ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended
This commit is contained in:
@@ -7,6 +7,7 @@ code:
|
||||
- mesh-catalog modules/builder
|
||||
updated: 2026-09-21
|
||||
decisions:
|
||||
- 02-DECISIONS/0091-a-mount-is-declared-three-ways.md
|
||||
- 02-DECISIONS/0087-a-seeded-file-is-created-once.md
|
||||
- 02-DECISIONS/0040-what-a-module-is.md
|
||||
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
||||
@@ -182,6 +183,16 @@ disagrees with it.
|
||||
| `computed` | marks a module the controller generates rather than an author writing |
|
||||
| `build.artifacts` | what it produces |
|
||||
|
||||
**A container mounts only what the manifest declares**
|
||||
([ADR 0091](../../02-DECISIONS/0091-a-mount-is-declared-three-ways.md)). A bind mount the module
|
||||
never declared is created by the container runtime as root, so the module's owner and mode never
|
||||
reach its data and the rule that keeps data when a module goes away does not cover it. A path is
|
||||
declared in one of three ways, for the three things a path can be: the module's own (a directory
|
||||
or file resource, or where a secret, grant or contribution lands), the operator's (an `accesses`
|
||||
entry), or the machine's (a facility a declared capability grants — `container-runtime` grants its
|
||||
socket). *How it is checked:* the parser refuses an undeclared mount naming the path and the three
|
||||
remedies, and a test parses every manifest in the catalogue beside the checkout.
|
||||
|
||||
### What it builds
|
||||
|
||||
| kind | is |
|
||||
|
||||
Reference in New Issue
Block a user