Stacked on #1 (events/adr-0047-alignment). Three commits:
tools serve per key (ADR 0052): each tool is served on <module>.<tool> via broker.handle, and invokeTool/toolKey invoke by module and tool — the module namespaces the tool, so two modules may share a name and one cannot answer another's calls.
provisioner: a provider consumes the mesh's credential, seals nothing (ADR 0053):runProvisioner reconciles the mesh's receives contributions, reading each consumer's mesh-minted password from the file the host unsealed, and calls the adapter to create the resource under the mesh-derived login. create({as,password,values}) / remove({as}), returning nothing. $MESH_SEAL_KEY, the symmetric seal()/unseal() primitive, writeSealedCredential, and the .grant.json/.credential files are removed.
tests for the new provisioner contract, and the tool tests updated to per-key serving.
Proven in mesh-lab: the tool-runtime and provider-credential e2e suites (assigned-plex/sonarr/grafana, provider-uses-mesh-credential, mesh-grant-end-to-end) are green against this.
Implements novox/hq ADRs 0052 and 0053 (hq PRs #20, #21).
Stacked on #1 (events/adr-0047-alignment). Three commits:
- **tools serve per key (ADR 0052):** each tool is served on `<module>.<tool>` via `broker.handle`, and `invokeTool`/`toolKey` invoke by module and tool — the module namespaces the tool, so two modules may share a name and one cannot answer another's calls.
- **provisioner: a provider consumes the mesh's credential, seals nothing (ADR 0053):** `runProvisioner` reconciles the mesh's `receives` contributions, reading each consumer's mesh-minted password from the file the host unsealed, and calls the adapter to create the resource under the mesh-derived login. `create({as,password,values})` / `remove({as})`, returning nothing. `$MESH_SEAL_KEY`, the symmetric `seal()`/`unseal()` primitive, `writeSealedCredential`, and the `.grant.json`/`.credential` files are removed.
- **tests** for the new provisioner contract, and the tool tests updated to per-key serving.
Proven in mesh-lab: the tool-runtime and provider-credential e2e suites (assigned-plex/sonarr/grafana, provider-uses-mesh-credential, mesh-grant-end-to-end) are green against this.
Implements novox/hq ADRs 0052 and 0053 (hq PRs #20, #21).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben
changed target branch from events/adr-0047-alignment to main2026-09-05 01:01:32 +00:00
emit stamps the ADR 0047 headers — x-event-id, x-source, x-node, x-time,
content-type, and optional x-causation-id / x-schema — and publishes the
body as only the domain payload. on() reconstructs the Event from those
headers. Event gains id (the x-event-id a consumer dedups on) plus the
optional causation/schema. EventHeaders joins the contracts spine.
Supersedes the first cut that carried source/node/time in the body.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
serveTools now serves each tool on serve.<module>.<tool> instead of one
tools.invoke that dispatched by name — so a module's account is scoped to
serve.<module>.* and one module cannot answer another's calls. toolKey and
invokeTool are the caller's side. A tool name need only be unique within its
module now, not across the mesh.
runProvisioner now reconciles the mesh's `receives` contributions: for each
consumer it reads the mesh-minted password from the file the host unsealed and calls
the adapter to create the resource under the login the mesh derived. The adapter is
create({as,password,values}) / remove({as}), returning nothing — the consumer
already receives its copy through the mesh's own asymmetric channel. $MESH_SEAL_KEY,
the symmetric seal()/writeSealedCredential path, and the *.grant.json / *.credential
files are gone; the seal()/unseal() primitive had no other caller and was removed.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Rewrites the provisioner test to the new contract (a contributions file + an
unsealed secret; the adapter is handed the mesh's login and password, and removal
follows the consumer leaving the file) and drops the seal round-trip test with the
primitive it covered. Also fixes two tool tests left stale by the per-key serving
rework (ADR 0052): invoke by module.tool, and refuse one module's duplicate name
(two modules may now share a name). Suite green: 6 pass.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Stacked on #1 (events/adr-0047-alignment). Three commits:
<module>.<tool>viabroker.handle, andinvokeTool/toolKeyinvoke by module and tool — the module namespaces the tool, so two modules may share a name and one cannot answer another's calls.runProvisionerreconciles the mesh'sreceivescontributions, reading each consumer's mesh-minted password from the file the host unsealed, and calls the adapter to create the resource under the mesh-derived login.create({as,password,values})/remove({as}), returning nothing.$MESH_SEAL_KEY, the symmetricseal()/unseal()primitive,writeSealedCredential, and the.grant.json/.credentialfiles are removed.Proven in mesh-lab: the tool-runtime and provider-credential e2e suites (assigned-plex/sonarr/grafana, provider-uses-mesh-credential, mesh-grant-end-to-end) are green against this.
Implements novox/hq ADRs 0052 and 0053 (hq PRs #20, #21).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
runProvisioner now reconciles the mesh's `receives` contributions: for each consumer it reads the mesh-minted password from the file the host unsealed and calls the adapter to create the resource under the login the mesh derived. The adapter is create({as,password,values}) / remove({as}), returning nothing — the consumer already receives its copy through the mesh's own asymmetric channel. $MESH_SEAL_KEY, the symmetric seal()/writeSealedCredential path, and the *.grant.json / *.credential files are gone; the seal()/unseal() primitive had no other caller and was removed. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF