docs: renumber ADR-008 -> ADR-010 after canon ID collision
ADR-008 was concurrently allocated by two authors on 2026-08-17: the multi-tenancy framework (earlier provenance, draft-1 lineage) and the hub authority model. The multi-tenancy ADR keeps 008; the hub authority model becomes ADR-010. Also corrects the 'read replica' phrasing in T01, superseded by ADR-010. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
b65b5fb144
commit
a4637fdaf3
1 changed files with 6 additions and 6 deletions
|
|
@ -55,7 +55,7 @@ priority: high
|
|||
|
||||
Until derivation ships, exactly one instance may write hub identifiers into
|
||||
repository files. The interim registrar is the automated production instance;
|
||||
workstation hubs are development read replicas.
|
||||
workstation hubs are rebuildable caches (`ADR-010` decision 2).
|
||||
|
||||
- Make the writeback path refuse to mint identifiers when the instance is not
|
||||
the registrar, rather than relying on operator discipline.
|
||||
|
|
@ -152,14 +152,14 @@ status: wait
|
|||
priority: high
|
||||
```
|
||||
|
||||
Implement `ADR-008` decisions 1–3: the central hub on railiance is authoritative
|
||||
Implement `ADR-010` decisions 1–3: the central hub on railiance is authoritative
|
||||
as a *reading* of the repositories; local instances become rebuildable caches.
|
||||
|
||||
- A cache must be discardable and reconstructable from repository files alone,
|
||||
with no work lost.
|
||||
- Local work must not require a hub — repository files are self-describing, so
|
||||
reading them is sufficient for working inside a repo.
|
||||
- Cache reads are advisory and must carry their staleness (`ADR-008` decision 8).
|
||||
- Cache reads are advisory and must carry their staleness (`ADR-010` decision 8).
|
||||
|
||||
Measured 2026-08-17: 955 workplans locally against 649 on the primary, 320
|
||||
local-only, of which **288 are backed by files that all exist on disk**. That
|
||||
|
|
@ -173,7 +173,7 @@ status: wait
|
|||
priority: high
|
||||
```
|
||||
|
||||
Implement `ADR-008` decision 4. The two kinds need opposite handling:
|
||||
Implement `ADR-010` decision 4. The two kinds need opposite handling:
|
||||
|
||||
- **File-derived** (workplans, tasks, statuses, dependencies) — central derives
|
||||
it and must not accept pushes of it (decision 5). Offline, the git commit *is*
|
||||
|
|
@ -201,7 +201,7 @@ priority: high
|
|||
|
||||
28 records exist in the local instance with no backing file. They are the only
|
||||
records a cache rebuild would drop, so they must be classified first
|
||||
(`ADR-008` § Orphan disposition):
|
||||
(`ADR-010` § Orphan disposition):
|
||||
|
||||
1. **Broken links** — a file exists but `backing_filename` was never recorded.
|
||||
`RMGR-WP-0004` is a confirmed instance. Repair the link; no data at risk.
|
||||
|
|
@ -229,7 +229,7 @@ status: wait
|
|||
priority: medium
|
||||
```
|
||||
|
||||
Implement `ADR-008` decision 7. The retirement splits one hub into several, which
|
||||
Implement `ADR-010` decision 7. The retirement splits one hub into several, which
|
||||
is permitted only if every record has exactly one authoritative hub, determined
|
||||
by its repository and domain.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue