After the controller stopped granting a mesh seat to claimants that do not hold it, an image built before the runtime followed its membership still subscribed the seat's subject, and the refusal ended the process: ace's postgres runtime crash-looped. A subject the grants leave out now costs that subject only, as an announcement's already did (issue 217).
node-tools
The node's tool runtime as a module (novox/hq ADR 0175, to-be 38 WP3). Assigned to a machine, it is one process the host runs from this bundle, as the operator's account: it serves every assigned module's tools and every held seat's verbs on the bus, and answers MCP on the machine's loopback — the console (design 34). The controller composes the process (which bundles to load, where the credential is, whose machine it is); this manifest says only what the machine must have for it: the interpreter, a place for the credential, the loopback port, and leave to call every tool.
The code is the mesh-tools package in this directory; the module at the repository root,
mesh-tools, builds the images TypeScript bundles are compiled in. See the repository README.