Two machines: the anchor raises the foundation, joins over its own
loopback and becomes the hub; the joiner makes its tunnel key, is issued
a token for it and enrols with the bus's port closed to its own address,
so the enrolment can arrive only over the tunnel (novox/hq ADR 0169). The
check that had been added to the two-node walk moves here, closing the
port the bundle publishes the bus on rather than the bus's own.
And the uplink's range may be named: behind a VPN client that routes
every private range, incus had none left to pick and no scenario could
be raised.
The filter module now serves its verbs from a runtime the mesh builds
(novox/hq ADR 0170), and a bed registered its raw manifest, which the
mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the
filter helper registers the module through the stocked image.
A token carries the bus's address, and at genesis that is the anchor's
loopback, which no other machine reaches. The anchor joins locally and
becomes the hub; the laptop makes its tunnel key, is issued a token for
it and joins over the tunnel (novox/hq ADR 0169, issue 146).
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
The lab's check ran in the TypeScript toolchain, which holds no Go compiler,
so the replays register was never compiled before a merge. merge-check.sh now
declares replays/merge-check.sh as its Go part, which the build seat runs in
the Go toolchain: gofmt, go vet and the register's own tests. Both new
replays are proved: each fails on the commit before its fix and passes on it.
Two of nineteen image checks read unhealthy while working in the mesh's hands;
adopted without proof they would have put back two good builds. The replays
every catalogue merge check runs now start each long-running container whose
declared check or image the change touches, alone, with what its module
declares and nothing of the mesh's, and require the check to see the program
within its grace: a program that stays up while its check does not see it
fails the change; one that does not stay up alone is said and left to the
first machine's gate; a check needing a provider must only reach the program.
R-studio replays the studio's false unhealthy — a server bound to HOSTNAME's
address and an image check asking localhost — failed on the bed, and proved
with HOSTNAME=0.0.0.0.
For eleven hours a web application's port was open and its program ran while
every request hung; liveness and a TCP check both say it fine. R145 raises a
web server whose application never answers, has the node-engine at its commit
look at it with the module's declared HTTP check, and the controller at its
commit raise the module's condition on the second look. Proved: it fails on
the trunk before Phase B and passes on it.
The agent server crash-looped about a hundred times behind every passing check.
R-crashloop raises a container whose program exits at start, has the node-engine
at its commit judge it through the runtime, and the controller at its commit
judge the gate from what the engine said — two repositories, each at its own
commit before the fix and on it.
A merge-check.sh, the repository's layer of the mesh's merge check (mesh/repo-check), in
the TypeScript toolchain: install from the lock file, type-check, the unit suite. The
integration suite and the replays need a lab and the container runtime, which unapproved
code is not given: said as not run, never passed silently.
Phase 5 is done when the replays of 236, 262, 263 and 266 fail on the commit before their fix and
pass after. The register names every replay with its issue and fix; the bus replay (266) runs a
consumer filtered like the controller's against a bus of a given release, the resolver replay (262)
renders the catalogue's machine list and asks every machine's name by getaddrinfo under musl and
glibc, and the prover runs each at both commits: all five (236, 262, 263, 266, 273) proved.
The instructions in every bed named the bundle that raises the predecessor's
broker, so a first attempt ends in a control plane crash-looping on a missing
MESH_BUS_NATS — which reads like a broken lab. They name the bundle that works
now, and the README says the host binary needs SYSTEM=arch, because one built
without it refuses everything with an empty system name.
And the three habits that each cost a run before they were adopted:
MESH_LAB_KEEP to leave the machine standing, MESH_LAB_WARM while iterating,
and rebuilding all three repositories the bed places rather than the one that
changed.
novox/hq 04-ISSUES/146. The bed now does what raising a first node actually
takes: the private network so the authority can certify the address it holds,
and the composed user list placed beside the bus at the two moments an account
comes into existence — when the token is issued, and when the machine enrols.
Neither can arrive in a declaration, because a machine that has not enrolled
gets none.
MESH_LAB_KEEP leaves the machine standing, which is where every answer in this
sequence came from. No 'module issue' for the authority: that delivers a bus
account and it declares none.
The bed still fails, at the machine being enrolled twice from one attempt.
novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its
own API with a leaf it issued — so a plain client verifying that handshake is
verifying one thing: the mesh's root is in this machine's trust store. The
negative half runs twice, before the module is assigned and after it is
unassigned; an anchor bed that only checks the success would pass on a machine
that trusted everything.
foundationBundle learns the new bundle's bus reference, the way it already
knows the store's and the previous broker's. The bed does not run yet: raising
a foundation fails before any module is reached (novox/hq issue 146).