Rename mesh-control -> mesh-controller, substrate -> foundation
One name per thing, per the HQ glossary: the module/container/image/binary/repo becomes mesh-controller, the seat the-controller, and the store+broker pair the foundation (embedded base bundles, default template and example lock renamed with their go:embed directives). No behaviour change — a pure vocabulary rename. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -14,7 +14,7 @@ import (
|
||||
// storeFileSuffix is how a manifest asks for a store connection in a file rather than in the
|
||||
// environment.
|
||||
//
|
||||
// `MESH_STORE_<CONTEXT>` is what the control plane reads (mesh-control's `internal/store`.Variable)
|
||||
// `MESH_STORE_<CONTEXT>` is what the control plane reads (mesh-controller's `internal/store`.Variable)
|
||||
// and putting a password in a container's environment puts it in `docker inspect` for ever. So a
|
||||
// module manifest names a file per context and points at it with `…_FILE`; the mesh seals the value
|
||||
// into that file on the machine, and nothing but the process reads it.
|
||||
@@ -41,20 +41,20 @@ type Permanent struct {
|
||||
// **The host performs the replacement, not the control plane** (novox/hq ADR 0067). The temporary
|
||||
// control plane composes a declaration naming the registry-pinned image, publishes it, and this
|
||||
// node's host creates the container. Nothing is asked to replace itself while running, which is
|
||||
// what makes the whole thing expressible: the container being created is called `mesh-control` and
|
||||
// the one composing it is called `temp-mesh-control`, so there are two of them and neither is in
|
||||
// what makes the whole thing expressible: the container being created is called `mesh-controller` and
|
||||
// the one composing it is called `temp-mesh-controller`, so there are two of them and neither is in
|
||||
// the other's way.
|
||||
//
|
||||
// **The store connections are the substrate's, made at genesis, and the mesh cannot invent them.**
|
||||
// **The store connections are the foundation's, made at genesis, and the mesh cannot invent them.**
|
||||
// Every other secret in a mesh is one the mesh made; these existed before the mesh did — they are
|
||||
// the credentials the substrate bundle created the databases with. Generating replacements would
|
||||
// the credentials the foundation bundle created the databases with. Generating replacements would
|
||||
// put thirty-two random bytes where a working connection string has to be, and the control plane
|
||||
// would come up unable to open a single context. So they go in through `secret accept`, which is
|
||||
// exactly the path for a value the mesh must carry and could not have invented — and they are read
|
||||
// out of the bundle this installer produced rather than reconstructed, because the bundle is what
|
||||
// created them and a second opinion about what a DSN should say is a second chance to be wrong.
|
||||
func InstallControlPlane(ctx context.Context, o Options, d Deps, control controlPlane,
|
||||
substrate *declaration.Declaration, image string, say func(string)) (Permanent, error) {
|
||||
foundation *declaration.Declaration, image string, say func(string)) (Permanent, error) {
|
||||
|
||||
out := Permanent{Image: image}
|
||||
|
||||
@@ -63,7 +63,7 @@ func InstallControlPlane(ctx context.Context, o Options, d Deps, control control
|
||||
return out, fmt.Errorf(
|
||||
"%w\n"+
|
||||
"This is the manifest that makes the control plane an ordinary module. Without it "+
|
||||
"the machine keeps the temporary control plane the substrate raised, which works "+
|
||||
"the machine keeps the temporary control plane the foundation raised, which works "+
|
||||
"and cannot be upgraded — so the install stops here rather than pretending to "+
|
||||
"have pivoted", err)
|
||||
}
|
||||
@@ -92,7 +92,7 @@ func InstallControlPlane(ctx context.Context, o Options, d Deps, control control
|
||||
}
|
||||
|
||||
// The connections, before the push that would otherwise deliver random bytes for them.
|
||||
delivered, err := deliverStores(ctx, o, control, pinned, substrate, say)
|
||||
delivered, err := deliverStores(ctx, o, control, pinned, foundation, say)
|
||||
out.Delivered = delivered
|
||||
if err != nil {
|
||||
return out, err
|
||||
@@ -107,7 +107,7 @@ func InstallControlPlane(ctx context.Context, o Options, d Deps, control control
|
||||
}
|
||||
// And it answers, which is the same question step 5 asked of the temporary one and for the
|
||||
// same reason: `status` opens all three stores, so a reply proves the sealed connections it
|
||||
// was given are the ones the substrate made. Asked of the NEW container — this is the only
|
||||
// was given are the ones the foundation made. Asked of the NEW container — this is the only
|
||||
// moment in the program where two control planes are running, and asking the wrong one would
|
||||
// report the temporary one's health as the permanent one's.
