host bundle show what this host carries
|
||||
mesh-host owned what this host has applied and still owns
|
||||
--json machine-readable
|
||||
--state where this node keeps what it knows
|
||||
@@ -78,8 +80,42 @@ did, after each thing worked.
|
||||
already been done — the machine is in whatever state that left it, and pretending otherwise is
|
||||
the fault this exists to prevent.
|
||||
|
||||
## The bundle a host carries
|
||||
|
||||
A host built for a machine carries its declaration **inside the binary**:
|
||||
|
||||
```
|
||||
make host BUNDLE=path/to/substrate.lock
|
||||
```
|
||||
|
||||
`mesh-host reconcile` then applies it. That is the first node's path — no mesh present, nothing
|
||||
fetched, nothing else copied onto the machine. `copy it and run it` stops being true the moment
|
||||
a second file has to arrive with it, which is why the bundle is embedded rather than beside it.
|
||||
|
||||
**A default build carries nothing and refuses to reconcile**, saying so. A host that applied
|
||||
nothing and reported success would look exactly like one that raised a first node, and the
|
||||
difference would surface later as a mesh that never came up with nothing to point at.
|
||||
|
||||
Stages 3 and 4 — the link, and enrolment — are designed and not built.
|
||||
|
||||
## What stage 2 does not yet prove
|
||||
|
||||
The design defines stage 2 as *the host applies `substrate.lock` with no mesh present*, and
|
||||
calls out the claim underneath it: **that one host can raise the substrate alone**.
|
||||
|
||||
The mechanism is proved — a sealed machine, one binary, and it configures itself from what it
|
||||
carries. The claim is not. The substrate is four container services, and:
|
||||
|
||||
- the vocabulary has no container type, because a container needs an image and where images
|
||||
come from is open ([`novox/hq` research 012](https://git.novox.be/novox/hq));
|
||||
- what belongs in a substrate is not known — the closure for a one-node mesh is what
|
||||
research 011 and 012 exist to answer;
|
||||
- and the machine used to test this has no container runtime, because a sealed network cannot
|
||||
install one.
|
||||
|
||||
So `substrate.lock` here is a real bundle with a placeholder's content. Saying that plainly
|
||||
beats shipping a host that claims a substrate it has never raised.
|
||||
|
||||
## A capability is detected, never assumed
|
||||
|
||||
The reason this is the first thing built rather than a detail of it.
|
||||
|
||||
Reference in New Issue
Block a user