ADR 0076: the SDK is a published package the toolchain resolves by version
Records the decision the package-registry work turns on — the SDK is built on a public base and published before the toolchain that consumes it, so nothing is circular; mesh-tools stays the thin toolchain base but resolves the SDK by version. Reconciles docs 12/17/22 and indexes the record. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -63,6 +63,17 @@ registry. Nothing installs one, so the SDK comes from a git URL (issue 053). Nee
|
||||
**Done when.** A module builds against the SDK resolved from the mesh's own registry, and issue 053
|
||||
closes.
|
||||
|
||||
**Where it stands (2026-09-16).** The decision the bootstrap turned on is settled and recorded
|
||||
([ADR 0076](../../02-DECISIONS/0076-the-sdk-is-a-published-package.md)): the SDK is a published
|
||||
package, built on a public base image and published before the toolchain that consumes it; mesh-tools
|
||||
stays the thin toolchain base but `npm ci`s the SDK by version. On the code, the builder now resolves
|
||||
a package-registry credential — from a binding the mesh writes or from the environment for a hand-run
|
||||
or bootstrap build — and injects it into an image build as a buildkit secret, never a layer, so a
|
||||
token is not baked into the toolchain image. Unit-tested. Still ahead: gitea serving the registry in
|
||||
full with a provisioner that mints tokens (2.1), the SDK built and published by the mesh (2.2), the
|
||||
mesh-tools manifest flipped off the git URL to `npm ci` by version (2.3), and the genesis step that
|
||||
raises gitea and publishes the SDK before the base build. Those close together in one lab run.
|
||||
|
||||
## Phase 3 — nothing is special after installation
|
||||
|
||||
**Why last.** The hardest and riskiest, and it needs everything above: an installer that completes,
|
||||
|
||||
Reference in New Issue
Block a user