Files
mesh-host/examples
jschoubben 971a6d6d03 A first node gets as far as its own bus: three faults on the way
novox/hq 04-ISSUES/146. Each was right while the mesh ran on the previous
broker, and nothing has raised a foundation since it changed.

The bus's certificate is made by the program that needs it rather than by
openssl inside the broker's image — the bus's image is Alpine with a shell and
no openssl, so the step exited 127 and no mesh could be raised. Self-signed as
before and on purpose; --user 0:0 because the volume is root's and the control
plane's image runs as nobody.

Enrolment no longer opens a raw TLS connection to check the pin: NATS speaks
its own protocol and upgrades afterwards, so the handshake met a plaintext
greeting. The client that presents the token carries the same pinned config
and verifies inside its own handshake, so the secret still leaves only after
the certificate is checked. The raw dial stays as what its tests prove, and is
no longer a path anything takes.

And the token says which bus it is for. Empty meant 'whatever the mesh runs
today' while two buses existed and became a refusal the moment one did.

It now stops at the bus's user list, which is the genesis half of 146.
2026-09-29 15:42:43 +02:00
..

Examples

foundation-first-node.lock

What a machine must be before a mesh exists — the bootstrap in novox/hq 07-the-foundation.md, whole:

0  a container runtime
1  the store runs
2  a database per context        `inventory` and `identity`
3  those contexts' schemas       mesh-controller migrate
4  the broker runs               with a certificate it generated itself
5  the control plane runs        mesh-controller serve

A machine that applies this is a mesh — one node, with nothing joined to it yet, which is exactly what the first node is (novox/hq ADR 0004). From here it hands out tokens and everything else joins the ordinary way.

This file said it stopped at step 4 for longer than that was true, which is its own small lesson: a comment about what something does not do is a comment nobody updates.

Build a host carrying it:

make host SYSTEM=arch BUNDLE=examples/foundation-first-node.lock

The registry address and digests have to be replaced before this is useful. They are written as 192.0.2.250:5000/…@sha256:… because a digest belongs to whatever registry serves it — here, one a lab scenario raises, which reports its digests when it comes up. That is not a placeholder to be tidied away: a bundle is built for a target, and which registry that target pulls from is part of the target.

What was verified, and how

On a lab machine confirmed sealed — curl https://example.com times out, the lab registry answers 200 — the whole bundle applied from bare: eight resources, inventory created and mesh nowhere, the node table present with its indexes, the migration recorded, and LavinMQ answering lavinmqctl status with AMQP listening on 5672.

Three consecutive reconciles after that: already matches — 8 resource(s) checked, each time.

Then the machine was rebooted, and everything came back: docker from boot: enabled, both containers because the host creates every container --restart unless-stopped (internal/apply/apply.go), the schema intact in its named volume, and reconcile still finding nothing to do.

The reboot is worth doing rather than assuming. Nothing in the declaration asks for a container to return, so that it does is a property of the host, and the only way to know it holds is to take the machine away and give it back.