From d3a6dc97843e81bea6ae5f15ccd1fff9f7033bd7 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 22:23:13 +0200 Subject: [PATCH] The bed adopts only what genesis leaves it: the broker MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Run 3 showed the Phase-3 installer already adopts postgres (superuser included), nftables and the catalogue at genesis — re-registering them was redundant. Only lavinmq and the joined node's consumers are the bed's to add. Issuance is now asserted per module and each module is pushed as it lands, mirroring the one-node bringUp. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- .../built-store-cross-node.test.ts | 22 +++++++++---------- 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/test/integration/built-store-cross-node.test.ts b/test/integration/built-store-cross-node.test.ts index 6029ce8..b323578 100644 --- a/test/integration/built-store-cross-node.test.ts +++ b/test/integration/built-store-cross-node.test.ts @@ -126,8 +126,13 @@ async function buildAndAssign(module: string, node: string, opts?: { build?: boo assert.doesNotMatch(built, /failed/i, built); } const manifest = (await on(CONTROL, `docker exec mesh-controller cat /${module}.json`)).out; - if (manifest.includes("MESH_BROKER_FILE")) await mesh(`module issue ${module} --node ${node}`); + if (manifest.includes("MESH_BROKER_FILE")) { + const issued = await mesh(`module issue ${module} --node ${node}`); + assert.match(issued, /scoped to what it (emits and consumes|consumes and emits)/, + `the broker account for ${module} was not issued:\n${issued}`); + } await mesh(`assign ${node} ${module}`); + await mesh(`push ${node}`, 600_000); } async function waitForContainer(node: string, container: string, seconds = 300): Promise { @@ -205,18 +210,11 @@ test("a joined node's consumers open the store and broker the mesh built and ado const base = await mesh(`build ${forgeUrl(BASE.repo)} --ref ${refFor(BASE.repo)} --wait 1200s`, 1_500_000); assert.doesNotMatch(base, /failed/i, base); - // Adopt the foundation store and broker as the postgres and lavinmq modules, BUILT by the mesh. - // The store's superuser is the foundation's, made at genesis — carried in through `secret accept` - // before the push, or the module mints one the running store does not know. - await buildAndAssign("nftables", CONTROL, { build: false }); - await buildAndAssign("postgres", CONTROL); - const superPw = (await must(CONTROL, - `docker inspect mesh-store --format '{{range .Config.Env}}{{println .}}{{end}}' | sed -n 's/^POSTGRES_PASSWORD=//p'`)).trim(); - await must(CONTROL, `printf %s ${quote(superPw)} > /tmp/superuser && docker cp /tmp/superuser mesh-controller:/superuser`); - await mesh(`secret accept ${CONTROL} postgres superuser --from /superuser`); + // Genesis already adopted the store as the postgres module (superuser accepted), and installed + // nftables and the catalogue — verified rather than redone. The broker is the one foundation + // half genesis leaves to the mesh proper: adopt it here, BUILT by the mesh's own builder. + await waitForContainer(CONTROL, "mesh-postgres", 120); await buildAndAssign("lavinmq", CONTROL); - await mesh(`push ${CONTROL}`, 600_000); - await waitForContainer(CONTROL, "mesh-postgres", 600); await waitForContainer(CONTROL, "mesh-lavinmq", 600); // The consumers on the joined node — built by the mesh, delivered from its registry.