The host applies the newest declaration, a file may be created once, the foundation filters first
031: a window of unacknowledged declarations is drained to the newest; the rest are set aside and reported as superseded. 035: a file resource may say create-once — written when absent, kept untouched when present (ADR 0087). 054: the bundle installs nftables and loads a base ruleset before the store and broker, in the table the filter module later replaces (ADR 0088).
This commit is contained in:
@@ -135,6 +135,19 @@ type File struct {
|
||||
Content string `json:"content"`
|
||||
Mode string `json:"mode,omitempty"`
|
||||
|
||||
// CreateOnce says the content is a seed: written when the file is absent, and left alone —
|
||||
// content, mode and owner — whenever it is present.
|
||||
//
|
||||
// **Two intentions had one vocabulary** (novox/hq issue 035, ADR 0087). "This file has this
|
||||
// content, for ever" is what an ordinary file says, and the host holds the machine to it. A
|
||||
// module that needs a file to exist before a program first starts — an access list the
|
||||
// program then persists into, a bootstrap configuration it rewrites — needs the other thing,
|
||||
// and with only the first available, every reconcile restored the seed behind the running
|
||||
// program and erased what had grown in it, reporting success. What grows in a seeded file
|
||||
// is somebody else's work the mesh asked for; the mesh removes nothing it did not create
|
||||
// (ADR 0030), and it does not overwrite that either.
|
||||
CreateOnce bool `json:"create-once,omitempty"`
|
||||
|
||||
// Sealed is content encrypted to this node's sealing key, for a file the mesh must deliver
|
||||
// without being able to read.
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user