slides(tappaas): correct the rewrite history, note the other instances
All checks were successful
Build docs site / build (push) Successful in 46s
Build slides / build (push) Successful in 1m6s

The ADR-007 rewrite was the move from a flat pile of sequenced scripts to the
manager/controller paradigm — not the dependsOn change. That was an earlier
and separate rewrite, ADR-003: a plain install.sh per module replaced by
dependsOn/provides contracts the platform resolves into an order.

Also: a closing line on the hardware slide that this is one of five known
instances, and the September 2025 gap now answers itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Lars Rossen 2026-08-25 18:02:55 +02:00
parent d08e8ad743
commit e1d69309b8

View file

@ -19,7 +19,7 @@ th, td { padding: 0.2em 0.55em; }
code.todo { color: #ff8a80; font-weight: 600; }
/* Mermaid renders at its natural size, which is far too small on a projector. */
div.mermaid { display: flex; justify-content: center; width: 100%; }
div.mermaid svg { width: 100% !important; height: auto !important; max-height: 500px; }
div.mermaid svg { width: 100% !important; height: auto !important; max-height: 460px; }
section.diagram h2 { margin-bottom: 0.1em; }
/* Hand-drawn diagrams (inline SVG) get the same full-width treatment. */
section.diagram > svg { display: block; width: 100%; height: auto; max-height: 520px; margin: 0 auto; }
@ -143,8 +143,13 @@ flowchart TB
sw --- modem
```
This is one basement. **There are 4 other known instances of TAPPaaS.**
<!--
Every number here was read off the running cluster, not a wiki page.
The last line is deliberately understated — it sets up the sharing argument
in The Bad, and the Community repo in the next slide. Five sites is not a
movement yet; it is proof the thing installs somewhere that is not here.
Worth saying out loud: only tanka1 on tappaas1 is a mirror. tappaas2 and
tappaas3 run single NVMe — deliberate, they are rebuildable from backup.
The 10G links are direct-attach copper; tappaas1 and tappaas3 have a second
@ -356,7 +361,7 @@ What it actually cost.
**September–October 2025: 15 commits in two months.**
`TODO: what actually happened here — say it plainly, it is the most relatable slide in the deck`
I was on vacation.
The lesson I take from it: a self-hosted platform that needs *you* every week
is not a platform, it is a pet.
@ -446,22 +451,26 @@ TODO: your own hours-per-week number makes the concession land harder.
- **The predecessor.** I ran a hand-built setup for a few years before TAPPaaS
existed. Every design decision here is an argument I already lost once, at home.
- **Rewrite 1 — ADR-007.** Foundation modules used to be *numbered*:
`05-ProxmoxNode`, `10-firewall`, `30-tappaas-cicd`. The number **was** the
install order. Retired: order is now computed from `dependsOn`.
- **Rewrite 2 — ADR-014.** Zone tiers lived in prose in a README. Now `tier` and
`isolated` are state, and four invariants are machine-checked on every reconcile.
- **Rewrite 1 — ADR-003.** Every module was a plain `install.sh` you ran in the
right order, by hand. Replaced by `dependsOn` / `provides` contracts, resolved
into an install order by the platform.
- **Rewrite 2 — ADR-007.** The flat pile of sequenced scripts became a
**manager / controller** paradigm: 7 TypeScript managers that own intent,
6 controllers that do the live I/O against OPNsense, Authentik, Proxmox, the switch.
Both times the same lesson: something I had encoded as a **convention**
had to become a **declaration**.
Both times the same mistake: I had written as a **sequence of steps**
what needed to be a **structure** — dependencies the first time, roles the second.
`TODO: name the predecessor, and say how long you ran it`
<!--
This is the credibility slide. Do not soften the "No" — an audience that has
just been told you gave an AI root needs to hear that you rebuild things when
they are wrong. The ADR-007 and ADR-014 stories are both in the repo if
anyone wants to check.
they are wrong.
Both ADRs are in the repo, and ADR-007f was written by Erik, not me — which
is the two-reviewer rule from Guardrail 1 doing its job in public.
If you want a third: ADR-014 recast zone tiers from README prose into checked
state, and its own changelog lists four things the draft got wrong.
-->
---