Rename mesh-control -> mesh-controller, substrate -> foundation
One name per thing, per the HQ glossary: the module/container/image/binary/repo becomes mesh-controller, the seat the-controller, and the store+broker pair the foundation (embedded base bundles, default template and example lock renamed with their go:embed directives). No behaviour change — a pure vocabulary rename. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -1,19 +1,19 @@
|
||||
# The FULL mesh in its REAL production shape: two segments, one access point, one overlay.
|
||||
#
|
||||
# This is the first multi-segment whole-mesh bed. The earlier flat whole-mesh-full sat every node
|
||||
# on one public segment with a SEPARATE `anchor` carrying the substrate. Production is not flat, and
|
||||
# on one public segment with a SEPARATE `anchor` carrying the foundation. Production is not flat, and
|
||||
# there is no separate anchor: `novox` IS the anchor. It sits on the routable `hosting` segment,
|
||||
# runs the substrate (store, broker, control) AND its own service set AND is the overlay hub and the
|
||||
# runs the foundation (store, broker, control) AND its own service set AND is the overlay hub and the
|
||||
# public ingress. `ace`, `shanks` and `g14` sit on the household `home` segment BEHIND a NAT gateway
|
||||
# — the access point — reachable from the outside only through what they dial out to.
|
||||
#
|
||||
# hosting (public, routable) home (private, behind the access point)
|
||||
# novox 192.0.2.20 ── anchor ace 10.99.1.10 home server, media/IoT set
|
||||
# substrate + novox set shanks 10.99.1.20 workstation (light)
|
||||
# foundation + novox set shanks 10.99.1.20 workstation (light)
|
||||
# overlay hub, ingress g14 10.99.1.30 workstation (light)
|
||||
#
|
||||
# The `home` gateway masquerades v4 outbound and forwards inbound (an ordinary household router).
|
||||
# Home nodes reach novox's public 192.0.2.20 by dialling OUT through it: the substrate broker (5671),
|
||||
# Home nodes reach novox's public 192.0.2.20 by dialling OUT through it: the foundation broker (5671),
|
||||
# the mesh's own artifact store, and — the thing this bed exists to prove — the WireGuard overlay hub
|
||||
# (51820/udp). The hub keepalive holds the NAT hole open so the tunnel, once formed, stays up. novox
|
||||
# cannot initiate to a home node at all; every home↔novox path is either the overlay or a forwarded
|
||||
@@ -35,20 +35,20 @@
|
||||
# the gateway's masquerade? The driving test verifies the WireGuard handshake and cross-segment
|
||||
# reachability over the overlay explicitly, and reports form-vs-break as its headline.
|
||||
#
|
||||
# Substrate-on-novox collides on two host ports the separate-anchor beds never hit: the substrate
|
||||
# store binds 127.0.0.1:5432 and novox's postgres provider publishes 5432; the substrate broker binds
|
||||
# Foundation-on-novox collides on two host ports the separate-anchor beds never hit: the foundation
|
||||
# store binds 127.0.0.1:5432 and novox's postgres provider publishes 5432; the foundation broker binds
|
||||
# 5671 + 127.0.0.1:5672 and novox's lavinmq provider publishes 5672. The driving test REMAPS those two
|
||||
# provider host publishes off the substrate's ports (consumers reach the providers over the mesh
|
||||
# provider host publishes off the foundation's ports (consumers reach the providers over the mesh
|
||||
# network on the container port, so the host side is free to move). Reported as a topology finding.
|
||||
#
|
||||
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock
|
||||
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
# MESH_LAB_BOOTSTRAP_BINARY=.../mesh-bootstrap MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
#
|
||||
# GENESIS AND JOINING ARE TWO DIFFERENT ACTS, and this bed distinguishes them. novox is brought
|
||||
# into existence by `mesh-bootstrap` — the same program a bare machine runs — and is afterwards a
|
||||
# working mesh of one, with a registry and a control plane that is an ordinary module pinned to an
|
||||
# image that registry serves. ace, shanks and g14 then JOIN it: host binary, token, enrol, run. No
|
||||
# bootstrap, no substrate, no registry. novox is never enrolled twice, because the installer
|
||||
# bootstrap, no foundation, no registry. novox is never enrolled twice, because the installer
|
||||
# already did it.
|
||||
#
|
||||
# The images: are the UNION of the novox set (feat/novox-conversions @ 431310f: the slug + roundcube
|
||||
@@ -76,8 +76,8 @@ segments:
|
||||
mapping_ttl: 120s
|
||||
|
||||
machines:
|
||||
# The anchor: substrate (store, broker, control) + the whole novox service set + overlay hub +
|
||||
# public ingress. Bigger than the flat bed's novox, because it now carries the substrate too.
|
||||
# The anchor: foundation (store, broker, control) + the whole novox service set + overlay hub +
|
||||
# public ingress. Bigger than the flat bed's novox, because it now carries the foundation too.
|
||||
novox:
|
||||
at: { segment: hosting, address: [192.0.2.20] }
|
||||
egress: true
|
||||
@@ -90,7 +90,7 @@ machines:
|
||||
# because they carry no runtime image of their own — what they run is third-party or is the
|
||||
# node itself.
|
||||
#
|
||||
# **mesh-control is NOT here, and its absence is the point** (novox/hq ADR 0067). The anchor is
|
||||
# **mesh-controller is NOT here, and its absence is the point** (novox/hq ADR 0067). The anchor is
|
||||
# brought into existence by the installer, and the installer carries the control plane's image
|
||||
# inside itself — that is the whole reason a machine that can reach no registry can still raise
|
||||
# a mesh. Handing it over from the workstation as well would mean the bed never found out
|
||||
|
||||
Reference in New Issue
Block a user