The SDK's delivery is decided; the git URL violates it
ADR 0014 is accepted and unambiguous: each module consumes its dependencies from the private registry, the mesh's own shared library included, and a cross-package change is publish then consume. So the git dependency at a pinned commit is not a mechanism under consideration. It is the shared library being consumed a way the record rules out, and the lock naming a sibling directory is what that looks like when nobody publishes. Issue 053 is reclassified from a question about mechanism to a violation with a direction. What stays open is narrower and real: which software serves the private registry, and that a fresh mesh has none when the first SDK is built — ADR 0014 assumes one exists, and at genesis nothing has installed it. Recorded after arguing at length for a bespoke content-addressed alternative, against a decision that was already made and that I had not read. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -163,9 +163,13 @@ knows. Putting the Plex client anywhere else is the shared-library disease with
|
||||
|
||||
### What this leaves open
|
||||
|
||||
- **Which registry.** The catalogue holds a `verdaccio` module, and a forge typically serves package
|
||||
registries too. Two answers exist and nothing says which is the mesh's. That has to be settled
|
||||
before anything publishes.
|
||||
- **Which private registry.** That there *is* one is settled —
|
||||
[ADR 0014](../../02-DECISIONS/0014-no-npm-workspace.md) says each module consumes its dependencies
|
||||
from the private registry, the mesh's own shared library included. Which software serves it is
|
||||
not: the catalogue holds `verdaccio`, and a git host usually serves package registries too.
|
||||
- **And the bootstrap does not have one.** ADR 0014 assumes a registry exists; on a fresh mesh
|
||||
nothing has installed one when the first SDK is built. That is the same pivot as everything else
|
||||
and it has not been designed.
|
||||
- **Who may publish.** A builder pushing a package needs an account on that registry, which is a
|
||||
credential in the bootstrap path and does not exist yet.
|
||||
- **Versions and ranges.** Everything else the mesh delivers is pinned by digest, and a range is
|
||||
|
||||
Reference in New Issue
Block a user