ADR 0097: an undeclared base is said, not yet refused
This commit is contained in:
@@ -31,10 +31,15 @@ named it directly and the build worked when the public registry answered, which
|
|||||||
A build's `on` entry is either a module's artifact or an image published elsewhere, pinned by
|
A build's `on` entry is either a module's artifact or an image published elsewhere, pinned by
|
||||||
digest, read from one build argument. Before the build the image is copied into the mesh's
|
digest, read from one build argument. Before the build the image is copied into the mesh's
|
||||||
registry under the module's repository and the recipe is handed the copy; genesis, with no
|
registry under the module's repository and the recipe is handed the copy; genesis, with no
|
||||||
registry, pulls it into the first machine's store. A recipe whose `FROM` or `COPY --from` names a
|
registry, pulls it into the first machine's store. A recipe whose `COPY --from` names a registry
|
||||||
registry image the manifest did not declare is refused before the build, naming the image and
|
image the manifest did not declare is refused before the build, naming the image and the remedy;
|
||||||
the remedy; its own stages, declared arguments and `scratch` are not fetches. An unpinned vendor
|
its own stages, declared arguments and `scratch` are not fetches. An unpinned vendor image is
|
||||||
image is refused: a tag is what somebody else can move.
|
refused: a tag is what somebody else can move.
|
||||||
|
|
||||||
|
A recipe whose `FROM` names an undeclared base is **said, not yet refused**: the mesh's own images
|
||||||
|
— the control plane's, the builder's, the tool runtime's — start from a public base and declare
|
||||||
|
none, and refusing those refuses genesis. They declare their bases next; until then every build
|
||||||
|
names the undeclared base and the remedy.
|
||||||
|
|
||||||
The package half of the issue is not decided here: the mesh's package registry already proxies
|
The package half of the issue is not decided here: the mesh's package registry already proxies
|
||||||
the public one, and the failure the report saw has to be run again to be placed.
|
the public one, and the failure the report saw has to be run again to be placed.
|
||||||
|
|||||||
@@ -220,9 +220,11 @@ and nothing uploaded on a second copy.
|
|||||||
([ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md)). A build's `on`
|
([ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md)). A build's `on`
|
||||||
entry is a module's artifact or an image published elsewhere, pinned by digest, read from one
|
entry is a module's artifact or an image published elsewhere, pinned by digest, read from one
|
||||||
build argument; the image is copied into the mesh's registry before the build and the recipe is
|
build argument; the image is copied into the mesh's registry before the build and the recipe is
|
||||||
handed the copy. A recipe whose `FROM` or `COPY --from` names a registry image the manifest did not
|
handed the copy. A recipe whose `COPY --from` names a registry image the manifest did not declare
|
||||||
declare is refused before the build, naming it and the remedy. *How it is checked:* builder tests
|
is refused before the build, naming it and the remedy; an undeclared `FROM` is said, not yet
|
||||||
on a declared and an unpinned vendor image, and a recipe test on what counts as a fetch.
|
refused, because the mesh's own images start from a public base and declare none. *How it is
|
||||||
|
checked:* builder tests on a declared and an unpinned vendor image, and a recipe test on what
|
||||||
|
counts as a copy and what as a base.
|
||||||
|
|
||||||
### What it puts on a machine
|
### What it puts on a machine
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user