Six beds retired: their coverage lives in the catalogue beds and the whole-mesh beds now

The four sidecar beds (grafana, plex, sonarr, redis) proved a sidecar comes up and
serves tools with the module's server cut away; the catalogue beds and the whole-mesh
beds prove the modules whole. The minio and postgres grant beds proved a grant
mechanism with a second store beside the foundation's; the grant bed and the vault bed
prove it against the catalogue. Ten conversions become six deletions (novox/hq
04-ISSUES/074).
This commit is contained in:
2026-09-21 21:53:11 +02:00
parent 543ccb7380
commit 26177d81be
12 changed files with 1 additions and 1544 deletions
-30
View File
@@ -1,30 +0,0 @@
# One machine that becomes a mesh and grants a consumer an S3 bucket from an assigned minio provider.
#
# The postgres bed proves the provider/consumer contract for a database; this proves it for object
# storage (novox/hq ADR 0052/0053), on a provider whose code drives the `mc` CLI (so the runtime image
# carries it): minio is assigned, a consumer that requires s3-bucket is assigned, and the mesh mints
# one secret key; minio's provisioner creates a bucket and a service account under the access key the
# mesh derived with the secret it minted, and the consumer reaches its bucket with only that.
scenario: minio-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
# minio's runtime, built by scripts/build-module-runtime.sh minio (it carries mc), loaded onto
# the machine.
- mesh-runtime-minio:development
place:
all: [host, runtime]
-30
View File
@@ -1,30 +0,0 @@
# One machine that becomes a mesh and then assigns itself plex's tool runtime.
#
# The audit-node bed proved an assigned *consumer* (novox/hq ADR 0048). This proves an assigned
# module that *serves tools* (ADR 0052): the same first-node foundation, plus plex's tool runtime on
# top. The node enrols itself, the mesh issues plex a broker account scoped to serve.plex.* and
# assigns it, the host runs the runtime container, and a caller invokes plex.plex_reachable over the
# mesh — proof the module runs its own code as its own process under its own scoped account.
scenario: plex-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
# Plex's tool runtime, built by scripts/build-module-runtime.sh plex into the local daemon and
# loaded onto the machine, which holds it by its own image ID.
- mesh-runtime-plex:development
place:
all: [host, runtime]
-29
View File
@@ -1,29 +0,0 @@
# One machine that becomes a mesh and grants a consumer a database from an assigned postgres provider.
#
# The redis mesh-grant bed proves the whole provider/consumer contract for a cache; this proves it for
# a database (novox/hq ADR 0052/0053): postgres's runtime carries psql, its provisioner creates a role
# and database under the login the mesh derived with the password the mesh minted, and a consumer
# connects to its own database with only what the mesh delivered.
scenario: postgres-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
# postgres's runtime, built by scripts/build-module-runtime.sh postgres (it carries psql), loaded
# onto the machine.
- mesh-runtime-postgres:development
place:
all: [host, runtime]
+1 -1
View File
@@ -1,6 +1,6 @@
# One machine that becomes a mesh and then assigns itself redis — a *provider* module.
#
# plex-node proves an assigned module that serves tools (novox/hq ADR 0052). This proves the same
# A bed proving an assigned module that serves tools (novox/hq ADR 0052) once lived beside this; this proves the same
# for a provider: redis's runtime runs its provisioner AND its tools as one process under one scoped
# broker account. The provisioner emitting a lifecycle event is the thing 0052 fixes — before it,
# the provisioner ran in a container with no broker and its emit could not fire.
-27
View File
@@ -1,27 +0,0 @@
# One machine that becomes a mesh and assigns itself sonarr's tool runtime.
#
# plex-node proved a tools+events module that self-detects its token from a mounted config dir; this
# proves the same self-configuring pattern generalises to the Servarr family (novox/hq ADR 0052):
# sonarr's runtime detects its API key from the server's config.xml and serves sonarr's tools over a
# mesh-issued scoped account, with no live Sonarr to reach.
scenario: sonarr-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
- mesh-runtime-sonarr:development
place:
all: [host, runtime]