Skip to content
Harobanda

The cloud

A cloud is a file, not a service you run.

Here a cloud is several declared machines, on several networks, serving one solution. You compose it the way you write one machine, in text files that are checked before anything boots, and no program manages it: the files, and each machine's own check of its own boot, are all the control there is. Two of the six steps it takes are built, and half of a third; every boot on these pages ran in an emulator.

The smallest cloud. A fleet file at the top names three machines and the two links between them. A till, on the front link, asks for a server by name. A box, drawn with the one orange mark, has a foot on both links and is the way between them. A server, RingServ 0.9, is on the core link. Beneath them, what the machines said, quoted from the pinned boot: the box says commons.core.cloud is 10.20.0.2; the till gets commons.core.cloud:8210/health -- 200; the server runs as appserver (2000:2000). A last band lists what is not there yet: no front, only plain HTTP inside the cloud; no packet filter, a route is a way both ways; no board, every boot shown is emulated. The smallest cloud, as a column. A fleet file names three machines and the two links between them. A till asks for a server by name; the front link joins it to a box, drawn with the one orange mark, which is the way between; the core link joins the box to a server, RingServ 0.9. Then what the machines said, quoted from the pinned boot: the box says commons.core.cloud is 10.20.0.2; the till gets commons.core.cloud:8210/health -- 200; the server runs as appserver (2000:2000). Last, what is not there yet: no front, only plain HTTP inside the cloud; no packet filter, a route is a way both ways; no board, every boot shown is emulated.

This is the smallest cloud there is: three machines on two networks, each booted from its own file in an emulator, and a fleet file that names them. The till, a shop's counter device and here simply the machine that asks, is on the front network, and the server is on the core network. The box has a foot on each, and the fleet file says it is the one machine that is the way between them. The till asks the box for commons.core.cloud, is told 10.20.0.2, and reaches the server, which answers its health check.

The server is RingServ 0.9, built from its own source at a pinned version, and it stands in for a customer's server. It runs as a user of its own, not as root, in directories only that user may write.

What the machines said

Every line is quoted from a pinned boot.

A pinned boot is a transcript the repository keeps and compares, line for line, with each new run: if a machine says something else, the comparison fails. These lines are from the three machines above, from a device the fleet file never named, and from the same box with one line taken out of its file.

the smallest cloud, from its pin
# the box, which is the way between the two networks
box: boot: forward -- between front and core: a packet that arrives on one may leave by another, and nothing here filters it
box: boot: names front -- commons.core.cloud is 10.20.0.2, through this machine

# the server, behind the box
core: boot: state -- ringserv owns /run/ringserv and /data/ringserv as appserver (2000:2000); each made, then read back as that identity's, mode 0700

# the till, asking by name
till: ask commons.core.cloud -- 10.20.0.2 (from 192.168.20.1)
till: get http://commons.core.cloud:8210/health -- 200 {"code":0,"message":"OK","data":{"up":true}}

# a device nobody declared, on the same network
stranger: boot: network front -- eth0 dhcp: no lease after 3 tries (no server answered on this network)
stranger: ask commons.core.cloud -- no resolver: this machine was never told where to ask (/etc/resolv.conf)

# the same box with one line of its file taken out: FORWARD yes
closed: ask commons.core.cloud -- no such name on this network (from 192.168.20.1)

The first two lines are the box saying what it will do for both networks. The third is the server's own user and the directories it was handed. The till's two lines are the question and the server's answer. The stranger is a machine whose hardware address the fleet file never declared: it is given no address, so no router and no resolver, and is told nothing. Without its one line the box serves both networks but is the way between neither, so the till is told the name does not exist. A device that chose its own address and named the box as its gateway would still be carried, because forwarding filters nothing.

Next: How it is written → The three kinds of file that write a cloud, what is left out on purpose, and what you keep when somebody else owns the hardware.