Record what genesis now does, and how each rule is checked
The builder's arrival was the one rule the document said nothing checked. It is checked now, by both genesis beds — and so is the thing that distinguishes a built control plane from a carried one, which every earlier assertion accepted either way.
This commit is contained in:
@@ -159,9 +159,16 @@ needs a toolchain and a working tree, which is most of the burden the installer
|
||||
**A mesh cannot say how it was raised.** Nothing afterwards can contradict a claim that a machine
|
||||
was brought up the supported way, so the rule that it must be is, today, unenforced.
|
||||
|
||||
**The init builder is not built.** Until it is, the installer carries the control plane's image and
|
||||
nothing gives a fresh mesh a builder or a catalogue, so the paragraphs above describing the core
|
||||
modules being built describe something that cannot yet start.
|
||||
**The builder's own module is not installed by genesis.** The installer carries a builder and uses
|
||||
it, so a fresh mesh is raised on something it built; but nothing afterwards installs that builder as
|
||||
an ordinary module on the machine, so the mesh cannot yet be asked to build anything else. The
|
||||
paragraphs above describing the core modules being built can start now — a builder exists and has
|
||||
somewhere to publish — and nothing yet starts them.
|
||||
|
||||
**A module's declaration still has to be copied onto the machine by hand.** The installer reads the
|
||||
registry's and the control plane's manifests from a checkout somebody put there. The control plane's
|
||||
now lives in the control plane's own repository, which the installer clones anyway, so this is a
|
||||
thing that can be removed rather than a thing that must be designed.
|
||||
|
||||
**A machine has no account for a registry that asks for one.** The mesh grants a consumer a
|
||||
credential for a database; it does not yet do so for the store its own images live in. Genesis
|
||||
@@ -177,6 +184,7 @@ pulling problem, not a genesis one.
|
||||
| Every step may be run again | The installer is re-run against a raised machine and must change nothing and report why. |
|
||||
| An image is named exactly | A machine refuses a bundle naming an image by tag. The refusal is exercised, not assumed. |
|
||||
| The installer is what installed this | **Nothing.** See above. |
|
||||
| The builder can arrive on a fresh mesh | **Nothing.** There is no route for it yet. |
|
||||
| The builder can arrive on a fresh mesh | The installer carries it, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. |
|
||||
| The control plane a mesh runs is one it built | The genesis bed asserts the running control plane is pinned to a digest this mesh's own registry serves, for an image built from a named repository and commit — not one the installer carried. |
|
||||
| A core module is built rather than only carried | The control plane is rebuilt from its own repository and path, and the running mesh is upgraded to the result — the same path any module takes. |
|
||||
| Installing produced a mesh that can produce | After installing, a module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. |
|
||||
|
||||
Reference in New Issue
Block a user