Commit Graph
346 Commits
Author SHA1 Message Date
jschoubben 960539066e The two-node bed places the bus's users as genesis must
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
2026-10-08 01:39:02 +02:00
jschoubben d2c6e8fc5a The two-node bed proves a machine joins through the tunnel with the bus closed to it
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
2026-10-08 01:39:02 +02:00
mesh-admin b75a17e51b Merge pull request 'Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)' (#59) from fix/the-replays-are-checked-in-go into main 2026-10-07 22:26:26 +00:00
jochen c4f57432e1 Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The lab's check ran in the TypeScript toolchain, which holds no Go compiler,
so the replays register was never compiled before a merge. merge-check.sh now
declares replays/merge-check.sh as its Go part, which the build seat runs in
the Go toolchain: gofmt, go vet and the register's own tests. Both new
replays are proved: each fails on the commit before its fix and passes on it.
2026-10-08 00:13:46 +02:00
mesh-admin a9c3bd8e6d Merge pull request 'Register the replays of issues 296, 299 and 300 (hq ADR 0237)' (#58) from replays/296-299-300 into main 2026-10-07 21:55:20 +00:00
jochen 74c59661b1 Register the replays of issues 296, 299 and 300, each proved to fail before its fix and pass on it (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group replays/296-299-300 delivered: every member is delivered
2026-10-07 23:43:56 +02:00
mesh-admin a7903562b4 Merge pull request 'Name the merges R145 and R-crashloop replay at, not branches that are gone' (#57) from fix/r145-names-its-merges into main 2026-10-07 16:54:27 +00:00
jochen 14246bcf01 Name the merges R145 and R-crashloop replay at, not branches that are gone
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 18:49:58 +02:00
mesh-admin 2b489783ec Merge pull request 'Prove every changed health check on a bed before the catalogue merges (hq ADR 0240, to-be 48 Phase D)' (#56) from feat/health-the-bed into main 2026-10-07 16:28:44 +00:00
mesh-admin 3d871c992d Merge pull request 'Replay the silent web application: its declared HTTP check raises it within two looks (hq ADR 0240 Phase B, issue 145)' (#55) from feat/health-the-field into main 2026-10-07 16:28:34 +00:00
jochen a1a03f9880 Pull an image named by its digest as the runtime's own client does, and say a pull that failed
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 15:52:54 +02:00
jochen eecbfd6693 Prove every changed health check on a bed before the catalogue merges (hq ADR 0240, to-be 48 Phase D)
Two of nineteen image checks read unhealthy while working in the mesh's hands;
adopted without proof they would have put back two good builds. The replays
every catalogue merge check runs now start each long-running container whose
declared check or image the change touches, alone, with what its module
declares and nothing of the mesh's, and require the check to see the program
within its grace: a program that stays up while its check does not see it
fails the change; one that does not stay up alone is said and left to the
first machine's gate; a check needing a provider must only reach the program.
R-studio replays the studio's false unhealthy — a server bound to HOSTNAME's
address and an image check asking localhost — failed on the bed, and proved
with HOSTNAME=0.0.0.0.
2026-10-07 15:12:26 +02:00
jochen d93f1e4eab Replay the silent web application: its declared HTTP check raises it within two looks (hq ADR 0240 Phase B, issue 145)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-field delivered: every member is delivered
For eleven hours a web application's port was open and its program ran while
every request hung; liveness and a TCP check both say it fine. R145 raises a
web server whose application never answers, has the node-engine at its commit
look at it with the module's declared HTTP check, and the controller at its
commit raise the module's condition on the second look. Proved: it fails on
the trunk before Phase B and passes on it.
2026-10-07 14:41:54 +02:00
mesh-admin 69e1215424 Merge pull request 'Replay the crash loop: a container that exits at start fails its gate on the first machine (hq ADR 0240)' (#54) from feat/a-module-says-how-it-is-healthy into main 2026-10-07 00:39:40 +00:00
jochen 5e3ae7b835 Replay the crash loop: a container that exits at start fails its gate on the first machine (hq ADR 0240)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/a-module-says-how-it-is-healthy delivered: every member is delivered
The agent server crash-looped about a hundred times behind every passing check.
R-crashloop raises a container whose program exits at start, has the node-engine
at its commit judge it through the runtime, and the controller at its commit
judge the gate from what the engine said — two repositories, each at its own
commit before the fix and on it.
