ADR 0076: the SDK is a published package the toolchain resolves by version

Records the decision the package-registry work turns on — the SDK is built on a
public base and published before the toolchain that consumes it, so nothing is
circular; mesh-tools stays the thin toolchain base but resolves the SDK by
version. Reconciles docs 12/17/22 and indexes the record.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 10:28:08 +02:00
parent 17c2e061df
commit b43b60b183
5 changed files with 118 additions and 0 deletions
@@ -408,6 +408,15 @@ being a builder rather than a result.
Everything outside those four is either upstream — a third-party image pulled by digest — or built
by the builder from a repository and a path, and published to the registry.
**One of those built things has an ordering constraint worth naming, because it looks like a fifth
member of the list and is not.** The SDK the toolchain compiles against is built by the ordinary
builder and published like anything else — but it cannot be compiled *in the mesh toolchain*, since
that toolchain is built from it, and it is published to the *package* registry rather than the
artifact store. So it is compiled on a public base image and published before the toolchain that
consumes it ([ADR 0076](../../02-DECISIONS/0076-the-sdk-is-a-published-package.md)). It is not
carried and it is not machinery; it is a dependency with a sequence, which is why it belongs here as
a footnote to the rule rather than a row in the table.
**A carried artifact is not a differently-pinned artifact.** Once published it is named by a digest
the mesh's registry assigned, exactly like everything the builder produces. A reader cannot tell
from a running mesh which of its images were carried, and that is the point: carrying is how the