Installing ends with a builder, and the record says so

The design said how the builder arrives was unsettled and that nothing
installed it — the one gap stopping a fresh mesh from producing anything. Both
are now false. What is still true is narrower and worth keeping separate:
nothing asks a raised mesh for the rest of the catalogue, and no bed asserts
that it could.
This commit is contained in:
2026-09-14 12:34:26 +02:00
parent aa35ba1594
commit 256884e671
+14 -11
View File
@@ -104,11 +104,15 @@ names what its artifacts are and nothing has made them.
So installing continues:
**The builder arrives.** It is a module like any other and is assigned to a machine like any other,
but it cannot be built by the thing it is — see
**The builder arrives, and installing is what brings it.** It is a module like any other and is
assigned to a machine like any other, but it cannot be built by the thing it is — see
[`12-a-module-repository`](12-a-module-repository.md#the-three-the-loop-cannot-build-and-there-are-only-three).
**How it arrives is unsettled**, and it is the one gap that stops everything after this paragraph
from being possible on a machine nobody is sitting at.
So it is carried, and it is already here: it is what built the control plane. The last step of
installing publishes it into the mesh's own registry, installs it as an ordinary module pinned to
that digest, and issues it a broker account — the same two acts the control plane went through,
plus the one thing only a builder needs. The account is issued before the machine is sent anything,
because a builder that arrives without its credential starts, finds nothing it may read, and waits,
which looks exactly like a builder with no work.
**The core modules are built.** Each is named by a repository and a path
([ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md)), and the builder is
@@ -159,11 +163,10 @@ needs a toolchain and a working tree, which is most of the burden the installer
**A mesh cannot say how it was raised.** Nothing afterwards can contradict a claim that a machine
was brought up the supported way, so the rule that it must be is, today, unenforced.
**The builder's own module is not installed by genesis.** The installer carries a builder and uses
it, so a fresh mesh is raised on something it built; but nothing afterwards installs that builder as
an ordinary module on the machine, so the mesh cannot yet be asked to build anything else. The
paragraphs above describing the core modules being built can start now — a builder exists and has
somewhere to publish — and nothing yet starts them.
**Nothing asks for the core modules yet.** Installing ends with a builder that works — a raised
machine will build the shared base and a module on top of it when asked — and nothing asks. The
paragraphs above describing the catalogue being built are a thing somebody now types, rather than a
thing that cannot happen.
**A module's declaration still has to be copied onto the machine by hand.** The installer reads the
registry's and the control plane's manifests from a checkout somebody put there. The control plane's
@@ -184,7 +187,7 @@ pulling problem, not a genesis one.
| Every step may be run again | The installer is re-run against a raised machine and must change nothing and report why. |
| An image is named exactly | A machine refuses a bundle naming an image by tag. The refusal is exercised, not assumed. |
| The installer is what installed this | **Nothing.** See above. |
| The builder can arrive on a fresh mesh | The installer carries it, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. |
| The builder can arrive on a fresh mesh | The installer carries it and installs it as its last step, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. |
| The control plane a mesh runs is one it built | The genesis bed asserts the running control plane is pinned to a digest this mesh's own registry serves, for an image built from a named repository and commit — not one the installer carried. |
| A core module is built rather than only carried | The control plane is rebuilt from its own repository and path, and the running mesh is upgraded to the result — the same path any module takes. |
| Installing produced a mesh that can produce | After installing, a module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. |
| Installing produced a mesh that can produce | A module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. **Done by hand on a raised machine, not yet by a bed** — it built the shared base and then a module naming that base. Nothing automated asserts it, which makes this the weakest check on this page. |