2026-10-07 02:28:50 +02:00
mesh-admin bc3709a66a Merge pull request 'A merge check of its own (hq ADR 0238)' (#53) from feat/a-merge-check-of-its-own into main 2026-10-06 21:00:38 +00:00
jochen 6b44d7c414 Check the lab's own code before it merges (hq ADR 0237)
A merge-check.sh, the repository's layer of the mesh's merge check (mesh/repo-check), in
the TypeScript toolchain: install from the lock file, type-check, the unit suite. The
integration suite and the replays need a lab and the container runtime, which unapproved
code is not given: said as not run, never passed silently.
2026-10-06 22:06:35 +02:00
mesh-admin 8962454530 Merge pull request 'Phase 5: replay the core incidents, and prove each fails before its fix (hq ADR 0237)' (#52) from feat/replays into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:19:21 +00:00
jochen 70f62ee17b Replay the core incidents, and prove each fails before its fix and passes on it (hq to-be 45 §9)
Phase 5 is done when the replays of 236, 262, 263 and 266 fail on the commit before their fix and
pass after. The register names every replay with its issue and fix; the bus replay (266) runs a
consumer filtered like the controller's against a bus of a given release, the resolver replay (262)
renders the catalogue's machine list and asks every machine's name by getaddrinfo under musl and
glibc, and the prover runs each at both commits: all five (236, 262, 263, 266, 273) proved.
2026-10-06 21:01:39 +02:00
mesh-admin a4f6bb8ce0 Merge pull request 'The trust bed raises a mesh, and places the bus's users as genesis must' (#53) from feat/the-trust-bed-raises-a-mesh into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-01 11:18:12 +00:00
jschoubben a734d427c0 A bed says what it actually needs to be pointed at
The instructions in every bed named the bundle that raises the predecessor's
broker, so a first attempt ends in a control plane crash-looping on a missing
MESH_BUS_NATS — which reads like a broken lab. They name the bundle that works
now, and the README says the host binary needs SYSTEM=arch, because one built
without it refuses everything with an empty system name.

And the three habits that each cost a run before they were adopted:
MESH_LAB_KEEP to leave the machine standing, MESH_LAB_WARM while iterating,
and rebuilding all three repositories the bed places rather than the one that
changed.
2026-09-29 17:45:09 +02:00
jschoubben f2d6ab3bf9 The trust bed raises a mesh, and places the bus's users as genesis must
novox/hq 04-ISSUES/146. The bed now does what raising a first node actually
takes: the private network so the authority can certify the address it holds,
and the composed user list placed beside the bus at the two moments an account
comes into existence — when the token is issued, and when the machine enrols.
Neither can arrive in a declaration, because a machine that has not enrolled
gets none.

MESH_LAB_KEEP leaves the machine standing, which is where every answer in this
sequence came from. No 'module issue' for the authority: that delivers a bus
account and it declares none.

The bed still fails, at the machine being enrolled twice from one attempt.
2026-09-29 17:37:08 +02:00
jschoubben f94ee2dd0e Merge pull request 'A bed for the trust anchor, and the bundle rewrite its foundation needs' (#52) from feat/ca-trust into main 2026-09-29 14:06:38 +00:00
jschoubben 62a02d7e94 A bed for the trust anchor, and the bundle rewrite its foundation needs
novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its
own API with a leaf it issued — so a plain client verifying that handshake is
verifying one thing: the mesh's root is in this machine's trust store. The
negative half runs twice, before the module is assigned and after it is
unassigned; an anchor bed that only checks the success would pass on a machine
that trusted everything.

foundationBundle learns the new bundle's bus reference, the way it already
knows the store's and the previous broker's. The bed does not run yet: raising
a foundation fails before any module is reached (novox/hq issue 146).
