ADR 0097: an undeclared base is said, not yet refused
This commit is contained in:
@@ -220,9 +220,11 @@ and nothing uploaded on a second copy.
|
||||
([ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md)). A build's `on`
|
||||
entry is a module's artifact or an image published elsewhere, pinned by digest, read from one
|
||||
build argument; the image is copied into the mesh's registry before the build and the recipe is
|
||||
handed the copy. A recipe whose `FROM` or `COPY --from` names a registry image the manifest did not
|
||||
declare is refused before the build, naming it and the remedy. *How it is checked:* builder tests
|
||||
on a declared and an unpinned vendor image, and a recipe test on what counts as a fetch.
|
||||
handed the copy. A recipe whose `COPY --from` names a registry image the manifest did not declare
|
||||
is refused before the build, naming it and the remedy; an undeclared `FROM` is said, not yet
|
||||
refused, because the mesh's own images start from a public base and declare none. *How it is
|
||||
checked:* builder tests on a declared and an unpinned vendor image, and a recipe test on what
|
||||
counts as a copy and what as a base.
|
||||
|
||||
### What it puts on a machine
|
||||
|
||||
|
||||
Reference in New Issue
Block a user