Rename mesh-control -> mesh-controller, substrate -> foundation

One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 18:40:40 +02:00
parent 49b80d8516
commit 5d6e8fbe7a
89 changed files with 785 additions and 785 deletions
+14 -14
View File
@@ -12,7 +12,7 @@
* ordinary sealed-delivery path — with NO manager, NO refresh, NO access/refresh split, NO usage. The
* whole of OpenAI's integration in the control plane is one registry line (vendor -> static-key).
*
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
* Build the consumer runtime image into the local daemon first:
* scripts/build-module-runtime.sh openai-consumer /tmp/openai-consumer.tar
*/
@@ -24,7 +24,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
import { raise } from "../../src/lifecycle/raise.ts";
import { destroy, exec } from "../../src/lifecycle/operate.ts";
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
import { labIsUsable, destroyAll, substrateBundle, onTheMachine } from "./harness.ts";
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts";
import type { HeldImage } from "../../src/pinning.ts";
const capability = await labIsUsable();
@@ -36,7 +36,7 @@ const skip = !capability.usable
: !binary || !existsSync(binary)
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
: !bundle || !existsSync(bundle)
? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)"
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
: false;
const SCENARIO = "openai-bed";
@@ -69,11 +69,11 @@ async function must(command: string, timeoutMs?: number): Promise<string> {
}
async function mesh(command: string, timeoutMs?: number): Promise<string> {
return must(`docker exec mesh-control /mesh-control ${command}`, timeoutMs);
return must(`docker exec mesh-controller /mesh-controller ${command}`, timeoutMs);
}
async function meshTry(command: string): Promise<{ out: string; ok: boolean }> {
return on(`docker exec mesh-control /mesh-control ${command}`);
return on(`docker exec mesh-controller /mesh-controller ${command}`);
}
/** What a manifest's image reference becomes on the machine — ours by ID, everything else as written. */
@@ -82,7 +82,7 @@ function pinned(reference: string): string {
}
function bundleFor(images: HeldImage[]): string {
return substrateBundle(bundle, images);
return foundationBundle(bundle, images);
}
function tokenFrom(said: string): string {
@@ -135,11 +135,11 @@ before(async () => {
instanceId = raised.instanceId;
held = raised.images;
await must(`cat > /tmp/substrate.lock <<'MESHBUNDLE'\n${bundleFor(raised.images)}\nMESHBUNDLE`);
await must(`${HOST_PATH} apply /tmp/substrate.lock`, 600_000);
await must(`cat > /tmp/foundation.lock <<'MESHBUNDLE'\n${bundleFor(raised.images)}\nMESHBUNDLE`);
await must(`${HOST_PATH} apply /tmp/foundation.lock`, 600_000);
const up = await must(`docker ps --format '{{.Names}}'`);
for (const c of ["mesh-store", "mesh-broker", "mesh-control"]) {
assert.match(up, new RegExp(c), `the substrate did not raise ${c}:\n${up}`);
for (const c of ["mesh-store", "mesh-broker", "mesh-controller"]) {
assert.match(up, new RegExp(c), `the foundation did not raise ${c}:\n${up}`);
}
await mesh(`node add ${MACHINE}`);
@@ -159,7 +159,7 @@ test("a static-key model-access licence delivers the operator's API key to the c
const consumerImage = pinned("mesh-runtime-openai-consumer");
// --- the licence, a record with vendor openai (static-key) -------------------------------------
// No manager: a static-key licence has none (mesh-control refuses `licence manager` on it). The
// No manager: a static-key licence has none (mesh-controller refuses `licence manager` on it). The
// consumer is put on the licence BEFORE the key is set — the static-key adapter's Accept seals to the
// CURRENT holders, so a holder must exist first, or the key would seal to nobody.
await mesh(`licence add openai personal --serves '{"model":"gpt-model"}'`);
@@ -167,8 +167,8 @@ test("a static-key model-access licence delivers the operator's API key to the c
// The operator sets the static key. `licence key` reads it from a file (never a CLI arg) and seals it
// to the holder; the plaintext is discarded by the control plane. Staged 0644 so distroless
// mesh-control can read the file (docker cp preserves the mode).
await must(`printf %s ${quote(API_KEY)} > /tmp/openai-key && chmod 0644 /tmp/openai-key && docker cp /tmp/openai-key mesh-control:/openai-key`);
// mesh-controller can read the file (docker cp preserves the mode).
await must(`printf %s ${quote(API_KEY)} > /tmp/openai-key && chmod 0644 /tmp/openai-key && docker cp /tmp/openai-key mesh-controller:/openai-key`);
await mesh(`licence key personal --file /openai-key`);
// --- deploy the consumer -----------------------------------------------------------------------
@@ -199,7 +199,7 @@ test("a static-key model-access licence delivers the operator's API key to the c
},
],
});
await must(`printf %s ${quote(consumerManifest)} > /tmp/openai-consumer.json && docker cp /tmp/openai-consumer.json mesh-control:/openai-consumer.json`);
await must(`printf %s ${quote(consumerManifest)} > /tmp/openai-consumer.json && docker cp /tmp/openai-consumer.json mesh-controller:/openai-consumer.json`);
await mesh(`module add /openai-consumer.json`);
await mesh(`module issue openai-consumer --node ${MACHINE}`);
await mesh(`assign ${MACHINE} openai-consumer`);