From 43ca9ce0ae259d180101af1a42ef671190ff5024 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 20:48:19 +0200 Subject: [PATCH] ADR 0097: an undeclared base is said, not yet refused --- ...0097-a-vendor-image-is-a-declared-build-input.md | 13 +++++++++---- 03-DESIGN/01-to-be/18-building-a-module.md | 8 +++++--- 2 files changed, 14 insertions(+), 7 deletions(-) diff --git a/02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md b/02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md index 3763486..7b0131c 100644 --- a/02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md +++ b/02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md @@ -31,10 +31,15 @@ named it directly and the build worked when the public registry answered, which A build's `on` entry is either a module's artifact or an image published elsewhere, pinned by digest, read from one build argument. Before the build the image is copied into the mesh's registry under the module's repository and the recipe is handed the copy; genesis, with no -registry, pulls it into the first machine's store. A recipe whose `FROM` or `COPY --from` names a -registry image the manifest did not declare is refused before the build, naming the image and -the remedy; its own stages, declared arguments and `scratch` are not fetches. An unpinned vendor -image is refused: a tag is what somebody else can move. +registry, pulls it into the first machine's store. A recipe whose `COPY --from` names a registry +image the manifest did not declare is refused before the build, naming the image and the remedy; +its own stages, declared arguments and `scratch` are not fetches. An unpinned vendor image is +refused: a tag is what somebody else can move. + +A recipe whose `FROM` names an undeclared base is **said, not yet refused**: the mesh's own images +— the control plane's, the builder's, the tool runtime's — start from a public base and declare +none, and refusing those refuses genesis. They declare their bases next; until then every build +names the undeclared base and the remedy. The package half of the issue is not decided here: the mesh's package registry already proxies the public one, and the failure the report saw has to be run again to be placed. diff --git a/03-DESIGN/01-to-be/18-building-a-module.md b/03-DESIGN/01-to-be/18-building-a-module.md index d28567d..752e14c 100644 --- a/03-DESIGN/01-to-be/18-building-a-module.md +++ b/03-DESIGN/01-to-be/18-building-a-module.md @@ -220,9 +220,11 @@ and nothing uploaded on a second copy. ([ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md)). A build's `on` entry is a module's artifact or an image published elsewhere, pinned by digest, read from one build argument; the image is copied into the mesh's registry before the build and the recipe is -handed the copy. A recipe whose `FROM` or `COPY --from` names a registry image the manifest did not -declare is refused before the build, naming it and the remedy. *How it is checked:* builder tests -on a declared and an unpinned vendor image, and a recipe test on what counts as a fetch. +handed the copy. A recipe whose `COPY --from` names a registry image the manifest did not declare +is refused before the build, naming it and the remedy; an undeclared `FROM` is said, not yet +refused, because the mesh's own images start from a public base and declare none. *How it is +checked:* builder tests on a declared and an unpinned vendor image, and a recipe test on what +counts as a copy and what as a base. ### What it puts on a machine