Apply a run-once container to completion and gate on it (ADR 0052) #5

Merged
jschoubben merged 1 commits from feat/apply-run-once into main 2026-09-05 22:05:09 +00:00
Owner

Implements ADR 0052's host half. applyRunOnce runs the container in the foreground (no detach, no restart) so its exit code returns; a non-zero exit fails and gates the apply (the gate branch, previously action-only, now fires for a failed run-once container too); success records the declaration digest; a matching prior digest short-circuits to unchanged (idempotent). Six unit tests (run-to-completion not detached, non-zero fails, failed step gates the follower, already-completed not re-run, changed declaration re-runs, run-once+restart-on refused). go test ./... green.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Implements ADR 0052's host half. `applyRunOnce` runs the container in the foreground (no detach, no restart) so its exit code returns; a non-zero exit fails and **gates** the apply (the gate branch, previously action-only, now fires for a failed run-once container too); success records the declaration digest; a matching prior digest short-circuits to unchanged (idempotent). Six unit tests (run-to-completion not detached, non-zero fails, failed step gates the follower, already-completed not re-run, changed declaration re-runs, run-once+restart-on refused). `go test ./...` green. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-05 22:04:55 +00:00
A module can declare state but not a step that runs at first boot. This adds
`run-once: true` to the container shape: the host runs it in the foreground,
requires it to exit 0, and records that it did — as the digest of the
declaration, so a re-apply does not re-run it unless the declaration changed.

Because the declaration is applied in order and a failed run-once step gates the
apply the way a failed action does, whatever is declared after the step starts
only once it has completed. That is how "before the broker starts" is enforced,
with no dependency graph the host must resolve (ADR 0005): the step is declared
first, and the container that needs it is never reached until it is done.

No new host shape and no arbitrary host command — a run-once container is
strictly less powerful than an action. Validation refuses run-once with
restart-on (contradictory lifecycles). Six unit tests; go test ./... green.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit 24e9ae4065 into main 2026-09-05 22:05:09 +00:00
jschoubben deleted branch feat/apply-run-once 2026-09-05 22:05:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#5