ADR 0076: the SDK is a published package the toolchain resolves by version

Records the decision the package-registry work turns on — the SDK is built on a
public base and published before the toolchain that consumes it, so nothing is
circular; mesh-tools stays the thin toolchain base but resolves the SDK by
version. Reconciles docs 12/17/22 and indexes the record.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 10:28:08 +02:00
parent 17c2e061df
commit b43b60b183
5 changed files with 118 additions and 0 deletions
+10
View File
@@ -178,6 +178,16 @@ credential for a database; it does not yet do so for the store its own images li
avoids the question by carrying the image it needs, which makes this a joining problem and a
pulling problem, not a genesis one.
**The SDK still comes from a git URL, and the ordering that fixes it is decided but not built.**
[ADR 0076](../../02-DECISIONS/0076-the-sdk-is-a-published-package.md) settles that the package
registry (gitea) comes up and the SDK is published into it *before* the base toolchain is built, so
the toolchain resolves the SDK by version rather than cloning it — closing
[issue 053](../../04-ISSUES/053-the-sdk-is-pinned-twice-and-the-two-disagree/00-report.md). The
builder already knows how to be handed a package-registry credential and inject it into a build; what
is not yet wired is the genesis step that raises gitea and publishes the SDK ahead of the base, and
the toolchain's own manifest still names the SDK by a git URL. Until both land, the base build clones
the SDK inside `docker build`, which is slow and names a branch head rather than a version.
## How these rules are checked
| Rule | Checked by |