The bed adopts only what genesis leaves it: the broker

Run 3 showed the Phase-3 installer already adopts postgres (superuser included), nftables
and the catalogue at genesis — re-registering them was redundant. Only lavinmq and the
joined node's consumers are the bed's to add. Issuance is now asserted per module and each
module is pushed as it lands, mirroring the one-node bringUp.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-17 22:23:13 +02:00
parent bfd70e9e57
commit d3a6dc9784
+10 -12
View File
@@ -126,8 +126,13 @@ async function buildAndAssign(module: string, node: string, opts?: { build?: boo
assert.doesNotMatch(built, /failed/i, built); assert.doesNotMatch(built, /failed/i, built);
} }
const manifest = (await on(CONTROL, `docker exec mesh-controller cat /${module}.json`)).out; const manifest = (await on(CONTROL, `docker exec mesh-controller cat /${module}.json`)).out;
if (manifest.includes("MESH_BROKER_FILE")) await mesh(`module issue ${module} --node ${node}`); if (manifest.includes("MESH_BROKER_FILE")) {
const issued = await mesh(`module issue ${module} --node ${node}`);
assert.match(issued, /scoped to what it (emits and consumes|consumes and emits)/,
`the broker account for ${module} was not issued:\n${issued}`);
}
await mesh(`assign ${node} ${module}`); await mesh(`assign ${node} ${module}`);
await mesh(`push ${node}`, 600_000);
} }
async function waitForContainer(node: string, container: string, seconds = 300): Promise<string> { async function waitForContainer(node: string, container: string, seconds = 300): Promise<string> {
@@ -205,18 +210,11 @@ test("a joined node's consumers open the store and broker the mesh built and ado
const base = await mesh(`build ${forgeUrl(BASE.repo)} --ref ${refFor(BASE.repo)} --wait 1200s`, 1_500_000); const base = await mesh(`build ${forgeUrl(BASE.repo)} --ref ${refFor(BASE.repo)} --wait 1200s`, 1_500_000);
assert.doesNotMatch(base, /failed/i, base); assert.doesNotMatch(base, /failed/i, base);
// Adopt the foundation store and broker as the postgres and lavinmq modules, BUILT by the mesh. // Genesis already adopted the store as the postgres module (superuser accepted), and installed
// The store's superuser is the foundation's, made at genesis — carried in through `secret accept` // nftables and the catalogue — verified rather than redone. The broker is the one foundation
// before the push, or the module mints one the running store does not know. // half genesis leaves to the mesh proper: adopt it here, BUILT by the mesh's own builder.
await buildAndAssign("nftables", CONTROL, { build: false }); await waitForContainer(CONTROL, "mesh-postgres", 120);
await buildAndAssign("postgres", CONTROL);
const superPw = (await must(CONTROL,
`docker inspect mesh-store --format '{{range .Config.Env}}{{println .}}{{end}}' | sed -n 's/^POSTGRES_PASSWORD=//p'`)).trim();
await must(CONTROL, `printf %s ${quote(superPw)} > /tmp/superuser && docker cp /tmp/superuser mesh-controller:/superuser`);
await mesh(`secret accept ${CONTROL} postgres superuser --from /superuser`);
await buildAndAssign("lavinmq", CONTROL); await buildAndAssign("lavinmq", CONTROL);
await mesh(`push ${CONTROL}`, 600_000);
await waitForContainer(CONTROL, "mesh-postgres", 600);
await waitForContainer(CONTROL, "mesh-lavinmq", 600); await waitForContainer(CONTROL, "mesh-lavinmq", 600);
// The consumers on the joined node — built by the mesh, delivered from its registry. // The consumers on the joined node — built by the mesh, delivered from its registry.