ADR 0097: a vendor image is a declared build input; issue 064's image half decided; design 18 amended

This commit is contained in:
2026-09-21 20:45:36 +02:00
parent 8d981e21b1
commit 71072e240d
4 changed files with 74 additions and 2 deletions
@@ -7,6 +7,7 @@ code:
- mesh-catalog modules/builder
updated: 2026-09-21
decisions:
- 02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md
- 02-DECISIONS/0096-an-upstream-image-is-copied-between-registries.md
- 02-DECISIONS/0091-a-mount-is-declared-three-ways.md
- 02-DECISIONS/0087-a-seeded-file-is-created-once.md
@@ -215,6 +216,14 @@ test copies an index over two platforms from a fake registry behind a bearer cha
mesh registry and asserts every blob arrived once, the manifests and index under their digests,
and nothing uploaded on a second copy.
**A vendor image is a declared build input**
([ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md)). A build's `on`
entry is a module's artifact or an image published elsewhere, pinned by digest, read from one
build argument; the image is copied into the mesh's registry before the build and the recipe is
handed the copy. A recipe whose `FROM` or `COPY --from` names a registry image the manifest did not
declare is refused before the build, naming it and the remedy. *How it is checked:* builder tests
on a declared and an unpinned vendor image, and a recipe test on what counts as a fetch.
### What it puts on a machine
| resource | is | a module may |