Commit Graph
205 Commits
Author SHA1 Message Date
jschoubben 85dc827660 The confluence bed asks a tool through the control plane, and the tool answers
No account in the mesh but the control plane's may create a reply queue and publish
to a module's request key (novox/hq 04-ISSUES/049, ADR 0095).
2026-09-21 20:34:03 +02:00
jschoubben 64c081d025 The vault bed installs a consumer that keeps two secrets, and both are delivered and rotated
Two files with two values, two holders in the vault's ledger — the identity with the
local name after it — and one rotate moves both (novox/hq ADR 0094).
2026-09-21 20:29:49 +02:00
jschoubben e4c924a85e The grant bed's consumer takes a slug: its derived identity was one character over what a backend keeps 2026-09-21 19:32:36 +02:00
jschoubben 1b2443690d Two mechanism beds install the catalogue's redis with the vault beside it
A module's name is its tool namespace and its broker scope, so a fixture running
the module's runtime cannot carry another name (novox/hq ADR 0093). The grant and
backend-network beds now read the catalogue's redis and install mesh-vault, which
provides the secret it requires; the redis-node scenario stocks the vault's runtime.
The remaining declared copies say why they stand (novox/hq 04-ISSUES/074).
2026-09-21 19:30:34 +02:00
jschoubben d7959001dd The run rebuilds the module runtimes its beds stock
A per-module bed stocks mesh-runtime-<module>:development from the workstation's
image store, built by hand by a script the suite never called; six were two weeks
older than the manifests they served. For the beds named, every runtime their
scenarios stock is compared against the module's source and the tool runtime and
SDK it is built on, and rebuilt where older, missing or uncommitted; a failed
build stops the suite (novox/hq 04-ISSUES/075).
2026-09-21 19:26:59 +02:00
jschoubben 6083b9310a Genesis reads the registry's and the builder's manifests from the catalogue, not the control plane's
The control plane's manifest comes out of the build the installer runs (novox/hq ADR
0069, 04-ISSUES/072); the catalogue no longer holds a copy, and a bed that demanded
one would stop a genesis that is about to succeed.
2026-09-21 19:23:44 +02:00
jschoubben ec23e9f4cd The catalogue is named or absent, the scanner reads both key orders, the loader has unit tests
Review findings: a sibling-path fallback read a catalogue the receipt never claimed;
a manifest literal naming its version first slipped the fence; the shared loader
thirteen beds install through had no test short of a lab run.
2026-09-21 19:21:54 +02:00
jschoubben 8c37328ba3 The catalogue is recognised by the registry's manifest, not the control plane's
The control plane's manifest is leaving the catalogue (ADR 0069, issue 072); a marker
that named it would make every catalogue-reading bed skip the day it goes.
2026-09-21 15:18:46 +02:00
jschoubben e596758db9 The five beds that read the catalogue read it through the harness
adopted-store-cross-node, two-node-db and the three whole-mesh beds each carried a
private loader; they drifted. The ace loader never resolved a runtime artifact, so a
module the mesh builds travelled unresolved; whole-mesh-full still asked for
'registry' and 'firewall', which the catalogue names distribution and nftables, and
swallowed the miss as NOT ASSIGNED. One loader now (novox/hq 04-ISSUES/073).
2026-09-21 14:33:02 +02:00
jschoubben 2456b2f533 Beds read the catalogue: a shared loader, eight beds converted, the rest declared
catalogueModule() in the harness reads a module's manifest from the catalogue and
rewrites only what the lab must: the build section goes, each artifact becomes the
image the machine holds, images are pinned, and a bed may declare a host-port remap
or a lab-local address. confluence, gitlab, openai-consumer, audit-logger, ollama,
local-model-consumer, model-usage, mosquitto, anthropic-manager and
anthropic-consumer now install the catalogue's manifest. A unit test refuses any
inline copy naming a catalogue module unless the bed is declared with its reason;
the declared list is the debt (novox/hq 04-ISSUES/073).
2026-09-21 14:27:49 +02:00
jschoubben f2d29491b2 The receipt claims the catalogue the beds read
A bed installs a catalogue module by reading its manifest from MESH_LAB_CATALOG at
run time, so a receipt naming no catalogue commit cannot say whether a catalogue
change was ever proven. Claimed under either spelling of the variable; not built,
because a manifest is read, not compiled (novox/hq 04-ISSUES/073).
2026-09-21 14:14:54 +02:00
jschoubben b0e7cf96d1 The apps bed's mongodb names its secrets' owner, as the catalogue's does, and says what the server said when the consumer cannot reach it 2026-09-21 13:43:42 +02:00
jschoubben e085e31f95 A bed that raises the foundation from the bundle derives the anchor's filter before it relies on the hub
The base ruleset (ADR 0088) admits ssh, the bus and the registry and nothing else until the mesh
derives one, and the mesh derives one only where the filter module is assigned — which genesis
does and these beds did not. Without it the hub's WireGuard port stayed closed, no joined node's
tunnel formed, and every module dialling the anchor by its overlay name timed out fetching the
broker's certificate; the model-usage bed showed it as a login that failed for a role never made.