|
||||
answered, err := waitForTheControlPlane(ctx, control.run, o.Timeout, o.Wait, container, say)
|
||||
@@ -142,7 +142,7 @@ func pinImage(manifest []byte, reference string) ([]byte, int, error) {
|
||||
}
|
||||
// The reference the registry gave back is `<registry>/<repository>@sha256:…`, and what the
|
||||
// manifest holds is `<something>@sha256:0…0`. Replacing only the digest would leave the
|
||||
// manifest's own repository name in front of it — which may be `mesh-control` with no
|
||||
// manifest's own repository name in front of it — which may be `mesh-controller` with no
|
||||
// registry, and a runtime would then pull it from the internet. The whole reference moves.
|
||||
var out bytes.Buffer
|
||||
rest := manifest
|
||||
@@ -215,21 +215,21 @@ func controlPlaneResourceIn(manifest []byte) string {
|
||||
return ""
|
||||
}
|
||||
|
||||
// deliverStores carries the substrate's own database connections into the module.
|
||||
// deliverStores carries the foundation's own database connections into the module.
|
||||
//
|
||||
// The pairing is read from the manifest rather than assumed, so that whatever the catalogue calls
|
||||
// these secrets is what is delivered. The installer does not guess that the secret holding the
|
||||
// inventory connection is called `inventory`; it follows the manifest from the variable to the
|
||||
// secret, and a manifest whose two ends do not meet is refused rather than half-delivered.
|
||||
//
|
||||
// **What is delivered is what the substrate already has, and only that.** The mesh generates an
|
||||
// **What is delivered is what the foundation already has, and only that.** The mesh generates an
|
||||
// own-secret nobody supplied, which is right for something coming into existence and wrong for
|
||||
// something that already exists. So every variable the module fills from a secret is looked up in
|
||||
// the substrate's control plane: what it names is accepted, what it does not is left for the mesh
|
||||
// to make. A store connection missing from the substrate is the one exception and is an error —
|
||||
// the foundation's control plane: what it names is accepted, what it does not is left for the mesh
|
||||
// to make. A store connection missing from the foundation is the one exception and is an error —
|
||||
// a control plane that cannot open a context is not a control plane.
|
||||
func deliverStores(ctx context.Context, o Options, control controlPlane, manifest []byte,
|
||||
substrate *declaration.Declaration, say func(string)) ([]string, error) {
|
||||
foundation *declaration.Declaration, say func(string)) ([]string, error) {
|
||||
|
||||
wanted, err := secretsByVariableIn(manifest)
|
||||
if err != nil {
|
||||
@@ -246,7 +246,7 @@ func deliverStores(ctx context.Context, o Options, control controlPlane, manifes
|
||||
ControlPlaneModule, storeVariablePrefix, storeVariablePrefix, storeFileSuffix)
|
||||
}
|
||||
|
||||
temporary, err := controlPlaneIn(substrate)
|
||||
temporary, err := controlPlaneIn(foundation)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -260,13 +260,13 @@ func deliverStores(ctx context.Context, o Options, control controlPlane, manifes
|
||||
return delivered, fmt.Errorf(
|
||||
"the %s module wants %s and the bundle this installer produced does not name "+
|
||||
"one.\n"+
|
||||
"That connection is the substrate's, created at genesis — the mesh cannot "+
|
||||
"That connection is the foundation's, created at genesis — the mesh cannot "+
|
||||
"invent it and the installer will not guess at one",
|
||||
ControlPlaneModule, variable)
|
||||
}
|
||||
// Not something the substrate made. The mesh generates its own, which is exactly what
|
||||
// Not something the foundation made. The mesh generates its own, which is exactly what
|
||||
// an own-secret is for; said so that nothing about the delivery is silent.
|
||||
say(" the mesh will make " + secret + " — the substrate names no " + variable)
|
||||
say(" the mesh will make " + secret + " — the foundation names no " + variable)
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -282,7 +282,7 @@ func deliverStores(ctx context.Context, o Options, control controlPlane, manifes
|
||||
return delivered, err
|
||||
}
|
||||
delivered = append(delivered, secret)
|
||||
say(" accepted " + secret + " — " + variable + ", as the substrate made it")
|
||||
say(" accepted " + secret + " — " + variable + ", as the foundation made it")
|
||||
}
|
||||
return delivered, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user