2026-09-29 15:26:05 +02:00
jschoubben 08e3aa04e7 Merge pull request 'Adoption bed: a machine in use raised adopted, held, taken and converged (hq ADR 0100–0103)' (#51) from feat/adoption-mode into main 2026-09-22 21:02:12 +02:00
jschoubben d93dc2628f Adoption bed: the anchor keeps its host service, so a machine that reboots comes back holding itself; only the fresh-machine dry run goes without 2026-09-22 20:52:42 +02:00
jschoubben 23ca9cadad Adoption bed: the machine the predecessor leaves also runs a container with no restart policy 2026-09-22 20:05:21 +02:00
jschoubben 204a226e36 Adoption bed: prove the guard rather than the found firewall, the runtime's own settings and a container with no restart policy, a held file not reverted once its writer stops, and the operator's rule outliving the mesh's opening 2026-09-22 19:53:47 +02:00
jschoubben 8d9e4bdb77 Adoption bed: the container probe asks the guard's promise, admitting the container interface through the found firewall for itself alone 2026-09-22 19:00:39 +02:00
jschoubben 3f224c2876 Adoption bed: an opening the operator's own rule answers is satisfied, and a failed container probe records its evidence 2026-09-22 18:49:06 +02:00
jschoubben a53dc8c586 Adoption bed (in progress): a machine in use raised adopted, held, opened through its firewall, taken and converged (hq ADR 0100-0103) 2026-09-22 18:19:36 +02:00
jschoubben bb746505dc Merge pull request 'The store-window bed: a machine enrols and a report arrives while the store is away (issue 083)' (#50) from multiple-fixes into main 2026-09-22 14:42:59 +02:00
jschoubben 514f7a46cd The store-window bed holds a report through the gap, asserts the enrolment is answered meanwhile, and compares the keys the mesh recorded with the ones the machine generated 2026-09-22 14:24:01 +02:00
jschoubben c9fd6d7887 A bed that takes the store away while a machine enrols, and holds the enrolment to completing on its own (novox/hq issue 083) 2026-09-22 14:08:45 +02:00
jschoubben 4d2ec6e6a8 Merge pull request 'A cache consumer must present its login; the two-node bed runs green again' (#49) from multiple-fixes into main 2026-09-22 13:53:15 +02:00
jschoubben dba95f7e27 The two-node bed's baserow data directory is 0755, as the catalogue's 2026-09-22 13:46:04 +02:00
jschoubben 3ce66e8369 The two-node bed's copies declare the secrets they take through the environment, as the catalogue does (ADR 0086) 2026-09-22 13:30:01 +02:00
jschoubben 3f71b91fb8 The two-node bed's timeout report shows the node that did not answer, not always the second one 2026-09-22 12:59:28 +02:00
jschoubben 2dfffd6dac Review of 081: the bed asserts baserow chose its own cache and it challenges for its password; the check reads only what a module hands its software; stale comments 2026-09-22 12:34:59 +02:00
jschoubben 36f2fd1c2c A cache consumer presents the login it was granted, checked over the catalogue; the two-node bed's baserow keeps its own cache and the bed asserts it answers (issue 081) 2026-09-22 12:26:34 +02:00
jschoubben 7a5d670e4e Merge pull request 'The large mesh bed runs end to end again: 21/21' (#48) from multiple-fixes into main 2026-09-22 02:19:15 +02:00
jschoubben 8a85e2d02e The grant bed's tenancy assertions are scoped to the login's keyspace, as redis scopes the ACL 2026-09-22 01:41:16 +02:00
jschoubben 146d7da9ef The large bed starts the hand-started builder where a build is asked for: it does not outlive the broker's first reconcile 2026-09-22 01:30:53 +02:00
jschoubben 10cfbd094a Review: the cache grant's tenancy assertions move into the grant bed; retirement notes say what the beds prove; the builder binary is pushed on a warm return; the large bed needs the catalogue 2026-09-22 01:27:52 +02:00
jschoubben 353cf88a4b The large mesh bed catches up with the mesh: the anchor's filter derived, ports declared, an image awaited, one host and builder on a warm return, resolvers from the catalogue; four tests retired for the beds that prove them 2026-09-22 01:16:13 +02:00
jschoubben 9eaa3a623d node_modules is not tracked: the link committed by mistake goes, and the ignore covers a link too 2026-09-22 00:38:07 +02:00
jschoubben a964ec287d Merge pull request 'Issue 074 closed: the last WEARING fixtures renamed or retired; a stale delivery fixed' (#47) from multiple-fixes into main 2026-09-21 23:58:49 +02:00
jschoubben 2da442729f Review: the node_modules link is not committed; two beds no longer issue modules with no broker secret; a stale header 2026-09-21 23:56:02 +02:00
jschoubben 03bbc37572 Beds issue only modules with a broker secret: an own secret is minted at resolve 2026-09-21 23:46:27 +02:00
jschoubben 484fafe799 mesh.test.ts: the consumer's login carries its slug 2026-09-21 23:43:01 +02:00