From 8e7fac8bf161d05e50420047986bcfb8142f5ff7 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 06:09:31 +0200 Subject: [PATCH] Record what genesis now does, and how each rule is checked MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The builder's arrival was the one rule the document said nothing checked. It is checked now, by both genesis beds — and so is the thing that distinguishes a built control plane from a carried one, which every earlier assertion accepted either way. --- 03-DESIGN/01-to-be/17-raising-a-mesh.md | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/03-DESIGN/01-to-be/17-raising-a-mesh.md b/03-DESIGN/01-to-be/17-raising-a-mesh.md index a6b579c..069f4de 100644 --- a/03-DESIGN/01-to-be/17-raising-a-mesh.md +++ b/03-DESIGN/01-to-be/17-raising-a-mesh.md @@ -159,9 +159,16 @@ needs a toolchain and a working tree, which is most of the burden the installer **A mesh cannot say how it was raised.** Nothing afterwards can contradict a claim that a machine was brought up the supported way, so the rule that it must be is, today, unenforced. -**The init builder is not built.** Until it is, the installer carries the control plane's image and -nothing gives a fresh mesh a builder or a catalogue, so the paragraphs above describing the core -modules being built describe something that cannot yet start. +**The builder's own module is not installed by genesis.** The installer carries a builder and uses +it, so a fresh mesh is raised on something it built; but nothing afterwards installs that builder as +an ordinary module on the machine, so the mesh cannot yet be asked to build anything else. The +paragraphs above describing the core modules being built can start now — a builder exists and has +somewhere to publish — and nothing yet starts them. + +**A module's declaration still has to be copied onto the machine by hand.** The installer reads the +registry's and the control plane's manifests from a checkout somebody put there. The control plane's +now lives in the control plane's own repository, which the installer clones anyway, so this is a +thing that can be removed rather than a thing that must be designed. **A machine has no account for a registry that asks for one.** The mesh grants a consumer a credential for a database; it does not yet do so for the store its own images live in. Genesis @@ -177,6 +184,7 @@ pulling problem, not a genesis one. | Every step may be run again | The installer is re-run against a raised machine and must change nothing and report why. | | An image is named exactly | A machine refuses a bundle naming an image by tag. The refusal is exercised, not assumed. | | The installer is what installed this | **Nothing.** See above. | -| The builder can arrive on a fresh mesh | **Nothing.** There is no route for it yet. | +| The builder can arrive on a fresh mesh | The installer carries it, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. | +| The control plane a mesh runs is one it built | The genesis bed asserts the running control plane is pinned to a digest this mesh's own registry serves, for an image built from a named repository and commit — not one the installer carried. | | A core module is built rather than only carried | The control plane is rebuilt from its own repository and path, and the running mesh is upgraded to the result — the same path any module takes. | | Installing produced a mesh that can produce | After installing, a module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. |