2026-09-21 13:30:26 +02:00
jschoubben af14f1c909 The model-usage bed can be left standing, and its account names the filters 2026-09-21 13:18:23 +02:00
jschoubben ba49f571dc The model-usage bed says what the machine knows when the login fails 2026-09-21 13:12:19 +02:00
jschoubben 67a1f6a012 The harness pins minio from quay.io, as the catalogue does (docker.io denies anonymous pulls) 2026-09-21 12:58:35 +02:00
jschoubben b7316d40fe The three beds' inline postgres reads its superuser from a file, as the catalogue's does 2026-09-21 12:55:35 +02:00
jschoubben 97d71503ee Three beds deliver the secrets they copy from the catalogue as files (issue 073) 2026-09-21 12:32:00 +02:00
jschoubben 599d41eb42 Beds for the seed file and for the foundation's filter
The vault bed grows into a create-once file and pushes again; the genesis bed
probes the machine from the workstation for the whole install and asserts the
store's port never answers while the bus's does.
2026-09-21 12:11:52 +02:00
jschoubben 7fad006e56 A push that said 'told' is a push that sent, whatever became of the exec afterwards 2026-09-21 01:47:26 +02:00
jschoubben fb72db73bc The vault bed recovers redis's vault-provided secret from the export 2026-09-21 00:36:16 +02:00
jschoubben 960fa3607f The genesis bed waits for the node to settle before asking it anything
Applying the packet filter restarts the container runtime a few seconds
after the installer's last push returns; a command racing that window dies
with 'No such exec instance'. Wait for the node to report applied and
current, and retry that error like the recreate it is.
2026-09-21 00:33:23 +02:00
jschoubben 9da2d01ca0 The genesis bed checks the root secrets: made, sealed to the operator key, recoverable
V5: the template's password is refused by the store, the operator key and the
export sit beside the bundle at 0600, the vault keeps the export, and a person
with the key recovers the superuser off the mesh and opens the store with it.
V2 dials the broker with the administrator password genesis made.
2026-09-21 00:12:55 +02:00
jschoubben 639175ec4a A bed for the vault: redis's password as a secret it provides, rotated
Design 13's three logins, for a secret that had no owner before (novox/hq
ADR 0085): the delivered password authenticates against the real redis, the
one `rotate secret` delivers authenticates, and the one rotated away is
refused. Plus the owner's half: the vault's ledger names the holder and the
fingerprint, notices the rotation, and answers over the mesh by fingerprint,
never by value. Runs the catalogue's own manifests.
2026-09-21 00:01:50 +02:00
jschoubben 6bdf7104c8 whole-mesh-novox: the postgres server container is mesh-store, not postgres
The CORE convergence wait hung on a container named 'postgres' that
never exists — the postgres module's server is the adopted-store
container 'mesh-store' (like lavinmq's mesh-broker). Everything else
converged; this was the last phantom-name blocker.
2026-09-20 22:06:26 +02:00
jschoubben 0a05fbb434 whole-mesh-novox goes green: the store superuser, the artifact shape, and the missing CA
The bed had never resolved, then never converged. Fixed, in order:
- loadManifest maps a runtime container's 060 `artifact` to the stocked
  mesh-runtime-<module> image (keyed on the module name), so the push is
  no longer refused by built() — and drops the build section.
- Stale identities renamed: registry->distribution, firewall->nftables.
- step-ca added to the set: the web modules hard-require `route`,
  route-proxy provides it but requires `acme-ca`, and nothing provided
  that — so the whole web stack never resolved. step-ca is the missing CA.
- THE STORE SUPERUSER is delivered via `secret accept` before the push.
  postgres raises mesh-store with POSTGRES_PASSWORD=bootstrap, but
  `module add` minted a random superuser own-secret that did not match,
  so the provisioner could not log in and created NO consumer roles —
  every DB consumer (gitea/keycloak/nextcloud/umami/mailu) failed. This
  was the real cause behind what looked like per-module gaps; keycloak
  and umami converge once it is delivered (ADR 0078, hq phase3).
- mesh() retries through the controller recreating itself during the
  057 cascade (No such exec instance), so a real success is not read as
  a failed push.
- invoicing dropped (private-registry images the lab cannot pull).

Remaining KNOWN_GAPS are genuine catalog/upstream/resource gaps: minio
(stale Docker Hub digest), mssql (Error 945, memory), mailu (config
env), photos (alpine placeholder), nftables (service).
