ADR-016: deployment honesty — no runtime capability surface; compile-time identity + matrix (OQ-08 resolved)
This commit is contained in:
1 parent
8c4ec48f92
commit
8c8fec5cb8
12 files changed
+494
-72
No files matched your search
@@ -1,6 +1,6 @@
|
||||
---
|
||||
status: draft
|
||||
last_updated: 2026-10-05
|
||||
last_updated: 2026-10-06
|
||||
---
|
||||
|
||||
# Deployment
|
||||
@@ -8,8 +8,11 @@ last_updated: 2026-10-05
|
||||
What a deployer must know to size, run, and reason about alkstore
|
||||
engines: host semantics, connection budgets, durability knobs, and
|
||||
where engine differences may honestly surface in the contract. The
|
||||
capability-surface *decision* (how much of this the trait exposes) is
|
||||
OQ-08's; this document holds the facts and the decision's frame.
|
||||
capability-surface *decision* is resolved
|
||||
([ADR-016](decisions/016-deployment-honesty.md), 2026-10-06): no
|
||||
runtime capability surface — this document's matrix is (with the
|
||||
engine crates' own docs) where the honest boundary lives; this
|
||||
document holds the facts.
|
||||
|
||||
## Host semantics
|
||||
|
||||
@@ -18,24 +21,41 @@ OQ-08's; this document holds the facts and the decision's frame.
|
||||
| SQLite | **single-machine**, file-backed | NFS two-writers unsupported (honker's honesty posture, inherited, [ADR-003](decisions/003-sqlite-driver.md)). Cross-process *on one host* is verified POC ground (`data_version` is cross-process by nature). |
|
||||
| Postgres | **multi-host native** | Nothing assumes a shared host; POC #2 ran all-through-network (docker bridge) with the same properties ([ADR-004](decisions/004-postgres-driver.md)). |
|
||||
|
||||
The unified trait must not pretend SQLite is multi-host — but whether
|
||||
that honesty lives as runtime capability flags, compile-time engine
|
||||
knowledge, or a documented matrix only is OQ-08
|
||||
([ADR-006](decisions/006-wake-and-delivery-contract.md) note: the
|
||||
trait's shape constrains where capability differences can surface).
|
||||
The unified trait must not pretend SQLite is multi-host — and it does
|
||||
not: [ADR-016](decisions/016-deployment-honesty.md) resolves that
|
||||
honesty to compile-time engine identity (the engine crate a binary
|
||||
depends on *is* the deployment statement) plus this documented matrix.
|
||||
There is no `Store::capabilities()` — the trait's shape constrains
|
||||
where capability differences can surface
|
||||
([ADR-006](decisions/006-wake-and-delivery-contract.md)), and the
|
||||
resolution is: nowhere at runtime.
|
||||
|
||||
Options for OQ-08, with their shape:
|
||||
Options for OQ-08, with their outcome
|
||||
([ADR-016](decisions/016-deployment-honesty.md)):
|
||||
|
||||
1. **Compile-time only** — a consumer chooses an engine crate at
|
||||
dependency time; the engine's docs carry its deployment facts.
|
||||
Smallest contract; nothing runtime to match on.
|
||||
Smallest contract; nothing runtime to match on. **Adopted** —
|
||||
together with (3); the two compose (engine docs serve the consumer
|
||||
choosing the dependency, the matrix serves the operator choosing
|
||||
the topology).
|
||||
2. **`Store::capabilities()`** — a runtime description
|
||||
(payload limits, wake cadence knobs, host semantics). Lets a
|
||||
consumer adapt (e.g., chunk large notify payloads) but adds a
|
||||
contract surface all engines must keep honest.
|
||||
contract surface all engines must keep honest. **Rejected** —
|
||||
field-by-field under ADR-008 §5's act-differently rule, and no
|
||||
consumer-inventory row names a runtime-adapt need
|
||||
([ADR-016](decisions/016-deployment-honesty.md) §2).
|
||||
3. **Deployment matrix only** (this document) — no API surface. The
|
||||
honest-middle choice; matches the ecosystem's doc-first posture
|
||||
but provides no programmatic guard.
|
||||
but provides no programmatic guard. **Adopted** (with (1)) — the
|
||||
"programmatic guard" gap is closed where it can honestly be:
|
||||
the engine-crate dependency edge cannot drift out of sync with
|
||||
the truth it states; the misconfiguration case (SQLite as shared
|
||||
network storage) follows the family's
|
||||
deployment-asserts-truth posture — documented detection symptom,
|
||||
no fabricated runtime machinery
|
||||
([ADR-016](decisions/016-deployment-honesty.md) §3).
|
||||
|
||||
## Connection budgets
|
||||
|
||||
@@ -107,7 +127,8 @@ From both POCs (single-box, relative shapes are the deliverable —
|
||||
| [003](decisions/003-sqlite-driver.md) | SQLite driver | bundling, toolchain floor |
|
||||
| [004](decisions/004-postgres-driver.md) | Postgres driver | listener budget line, forwarder posture |
|
||||
| [006](decisions/006-wake-and-delivery-contract.md) | Wake contract | where capability differences may surface |
|
||||
| [008](decisions/008-contract-v1-pinning.md) | Contract v1 | constructor/options in engine crates; no capability surface in v1 (OQ-08) |
|
||||
| [008](decisions/008-contract-v1-pinning.md) | Contract v1 | constructor/options in engine crates; no capability surface in v1 (OQ-08; resolved by [ADR-016](decisions/016-deployment-honesty.md)) |
|
||||
| [016](decisions/016-deployment-honesty.md) | Deployment honesty | no runtime capability surface — compile-time identity + this matrix; `PayloadTooLarge` is the one runtime asymmetry carriage |
|
||||
|
||||
## Open Questions
|
||||
|
||||
@@ -115,5 +136,8 @@ Open questions are tracked in
|
||||
[open-questions.md](open-questions.md). Key
|
||||
questions affecting this document:
|
||||
|
||||
- **OQ-08**: capability-surface shape — compile-time vs runtime flags
|
||||
vs matrix-only (open)
|
||||
- **OQ-08**: capability-surface shape — **resolved**
|
||||
(2026-10-06, [ADR-016](decisions/016-deployment-honesty.md)):
|
||||
no runtime capability surface; compile-time engine identity +
|
||||
this matrix; re-entry via a consumer-inventory row naming a
|
||||
runtime-adapt need.
|
||||
Reference in new issue
Block a user