# Two machines, one mesh. # # The first raises everything from the bundle its host carries and joins the mesh it made. The # second is an ordinary node: it has a host and nothing else, and a person carries it a token. # # This is the first scenario where the mesh is a mesh. Everything before it proved a machine could # talk to a control plane on its own loopback, which proves less than it looks. scenario: two-nodes segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow # The whole foundation, the registry, the builder, an adopted workload and the modules under # test all land here — eleven containers before the forge arrives. At the 1GiB default this # machine thrashes, and it presents as "the mesh hangs": every exec slows from 15s to 105s # and the forge test fails on a status poll that is merely queued behind page-outs. memory: 4GiB cpus: 4 laptop: at: { segment: hosting, address: [192.0.2.20] } egress: true inbound: allow memory: 2GiB images: - mesh-controller:development # And the builder, because it is a module the mesh assigns rather than a program somebody # starts by hand — which is the only way its credential can be one the mesh delivered. - mesh-builder:development # And the provisioner, which is what makes a sealed credential true on a machine — the mesh # discarded the plaintext and cannot tell a database to start accepting it. - mesh-provision-postgres:development # And the proxy, which is what turns a route grant into traffic actually arriving. - mesh-route-proxy:development - mesh-provision-redis:development # And the object store's provisioner, so the module describing it can be planned. Without it # that module still names an image nothing serves, and planning it is refused — correctly. - mesh-provision-objectstore:development place: all: [host, runtime]