Access triggers materialization; dials wait for bootstrap
Source:
harness/docs/decisions/lazy-provisioning.md
Status: Current
Access triggers materialization; dials wait for bootstrap
Section titled “Access triggers materialization; dials wait for bootstrap”Decision
Section titled “Decision”Unseeded-ness is materialization, not a client’s retry loop. A client dialing a plane must not invent backoff against a transient “not ready” code. The server holds the upgrade until open-time bootstrap completes (bounded), then accepts.
Concretely: replication open bootstraps the Y.Doc + kernel/session model roots (genesis
modules may construct model entities), then accepts the connection. One daemon hosts the
kernel and session planes. Clients wait for local
roots with a deadline (sdk). That wait is doc bootstrap, not “spawn a runner then
seed.”
PEW execution lives in that same daemon process — nothing is provisioned per dial.
Two bounds
Section titled “Two bounds”- Bounded. Unbounded waiting turns broken bootstrap into a silent hang.
- Observable. Failures name the cause; lazy is not silent.
What this is not
Section titled “What this is not”- Not dial-time runner spawn / want→consider.
- Not peer-id uniqueness refuse on upgrade (path/token only).
- Not a client 409-unseeded retry policy.
Rationale
Section titled “Rationale”Client-side retry against transient unready worked and was the wrong shape: every client reimplemented “wait for materialization.” Holding the upgrade next to the provisioner keeps intent (“observe this plane”) honest.