Rename mesh-control -> mesh-controller, substrate -> foundation

One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 18:40:40 +02:00
parent 49b80d8516
commit 5d6e8fbe7a
89 changed files with 785 additions and 785 deletions
+17 -17
View File
@@ -10,7 +10,7 @@
* **What changed from the earlier cut, and why this is simpler.** The refresh token no longer rides a
* bespoke at-rest envelope the module opens with a node private key the mesh must somehow place — a
* module is never given a node's private key, so that path could not exist. It rides the ORDINARY
* sealed-delivery path instead: mesh-control (via the manager module at adoption) seals it to the
* sealed-delivery path instead: mesh-controller (via the manager module at adoption) seals it to the
* manager node's PUBLIC key, and the HOST unseals it with that node's real private key and mounts the
* cleartext at the manager module's bound secret path — exactly as a consumer's db password arrives.
* So there is no fake node key pair mounted here any more; the host's own real sealing key does the
@@ -32,11 +32,11 @@
* ~/.claude/.credentials.json, access-token-only.
*
* STUBBED, and flagged in the report: (a) the vendor OAuth endpoint (a node stub); (b) the submit
* transport (the test invokes `mesh-control licence submit-refresh` on the manager's output, standing
* transport (the test invokes `mesh-controller licence submit-refresh` on the manager's output, standing
* in for the authenticated cross-node call a manager node would make). The node-private-key stub of
* the earlier cut is GONE — the host uses its own real key.
*
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
* Build both runtime images into the local daemon first:
* scripts/build-module-runtime.sh anthropic-manager /tmp/anthropic-manager.tar
* scripts/build-module-runtime.sh anthropic-consumer /tmp/anthropic-consumer.tar
@@ -49,7 +49,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
import { raise } from "../../src/lifecycle/raise.ts";
import { destroy, exec } from "../../src/lifecycle/operate.ts";
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
import { labIsUsable, destroyAll, substrateBundle, onTheMachine } from "./harness.ts";
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts";
import type { HeldImage } from "../../src/pinning.ts";
const capability = await labIsUsable();
@@ -61,7 +61,7 @@ const skip = !capability.usable
: !binary || !existsSync(binary)
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)"
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
: false;
const SCENARIO = "anthropic-bed";
@@ -96,22 +96,22 @@ async function must(command: string, timeoutMs?: number): Promise<string> {
}
async function mesh(command: string, timeoutMs?: number): Promise<string> {
return must(`docker exec mesh-control /mesh-control ${command}`, timeoutMs);
return must(`docker exec mesh-controller /mesh-controller ${command}`, timeoutMs);
}
// The manager's adopt/refresh runtime writes its outputs as root, mode 0600 (secret files). To hand
// one to `mesh-control` — whose process runs as a non-root user — the test relaxes the mode on the
// one to `mesh-controller` — whose process runs as a non-root user — the test relaxes the mode on the
// anchor host (where `must` is root) and then copies it in: `docker cp` preserves the source mode, so
// the file lands 0644 and mesh-control (a distroless image with no `chmod` of its own) can read it.
// the file lands 0644 and mesh-controller (a distroless image with no `chmod` of its own) can read it.
// What is staged this way is a sealed box or the access token, never a cleartext refresh token, so a
// world-readable copy discloses nothing the control plane does not already hold. In production the
// operator who ran adopt owns the file and this does not arise.
async function stageIntoControl(hostPath: string, dest: string): Promise<void> {
await must(`chmod 0644 ${hostPath} && docker cp ${hostPath} mesh-control:${dest}`);
await must(`chmod 0644 ${hostPath} && docker cp ${hostPath} mesh-controller:${dest}`);
}
async function meshTry(command: string): Promise<{ out: string; ok: boolean }> {
return on(`docker exec mesh-control /mesh-control ${command}`);
return on(`docker exec mesh-controller /mesh-controller ${command}`);
}
/** What a manifest's image reference becomes on the machine — ours by ID, everything else as written. */
@@ -120,7 +120,7 @@ function pinned(reference: string): string {
}
function bundleFor(images: HeldImage[]): string {
return substrateBundle(bundle, images);
return foundationBundle(bundle, images);
}
function tokenFrom(said: string): string {
@@ -173,11 +173,11 @@ before(async () => {
instanceId = raised.instanceId;
held = raised.images;
await must(`cat > /tmp/substrate.lock <<'MESHBUNDLE'\n${bundleFor(raised.images)}\nMESHBUNDLE`);
await must(`${HOST_PATH} apply /tmp/substrate.lock`, 600_000);
await must(`cat > /tmp/foundation.lock <<'MESHBUNDLE'\n${bundleFor(raised.images)}\nMESHBUNDLE`);
await must(`${HOST_PATH} apply /tmp/foundation.lock`, 600_000);
const up = await must(`docker ps --format '{{.Names}}'`);
for (const c of ["mesh-store", "mesh-broker", "mesh-control"]) {
assert.match(up, new RegExp(c), `the substrate did not raise ${c}:\n${up}`);
for (const c of ["mesh-store", "mesh-broker", "mesh-controller"]) {
assert.match(up, new RegExp(c), `the foundation did not raise ${c}:\n${up}`);
}
await mesh(`node add ${MACHINE}`);
@@ -239,7 +239,7 @@ test("model access refreshes on the manager node and delivers only the access to
},
],
});
await must(`printf %s ${quote(managerManifest)} > /tmp/anthropic-manager.json && docker cp /tmp/anthropic-manager.json mesh-control:/anthropic-manager.json`);
await must(`printf %s ${quote(managerManifest)} > /tmp/anthropic-manager.json && docker cp /tmp/anthropic-manager.json mesh-controller:/anthropic-manager.json`);
await mesh(`module add /anthropic-manager.json`);
await mesh(`module issue anthropic-manager --node ${MACHINE}`);
await mesh(`assign ${MACHINE} anthropic-manager`);
@@ -355,7 +355,7 @@ test("model access refreshes on the manager node and delivers only the access to
},
],
});
await must(`printf %s ${quote(consumerManifest)} > /tmp/anthropic-consumer.json && docker cp /tmp/anthropic-consumer.json mesh-control:/anthropic-consumer.json`);
await must(`printf %s ${quote(consumerManifest)} > /tmp/anthropic-consumer.json && docker cp /tmp/anthropic-consumer.json mesh-controller:/anthropic-consumer.json`);
await mesh(`module add /anthropic-consumer.json`);
await mesh(`module issue anthropic-consumer --node ${MACHINE}`);
await mesh(`assign ${MACHINE} anthropic-consumer`);