Issue 113: ground the rebuildability point in what the design actually says
Review of my own text found an unattributed claim — "the mesh's claim that a node can be rebuilt from its declarations" — which is not a stated principle anywhere. Replaced with the design position that genuinely covers it: to-be 07 chooses references over payload because "reproducibility comes from pinning the identity of a thing rather than carrying its bytes". This incident is that choice's failure mode when the identity stops resolving, which is a sharper point than the one I made. Scope stated honestly: the passage is about the foundation bundle and this module is not in it, but pin-identity-fetch-bytes is how every module gets third-party images. Also names the tension the mirroring question actually carries — mirroring is a move away from references-over-payload, so it is a decision, not a fix.
This commit is contained in:
@@ -75,9 +75,19 @@ necessary.
|
|||||||
The instance is harmless; the standing condition is not.
|
The instance is harmless; the standing condition is not.
|
||||||
|
|
||||||
1. **No new node can ever provision this module.** Every node that does not already hold the
|
1. **No new node can ever provision this module.** Every node that does not already hold the
|
||||||
images is permanently unable to obtain them. The mesh's claim that a node can be rebuilt from
|
images is permanently unable to obtain them, and the same will be true of any module whose
|
||||||
its declarations is false for this module, and will be false the same way for any module whose
|
|
||||||
upstream withdraws an image.
|
upstream withdraws an image.
|
||||||
|
|
||||||
|
This is the failure mode of a deliberate design choice, which is why it is worth recording
|
||||||
|
rather than patching. The foundation design chooses **references over payload** — *"the bundle
|
||||||
|
names images by digest and the host fetches them"* — on the stated grounds that
|
||||||
|
*"reproducibility comes from pinning the identity of a thing rather than carrying its bytes"*
|
||||||
|
([to-be 07](../../03-DESIGN/01-to-be/07-the-foundation.md)). That reasoning is sound. It holds
|
||||||
|
only while a pinned identity stays **resolvable**, and nothing in the mesh's control guarantees
|
||||||
|
that for an image in somebody else's registry. The passage is about
|
||||||
|
the foundation bundle, and this module is not in it; but the pattern — pin the identity, fetch
|
||||||
|
the bytes on demand — is how every module gets its third-party images, so the exposure is
|
||||||
|
general even though the sentence is local.
|
||||||
2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is
|
2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is
|
||||||
archived, and no security fix will ever reach it.
|
archived, and no security fix will ever reach it.
|
||||||
3. **Nothing detects this class of failure.** The condition is invisible until a node without the
|
3. **Nothing detects this class of failure.** The condition is invisible until a node without the
|
||||||
@@ -94,8 +104,9 @@ mesh currently learns it has lost one only by trying to use it.
|
|||||||
|
|
||||||
- Should the mesh **hold** the images it depends on — mirroring third-party images into its own
|
- Should the mesh **hold** the images it depends on — mirroring third-party images into its own
|
||||||
registry at adoption, so a module's installability does not depend on an upstream's continued
|
registry at adoption, so a module's installability does not depend on an upstream's continued
|
||||||
goodwill? That is the fix that generalises, and it costs storage and a policy about what to
|
goodwill? That is the fix that generalises. It costs storage and a policy about what to mirror,
|
||||||
mirror.
|
and it is a deliberate move **away** from references-over-payload for third-party images
|
||||||
|
specifically — so it should be decided as such, not smuggled in as a fix.
|
||||||
- Should a module's images be pinned **by digest** rather than by tag? It makes the artifact
|
- Should a module's images be pinned **by digest** rather than by tag? It makes the artifact
|
||||||
exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone.
|
exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone.
|
||||||
- What **checks** that every module in the catalogue is still obtainable from a node that holds
|
- What **checks** that every module in the catalogue is still obtainable from a node that holds
|
||||||
|
|||||||
Reference in New Issue
Block a user