docs(canon): ADR-008 hub authority and local cache model (proposed)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Central hub on railiance is authoritative as a reading of the repositories;
local instances become rebuildable caches, never peer databases. Local work
requires no hub at all — repo files are self-describing.

Classifies hub data by origin: file-derived (central derives, never accepts
pushes, conflicts are git conflicts) vs hub-native (central owns, needs a
write path and an append-only offline buffer). Neither kind needs a hub-side
conflict model.

Measured divergence: 955 local / 649 primary / 320 local-only, of which 288
are backed by files that all exist on disk. Only 28 orphans need
disposition, and they are the ADR-001 violations.

Corrects ADR-007's 'development read replica' wording — the workstation
instance was the larger of the two by 306 workplans.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-17 12:18:01 +02:00
parent 495ecc61bd
commit f8038ecde5
2 changed files with 167 additions and 3 deletions

View file

@ -109,9 +109,15 @@ Decision 1 must therefore be enforced before derivation ships.
*Interim state (A).* Until derivation lands, exactly one instance writes hub
identifiers into repository files. Other instances may read, project, and serve,
but must not mint workplan or task UUIDs into git-tracked files. The interim
registrar is the automated production instance; workstation hubs are development
read replicas.
but must not mint workplan or task UUIDs into git-tracked files.
> **Corrected 2026-08-17, superseded by `ADR-008` decisions 1–3.** This decision
> originally described workstation hubs as "development read replicas". That was
> wrong on both counts: the workstation instance was not a replica, and it was
> the *larger* of the two, holding 306 more workplans than the primary. The two
> instances were peer databases. `ADR-008` establishes the central hub as
> authoritative and local instances as rebuildable caches, which is what makes
> this interim rule coherent.
The interim is policy, enforced by discipline, and it has a real cost:
registration requires connectivity to the registrar, so disconnected work cannot