One name per thing, per the HQ glossary: the module/container/image/binary/repo becomes mesh-controller, the seat the-controller, and the store+broker pair the foundation (embedded base bundles, default template and example lock renamed with their go:embed directives). No behaviour change — a pure vocabulary rename. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
41 lines
1.9 KiB
YAML
41 lines
1.9 KiB
YAML
# GENESIS, on its own: one machine, no mesh, and the installer.
|
|
#
|
|
# The smallest thing that proves a mesh can be raised. One machine on a public segment with a way
|
|
# out to the internet, the host placed, and nothing else — the installer carries the control
|
|
# plane's image and the foundation's own images are pulled over the uplink, exactly as they are on
|
|
# a bare machine.
|
|
#
|
|
# The address matters: the foundation template names the broker at 192.0.2.10, and a token carries
|
|
# that address verbatim as the endpoint an enrolling node dials. With one machine, that machine
|
|
# must BE it, or the mesh would hand out an endpoint nothing answers on.
|
|
scenario: genesis-single
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24, "2001:db8:a::/48"]
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10, "2001:db8:a::10"] }
|
|
# The way out. Without it the machine is sealed in, and the installer stops at its first pull:
|
|
# the store, the broker and the registry all come from the internet, exactly as they do on a
|
|
# bare machine. A scenario that needs no images can omit this; genesis cannot.
|
|
egress: true
|
|
inbound: allow
|
|
# Enough for the foundation (store, broker), the registry, and two control planes during the
|
|
# pivot. Smaller than the four-node bed's anchor, which also carries a whole service set.
|
|
memory: 8GiB
|
|
cpus: 4
|
|
disk: 40GiB
|
|
|
|
# The host, and a container runtime for it to drive.
|
|
#
|
|
# The runtime is not a mesh tier — it is a prerequisite of the machine, and the installer's first
|
|
# step refuses to go on without one. Placing it here is the lab preparing a machine, not the lab
|
|
# describing an installation. Everything above tier 0 — the foundation, the registry, the control
|
|
# plane — is the installer's, and the lab places none of it. That is the whole point of this bed:
|
|
# if the lab placed the foundation, it would be describing installing all over again.
|
|
place:
|
|
all: [host, runtime]
|