2026-09-20 22:06:26 +02:00
jschoubben 064a7a0934 The bed's 058 claim, base64 dump, and 063 comment are made honest (review)
- The RestartCount==0 assertion cannot discriminate the 058 fix: the
  consumer is built after its broker is already up, so patient and
  exit-on-unreachable code both connect first-try; and restart-on
  recreates reset the count. Downgraded to an honest liveness check and
  the comment now points at the mesh-tools unit test as the real proof.
- The trust-failure dump ran base64 -d over declared.json, which is JSON
  (not base64), so it always reported 'no trust' — removed; the adjacent
  python check that decodes the inner declaration field is kept.
- The 063 comment claimed the vhost is re-listed after the restart; the
  code only runs a TCP probe. Comment corrected to what the code proves,
  and the docker-proxy-vs-DNAT coupling is noted.
2026-09-20 13:32:14 +02:00
jschoubben 68133c2c56 The bed restarts the broker and reconnects across the overlay (issue 063)
A broker that is reachable only until its conntrack entry drops passes
every test written before it restarts. The bed now restarts mesh-broker
after adoption and asserts the joined node can still reach 5671 — the
forward rule, not a surviving entry, carrying the connection.
2026-09-18 02:21:48 +02:00
jschoubben 38a7180b8b The bed enforces one-push provisioning and a patient runtime (057/058)
The provider's workaround re-push is gone: pushing the consumer's node
must cascade to the provider (issue 057), and the vhost assertion is
what says so. The joined consumer must also show zero container-runtime
restarts (issue 058): a runtime whose broker is not up yet waits for it
in-process, so overlay-after-container ordering produces no churn.
2026-09-18 02:07:59 +02:00
jschoubben cb353f9881 The trust wait dumps mesh-host's log and the declaration on failure
Run 11 failed with node2's daemon.json never written and nothing to say
whether the declaration lacked the trust or never applied. The dump now
answers that, and the push output is printed so a compose that refused
is visible in the run log.
2026-09-18 00:15:16 +02:00
jschoubben ca263d2a8b The trust lands before anything builds
The networking module delivers the registry trust, so the bed pushes both machines after
assigning it and waits for each runtime to actually hold the trust (file present AND the
daemon reloaded) before the first build pushes to anchor.internal:5000.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 23:16:26 +02:00
jschoubben 5ded8e2a8e The bed keeps its genesis warm
MESH_LAB_WARM=1 snapshots the post-genesis, both-nodes-enrolled state and restores it in
seconds on later runs — refused, not silently rebuilt, when the commits have moved
(src/warm.ts, the mechanism mesh.test.ts already uses and this session had ignored).
Fresh stays the default.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:55:00 +02:00
jschoubben 832c287ccc The bed passes the gate under exactOptionalPropertyTypes
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:54:09 +02:00
jschoubben 31969e20e3 The bed rides the typecheck-gated main 2026-09-17 22:54:06 +02:00
jschoubben 494f73369a Every test passes the typecheck gate
tsconfig.test.json existed precisely so a test that does not compile cannot silently be a
test that never ran — and four beds did not compile: two returned strings from test bodies,
two predate GenesisOptions gaining sdkSource, one passed a nullable host binary. All clean;
the gate is now part of launching any bed.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:53:34 +02:00
jschoubben 27b5f8d092 The bed passes the typecheck gate
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:52:31 +02:00
jschoubben b77d03a1f8 readFileSync is imported, not assumed
https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:48:34 +02:00
jschoubben 158fe5c327 Apply the bed review: one buildable consumer, honest gates, tighter plumbing
letta is not mesh-buildable (hq issue 060) — the store's cross-node proof stays with the
stocked bed until a DB consumer gains a build section; amqp-ping carries the no-fake proof
alone, and the node2 delivery is named as the honest red gate for issues 042/048 (no
registry account, no registry trust). Also: overlay sites match genesis (hosting), the
manifest is read locally instead of a swallowed docker-exec, before() gets the one-node
budget, a node2 failure appends the host log (a failed pull never reaches container logs),
and the foundation's survival plus the consumer's steadiness are asserted.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:39:49 +02:00
jschoubben 428f13bfae The settle check records settling instead of inferring it from the clock
The review found a race: a container that settled in the window's last seconds could be
re-inspected past the deadline and failed as 'never stopped restarting'. A boolean now says
what happened.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:39:48 +02:00
jschoubben d3a6dc9784 The bed adopts only what genesis leaves it: the broker
Run 3 showed the Phase-3 installer already adopts postgres (superuser included), nftables
and the catalogue at genesis — re-registering them was redundant. Only lavinmq and the
joined node's consumers are the bed's to add. Issuance is now asserted per module and each
module is pushed as it lands, mirroring the one-node bringUp.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:23:13 +02:00
jschoubben bfd70e9e57 The no-fake multi-node bed: two machines, everything built by the mesh itself
The scenario names no images and the bed rewrites nothing: the installer raises anchor
(building the control plane), the mesh's own builder builds base, postgres, lavinmq and
the joined node's consumers from the forge and pins every digest itself, the committed
manifests are registered verbatim, and node2 proves both foundation halves cross-node.
