# A MACHINE IN USE, ADOPTED — and then converged, and returned (novox/hq ADR 0100, ADR 0101). # # The mesh replaces a predecessor that is running on the same machines. The anchor here is # prepared the way the predecessor leaves one: its own firewall (ufw) allowing a served port and # denying the rest, a service container on that port under a name a catalogue module also uses, a # file at a path that module declares, a stand-in for the predecessor's configuration sync that # rewrites the file, and a container holding the registry's port. The bed then raises the mesh on # it, adopted, and walks the migration the record decides. # # hosting (public) # anchor 192.0.2.10 the machine in use: the predecessor, then the mesh adopted on it # joiner 192.0.2.20 a fresh machine: the "second machine" that reaches the service and # enrols through the found firewall; also where a converged genesis on a # FRESH machine is asked (ADR 0101) # outsider 192.0.2.30 never enrolled, never on the private network: the probe from outside, # and the lab's forge — the bed serves the checkouts under test to the # anchor's builder from here, so nothing on the workstation listens # # inbound: allow on every machine — the anchor's firewall is the predecessor's, installed by the # bed; `inbound: deny` would load the lab's own table beside it and make that the thing under test. scenario: adoption segments: hosting: kind: public cidr: [192.0.2.0/24] machines: # Sized like the one-node bed's anchor: genesis builds the control plane, the base and the # catalogue's modules here, beside the predecessor's two containers. anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow memory: 12GiB cpus: 6 disk: 60GiB joiner: at: { segment: hosting, address: [192.0.2.20] } egress: true inbound: allow memory: 3GiB cpus: 2 disk: 20GiB outsider: at: { segment: hosting, address: [192.0.2.30] } egress: true inbound: allow memory: 2GiB cpus: 2 disk: 15GiB place: all: [host, runtime]