# GENESIS, on its own: one machine, no mesh, and the installer. # # The smallest thing that proves a mesh can be raised. One machine on a public segment with a way # out to the internet, the host placed, and nothing else — the installer carries the control # plane's image and the foundation's own images are pulled over the uplink, exactly as they are on # a bare machine. # # The address matters: the foundation template names the broker at 192.0.2.10, and a token carries # that address verbatim as the endpoint an enrolling node dials. With one machine, that machine # must BE it, or the mesh would hand out an endpoint nothing answers on. scenario: genesis-single segments: hosting: kind: public cidr: [192.0.2.0/24, "2001:db8:a::/48"] machines: anchor: at: { segment: hosting, address: [192.0.2.10, "2001:db8:a::10"] } # The way out. Without it the machine is sealed in, and the installer stops at its first pull: # the store, the broker and the registry all come from the internet, exactly as they do on a # bare machine. A scenario that needs no images can omit this; genesis cannot. egress: true inbound: allow # Enough for the foundation (store, broker), the registry, and two control planes during the # pivot. Smaller than the four-node bed's anchor, which also carries a whole service set. memory: 8GiB cpus: 4 disk: 40GiB # The host, and a container runtime for it to drive. # # The runtime is not a mesh tier — it is a prerequisite of the machine, and the installer's first # step refuses to go on without one. Placing it here is the lab preparing a machine, not the lab # describing an installation. Everything above tier 0 — the foundation, the registry, the control # plane — is the installer's, and the lab places none of it. That is the whole point of this bed: # if the lab placed the foundation, it would be describing installing all over again. place: all: [host, runtime]