Galaxy Deploy
Design notes on Galaxy Deploy: planning and running services across a heterogeneous fleet.
The gaps invented scenarios miss
Forty-three imagined workloads found the interesting failures. Four real repositories found a numeric user id.
Where the model broke
Two counterexamples that killed mechanisms which looked sound, and the rule they left behind.
The facts only the machine can answer
Probes are nodes in the deployment graph, so a plan takes as many evaluation stages as its dependencies require.
Change one value, move one service
Identity comes from content, and the plane a value travels on is derived rather than declared.
Ask first, receive later
A module states what it needs, the planner answers, and the second half of the module runs with the answers.
Nothing below the deployment plan evaluates Nix
One artifact cuts the system in half, and only the top half needs Nix.
Services are the new atoms
Why the unit of deployment decides your fleet, and what a heterogeneous fleet exposes.