Rename mesh-control -> mesh-controller, substrate -> foundation

One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 18:40:40 +02:00
parent 01c7730fb3
commit 121367319d
48 changed files with 317 additions and 317 deletions
+12 -12
View File
@@ -8,11 +8,11 @@
// cannot be folded into it without making that sentence false. Same tier, same repository,
// different program.
//
// Genesis is a pivot (novox/hq ADR 0067). It raises a substrate whose control plane is named by the
// Genesis is a pivot (novox/hq ADR 0067). It raises a foundation whose control plane is named by the
// digest of its own configuration — legal exactly where nothing could have served an image — then
// enrols this machine, installs the registry module, pushes that image into it to get the manifest
// digest it has never had, reinstalls the control plane as an ordinary module pinned to it, and
// drops the temporary one. Without --catalog it stops after the substrate and says why.
// drops the temporary one. Without --catalog it stops after the foundation and says why.
package main
import (
@@ -40,8 +40,8 @@ import (
var version = "development build"
const (
defaultTemplate = "substrate.lock"
defaultOut = "/var/lib/mesh-host/substrate.lock"
defaultTemplate = "foundation.lock"
defaultOut = "/var/lib/mesh-host/foundation.lock"
defaultRegistry = "127.0.0.1:5000"
defaultHost = "/usr/local/bin/mesh-host"
// The unit this project actually packages, in `packaging/`. It said `mesh-host.service`, which
@@ -58,7 +58,7 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
1 preflight what has to be true before anything is changed
2 load the builder's image, carried in this installer
3 build the control plane, from its own repository and a commit
4 bundle the substrate, named for this machine
4 bundle the foundation, named for this machine
5 apply raise it
6 verify it is up, and the control plane replies
7 enrol this machine becomes the mesh's first node
@@ -75,7 +75,7 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
13 base build the shared toolchain and runtime everything with code
stands on
14 store build and install postgres — a database provider, which the
substrate's own store is not
foundation's own store is not
15 catalogue build and install the module graph
16 network choose the private network (--private-network), place this
machine as its hub (--endpoint, --site)
@@ -83,7 +83,7 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
question is which, not whether
18 extras anything beyond the floor (--extras)
--bundle the substrate template to build this machine's bundle from
--bundle the foundation template to build this machine's bundle from
(default ` + defaultTemplate + `)
--out where the produced bundle is written, for a person to read
(default ` + defaultOut + `)
@@ -131,8 +131,8 @@ the same thing that will maintain it, and the control plane a mesh ends up runni
one it built itself, from a repository and a commit it can name and build again.
Genesis is a pivot: a temporary control plane installs the registry that makes it
permanent. The temporary one is called temp-mesh-control and the permanent one is
called mesh-control, so they are two containers with two owners and there is nothing
permanent. The temporary one is called temp-mesh-controller and the permanent one is
called mesh-controller, so they are two containers with two owners and there is nothing
to hand over.
Every step is idempotent: run it again after fixing whatever it named, and the steps
@@ -217,11 +217,11 @@ func newFlagSet(opts *bootstrap.Options, jsonOut *bool) *flag.FlagSet {
set := flag.NewFlagSet("mesh-bootstrap", flag.ContinueOnError)
set.SetOutput(os.Stderr)
set.Usage = func() { fmt.Fprint(os.Stderr, usage) }
set.StringVar(&opts.Template, "bundle", opts.Template, "the substrate template to build from")
set.StringVar(&opts.Template, "bundle", opts.Template, "the foundation template to build from")
set.StringVar(&opts.Out, "out", opts.Out, "where the produced bundle is written")
set.StringVar(&opts.State, "state", opts.State, "where this node records what it has applied")
set.StringVar(&opts.Catalogue, "catalog", opts.Catalogue,
"a checkout of the mesh's catalogue; without it this stops after the substrate")
"a checkout of the mesh's catalogue; without it this stops after the foundation")
set.StringVar(&opts.Source.Repository, "source", opts.Source.Repository,
"the repository the control plane is built from, on a mesh that already exists")
set.StringVar(&opts.Source.Ref, "source-ref", opts.Source.Ref,
@@ -367,7 +367,7 @@ func hostname() string {
//
// Plain HTTP, and only at the mesh's own registry: it is reached over the mesh's private network,
// which is already the encrypted and authenticated thing, and a second layer inside it would be
// certificates to issue and rotate for no property the first does not have (mesh-control's
// certificates to issue and rotate for no property the first does not have (mesh-controller's
// `internal/builder` pushes to it on the same reasoning).
//
// The body is read with a limit. What is asked for is a status and a short JSON answer, and a
+2 -2
View File
@@ -57,7 +57,7 @@ func TestAMistypedFlagIsRefusedNotIgnored(t *testing.T) {
}
func TestAnUnexpectedArgumentIsRefused(t *testing.T) {
if _, _, _, err := parseArgs([]string{"bootstrap", "substrate.lock"}); err == nil {
if _, _, _, err := parseArgs([]string{"bootstrap", "foundation.lock"}); err == nil {
t.Fatal("a stray argument was ignored rather than refused — the bundle is --bundle")
}
}
@@ -141,7 +141,7 @@ func TestThePivotsDefaultsAreTheDocumentedOnes(t *testing.T) {
// be a checkout somebody else made, at whatever commit they left it on — and it decides which
// image the mesh's control plane is pinned to for ever after.
if opts.Catalogue != "" {
t.Errorf("--catalog defaults to %q; without one the installer stops at the substrate",
t.Errorf("--catalog defaults to %q; without one the installer stops at the foundation",
opts.Catalogue)
}
// The machine's own name, because that is what a person already calls it.
+1 -1
View File
@@ -823,7 +823,7 @@ func sealOpener(statePath string) apply.Unseal {
// carriedPorts is every machine port held by what this host raised from its own bundle.
//
// **What the mesh must assign around** (novox/hq ADR 0038). The substrate is not a module: a node
// **What the mesh must assign around** (novox/hq ADR 0038). The foundation is not a module: a node
// raises it before any mesh exists, so the control plane has never heard of the store or the
// broker. Told this, it can put a module somewhere else; not told, it hands out a port one of them
// holds and finds out from a container runtime.