From 88037b33b708dfdf686501c84ce52f0ba5d442df Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 30 Sep 2026 14:38:11 +0200 Subject: [PATCH] Say what a container's host entries now are novox/hq ADR 0148: the mesh's names are no longer among them, only what the module declared. Comment only; the digest is unchanged. --- internal/apply/apply.go | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/internal/apply/apply.go b/internal/apply/apply.go index 1a86bba..8293d98 100644 --- a/internal/apply/apply.go +++ b/internal/apply/apply.go @@ -1501,13 +1501,15 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s for _, a := range r.Args { b.WriteString("arg " + a + "\n") } - // **The mesh's names are part of what a container is** (novox/hq 04-ISSUES/135). A container - // resolves every other machine and every public name through the entries the mesh gives it at - // creation, and nothing re-reads them afterwards — so a container left alone when the roster - // moved is one that cannot reach anything by name, for ever, while every check reports it - // running. That is exactly what happened when this mesh's overlay range changed: one container - // whose image and files never changed kept an address five days out of date and restarted - // 2286 times against a database it could no longer find. + // **A container's declared names are part of what it is** (novox/hq 04-ISSUES/135). What is + // here is what the module declared for itself and nothing else: the mesh's own names are no + // longer written into a container (ADR 0148) — they were once, every container got the whole + // roster at creation and nothing re-read it, so one left alone when the roster moved could not + // reach anything by name for as long as it ran while every check reported it running; and once + // the roster was in this digest so that could be caught, one name moving anywhere replaced + // every container in the mesh (04-ISSUES/151). A container resolves a mesh name through the + // machine's resolver at the moment it asks. What a module declares does not move when the + // roster does, so hashing it costs nothing and catches a manifest that changed. // // Sorted, so the digest does not move for a reordering nobody made. hosts := append([]string(nil), r.Hosts...)