Volter World

0017: The runtime's own infrastructure starts beside the co-located host

Status: Accepted. Date: 2026-10-07. Amends ADR 0015's rule that every declaration other than a twin waits for the host and every earlier service.

A World's managed infrastructure is the external service whose up is this runtime's own volter-world-infra up, run inside the runtime's process (runOwnInfrastructureUp). It starts the World's PGlite host, its redis twin and its mongod. ADR 0015 let a later twin declaration start beside the co-located host's startup, but the infrastructure is declared external. So it waited for the host's receipt and port admission, then for every earlier service's readiness, and only then created its database. In the browser tab that order set the docker boot. In Rallly's run 19 (page clock), up began at 2.90 s and the seven co-located twin ports listened at 6.09 s. The database child spawned at about 7.0 s, its port opened at 9.78 s, and the image's CMD missed its 10 s budget.

The runtime knows this service's shape because the code is its own. The infrastructure phase reads the World's configuration (VOLTER_WORLD_CONFIG, VOLTER_WORLD_DATA, the backing choice and the World's own variables), never another service's environment. It contacts no declared service while it starts: the PGlite host, the redis twin and mongod serve and call nothing. That is the same contract ADR 0015 relies on for a twin.

So the runtime starts its own infrastructure once the co-located host is spawned, with a copy of the environment as it stands then. It does not wait for the host's readiness or for any earlier service. Its result is taken at its declared position, so the record, the environment merge, issued credentials and the proxy environment keep declaration order. At that position the runtime still takes the host's readiness first, as it did before, so the host's twins' issued credentials merge ahead of the infrastructure's discovered variables. What changes is that its up has been running all along, so the boot pays the longer of the two startups instead of their sum. A non-twin declared before it still waits for the host, as before. up still returns only after every readiness. A failure in the early start fails the boot, as the host's does. Its teardown is published when it begins, as for every external service. Before rolling back, the runtime aborts the boot and waits for that up to settle, so down never runs beside a still-running up.

Boundary

Only the runtime's own volter-world-infra up is moved, identified as the in-process phase is (ownInfrastructureUp). Any other external service, whose command the runtime cannot read, waits as ADR 0015 says. If the infrastructure ever reads another service's variables while it starts, this decision no longer holds and must be revisited: it would see the environment from before those services started.

Evidence

Unmeasured. The motivating timings are Rallly run 19's page-clock readings, relayed by the orchestrator (thread B's run; engine-doors' profile put PGlite at 2.2 s of that realm). The effect of this change has not been run. Thread B's next Rallly run on this branch gives the number.

View Markdown source

On this page