026 filed; 025 corrected; the image store is a module
Three corrections, two of them to things I wrote today. 026 is the serious one. Four modules mounted fourteen host paths nothing declared — the mail spool, the databases, the object store's data. The runtime creates those as root, so owner and mode go unapplied, and the rule that keeps a directory holding data the mesh did not put there is written in terms of declared directories. It reached the configuration and missed the data. The cause was carrying compose files across: a container shape that can express one gets filled in like one. 025 claimed nothing turns a tag into a digest. That is false, and the answer was designed and built before I wrote it. A module names an artifact, not an image, and `kind: upstream` mirrors somebody else's image into the mesh's own registry, pinned by the digest it lands with. The two-document split the issue described as the shape of a fix is the design. Pinning twelve images by hand was treating the symptom, and left them pointing at a public registry rather than the mesh's. And the image store was written up as something the mesh does. It is an ordinary module — considered for the substrate and removed, because the test is whether the control plane needs it before its first instruction, not whether it can grant itself one. So somebody's own registry is the same module as the mesh's.
This commit is contained in:
@@ -162,6 +162,13 @@ same module. There is one derivation here, and there should stay one.
|
||||
**A live listing returned credentials in plaintext.** Not a coverage question, but the reason
|
||||
sealing is worth its inconvenience.
|
||||
|
||||
**An image store is a module, and was written up here as something the mesh does.** It was
|
||||
considered for the substrate and removed, because the test is not *can it grant itself one* —
|
||||
nearly anything passes that — but whether the control plane needs it before it can give its first
|
||||
instruction. It does not. So a registry somebody runs for their own images is the same module as
|
||||
the one the mesh runs for its own: it offers a place to push, and claims that role once per
|
||||
machine.
|
||||
|
||||
**A rule was enforced only at the far end.** A module may not declare an action, and the host
|
||||
refused one correctly — but the control plane accepted it into the catalogue, resolved it and
|
||||
pushed it, so the refusal arrived on a machine with nothing tying it back to the manifest. The
|
||||
|
||||
Reference in New Issue
Block a user