Adoption bed: a machine in use raised adopted, held, taken and converged (hq ADR 0100–0103) #51

Merged
jschoubben merged 6 commits from feat/adoption-mode into main 2026-09-22 19:02:12 +00:00
Owner

This adds test/integration/adoption.test.ts and scenarios/adoption.yml. It also extends the genesis helper with adopted genesis, given ports and expected refusals.

Setup. The bed prepares a machine the way a predecessor leaves one:

  • ufw denying incoming and routed traffic, with the ufw-docker pattern;
  • a service container and its file;
  • a stand-in writer that keeps changing that file;
  • a container holding the registry's port.

Checks. It then walks ADR 0100's "How it is checked" in order:

  • genesis refusals, and the adopted foundation on a given port;
  • nothing that serves changes;
  • the store unreachable from outside, before and after a firewall reload;
  • a second machine joining through the found firewall, after a reload and after a reboot;
  • assigning prepares, the stand-in writer is caught, and taking cuts over;
  • the converge preview, the flip, and returning to adopted.

Result. Run 2 passed 18 of 19 checks against mesh-host 60bb3d8, mesh-controller 65187d4 and mesh-catalog 84012fa. The one failure, B4, tested the found firewall's inbound policy rather than the guard. The probe now admits the container interface for itself alone. That form was verified by hand on the kept machine, but not yet in a full run.

This adds `test/integration/adoption.test.ts` and `scenarios/adoption.yml`. It also extends the genesis helper with adopted genesis, given ports and expected refusals. **Setup.** The bed prepares a machine the way a predecessor leaves one: - ufw denying incoming and routed traffic, with the ufw-docker pattern; - a service container and its file; - a stand-in writer that keeps changing that file; - a container holding the registry's port. **Checks.** It then walks ADR 0100's "How it is checked" in order: - genesis refusals, and the adopted foundation on a given port; - nothing that serves changes; - the store unreachable from outside, before and after a firewall reload; - a second machine joining through the found firewall, after a reload and after a reboot; - assigning prepares, the stand-in writer is caught, and taking cuts over; - the converge preview, the flip, and returning to adopted. **Result.** Run 2 passed 18 of 19 checks against mesh-host 60bb3d8, mesh-controller 65187d4 and mesh-catalog 84012fa. The one failure, B4, tested the found firewall's inbound policy rather than the guard. The probe now admits the container interface for itself alone. That form was verified by hand on the kept machine, but not yet in a full run.
jschoubben added 3 commits 2026-09-22 17:28:27 +00:00
jschoubben added 2 commits 2026-09-22 18:07:18 +00:00
jschoubben added 1 commit 2026-09-22 19:02:08 +00:00
jschoubben merged commit 08e3aa04e7 into main 2026-09-22 19:02:12 +00:00
jschoubben deleted branch feat/adoption-mode 2026-09-22 19:02:12 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-lab#51