A machine moves to the bus its declaration tells it to #34

Merged
jschoubben merged 1 commits from feat/a-machine-moves-to-the-bus-it-is-told into main 2026-09-27 22:09:09 +00:00
Owner

Until now a membership — bus address, fingerprint, password — was written once, at enrolment, and nothing ever rewrote it, so a machine already enrolled could not be moved to another bus at all (design 28, task 5.2).

The mesh now delivers a membership for the new bus as a sealed file in the declaration (/var/lib/mesh/membership-next.json), like any secret. The host reads it after the declaration has applied, saves it as its identity, and exits cleanly so the service manager restarts it dialling the bus it names — the same path a machine takes after a reboot, so nothing new has to be right for it to work. A membership carries its transport; empty means the bus the mesh ran on before, so nothing written earlier reads as unset. A delivered membership identical to the one held is nothing.

Pairs with the controller change that mints and composes these.

Until now a membership — bus address, fingerprint, password — was written once, at enrolment, and nothing ever rewrote it, so a machine already enrolled could not be moved to another bus at all (design 28, task 5.2). The mesh now delivers a membership for the new bus as a sealed file in the declaration (`/var/lib/mesh/membership-next.json`), like any secret. The host reads it after the declaration has applied, saves it as its identity, and exits cleanly so the service manager restarts it dialling the bus it names — the same path a machine takes after a reboot, so nothing new has to be right for it to work. A membership carries its transport; empty means the bus the mesh ran on before, so nothing written earlier reads as unset. A delivered membership identical to the one held is nothing. Pairs with the controller change that mints and composes these.
jschoubben added 1 commit 2026-09-27 22:08:58 +00:00
Until now a membership — bus address, fingerprint, password — was written once,
at enrolment, and nothing ever rewrote it, so a machine already enrolled could not
be moved to another bus at all (novox/hq design 28, task 5.2). The mesh now
delivers a membership for the new bus as a sealed file in the declaration, like
any secret; the host reads it after the declaration has applied, saves it as its
identity, and exits cleanly so the service manager restarts it dialling the bus it
names. The same path a machine takes after a reboot — so nothing new has to be
right for it to work. A membership carries its transport; empty means the bus the
mesh ran on before, so nothing written earlier reads as unset.
jschoubben merged commit d82fc9a121 into main 2026-09-27 22:09:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#34