Being iterated toward green (run 3 in flight); banked so nothing is lost.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:15:34 +02:00
jschoubben 2438883a5f Remove the inert MESH_SEAL_KEY, and cite the ADR that retired it correctly
ADR 0048 (2026-09-05) settled that a provider is handed the credential the mesh minted —
sealed to the provider node, unsealed by the host into a 0600 file — and removed the
symmetric seal from the SDK entirely; hq issue 032 records it resolved. The lab-only
MESH_SEAL_KEY injections were tombstones read by nothing: two-node-db went green on the
superuser delivery, not the seal key. Removed, and provider-uses-mesh-credential's
citations corrected from ADR 0053 (a scheduled step) to ADR 0048.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 22:02:31 +02:00
jschoubben 0e382f1db7 two-node-db is GREEN on the one-store model — store cross-node proven end-to-end
The complete recipe, found across five runs: adopt BOTH the store (postgres) and broker
(lavinmq) on the control-node — the broker's `listens` is what opens 5671 in the firewall
for cross-node bus access; deliver the store's genesis superuser via `secret accept` (else
the module mints a random one that cannot log in to the running store); inject the provider
seal key (open hq issue 022 workaround); push the provider node again after the remote
consumers (issue 057); and tolerate provisioner-runtime startup churn — a cross-node
provisioner exits until the overlay tunnel is up, then settles. baserow and letta on the
joined node get their databases from the one foundation store over the overlay.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 09:53:35 +02:00
jschoubben d8540bec42 Convert two-node-db to the one-store model (WIP: blocked on issue 058)
The bed assigned a separate app-postgres, which ADR 0079 now refuses. Converted to
adopt the foundation store on anchor and have baserow/letta consume it cross-node over
the overlay, with the 057 push-ordering. The store DB path reaches its asserts, but the
run is blocked by issue 058: redis's host-networked provisioner cannot reach the broker
across nodes (bridge consumers can). Committed as WIP until 058 is fixed.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 09:00:33 +02:00
jschoubben b6bf31d4e6 The cross-node bed is green: push the provider node after adding the remote consumer
A provision secret is minted as a side-effect of composing the CONSUMER's plan, and the
provider's grant list is a pure read of secrets already issued from it. So a cross-node
consumer's grant exists only after its node is pushed, and the provider's provisioner mints
the vhost only when the provider node is composed again. Push anchor once more after node2,
and the bed passes: amqp-ping on node2 reaches mesh-broker on anchor over the overlay, its
binding names anchor.internal, and its vhost is minted. Proves both halves of issue 055.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 01:34:22 +02:00
jschoubben 155800bc9a A two-node bed: a joined node opening the adopted broker over the overlay (055)
anchor raises the foundation and adopts lavinmq; node2 joins and runs amqp-ping,
which requires amqp and provides nothing. Asserts the grant names anchor.internal,
a vhost is minted on the far broker, and the consumer stays up. Currently RED: it
caught two real gaps — the broker's amqps port not in the firewall (fixed in
mesh-catalog) and the module broker URL using the public address not the overlay
(issue 055, needs a controller fix). Goes green when 055 is fixed.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-17 01:01:54 +02:00
jschoubben 440e2653b2 Phase 3.3/3.4: prove the store and broker upgrade in place, through the window
S1 upgrades the store: a spec change recreates mesh-store (the server the control
plane reads from), and asserts the data on the named volume survives and the
pool reconnects — the stated window. It also asserts postgres/lavinmq are now
source-tracked modules the mesh can report behind (3.4), the question that could
not form before adoption. S2 does the same for the broker, the harder case: the
push that upgrades it travels over it, so it proves the mesh reconnects to the
bus it just replaced.

Issue 051 (WBS 3.3, 3.4).

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 22:55:56 +02:00
jschoubben 70c1545161 Phase 3.2: lavinmq declares no network — it adopts mesh-broker
The V3 networking check asserted a `lavinmq` docker network exists, from the
two-server world. The module now adopts the foundation's broker rather than
raising its own on a private network (issue 051, WBS 3.2), so only the
consumer's own network remains.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 21:33:16 +02:00
jschoubben 5d6e8fbe7a Rename mesh-control -> mesh-controller, substrate -> foundation
One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 18:40:40 +02:00
jschoubben 49b80d8516 The one-node bed supervises the host as a service, so reboot is a real check
Installs the shipped nox-mesh-host launcher and unit in the machine and lets the
installer's --host-service start and enable it, instead of --host-in-background
which cannot survive a reboot. E2 now proves the mesh comes back on its own.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 16:20:44 +02:00