diff --git a/README.md b/README.md index a2ac393..2fcd77f 100644 --- a/README.md +++ b/README.md @@ -22,13 +22,15 @@ the host never queries the mesh database. It receives declarations and applies t ## What exists today -**Stage 1 only: it reports.** It applies nothing, connects to nothing, and listens on nothing. +**It reports, and it has begun to apply.** It connects to nothing and listens on nothing. ``` mesh-host profile what this machine can be asked to do mesh-host inventory what this machine is, and what it holds +mesh-host apply FILE make this machine match the declaration in FILE --json machine-readable --timeout how long any single probe may take (default 10s) + --store P where the applied-state store lives (apply) ``` ``` @@ -46,8 +48,12 @@ linux/amd64 cannot be asked to: [firewall privileged] ``` -Stages 2 to 4 — applying from a pinned bundle, the link and the local store, and enrolment — -are designed and not built. +Stage 2 has started: `apply` consumes a declaration (novox/hq ADR 0043) from a local file and +converges this machine, with no mesh present. The first vocabulary is the one that needs no +network — directories and files — applied in the stated order, read back, and recorded so what +was applied and no longer declared is removed, while what the host did not create never is. The +remaining resource types, sealed secrets, the link to the control plane, the pinned substrate +bundle and enrolment are designed and not yet built. ## A capability is detected, never assumed