From da6414c27cd03e5587d55bc8442cba4a1d3ed48c Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 15:18:32 +0200 Subject: [PATCH] Issue 072 diagnosed: genesis registers the manifest its build produced; design 17 says so ADR 0069 had already placed the controller's manifest in its own repository, and the raising design called the catalogue copy a thing to remove. The installer's step 3 was handed that manifest by the build and step 9 read a second copy anyway. --- 03-DESIGN/01-to-be/17-raising-a-mesh.md | 13 +++++--- .../00-report.md | 4 +-- .../01-diagnosis.md | 31 +++++++++++++++++++ 3 files changed, 42 insertions(+), 6 deletions(-) create mode 100644 04-ISSUES/072-the-controllers-manifest-exists-twice/01-diagnosis.md diff --git a/03-DESIGN/01-to-be/17-raising-a-mesh.md b/03-DESIGN/01-to-be/17-raising-a-mesh.md index 9d8f118..7ded49a 100644 --- a/03-DESIGN/01-to-be/17-raising-a-mesh.md +++ b/03-DESIGN/01-to-be/17-raising-a-mesh.md @@ -5,9 +5,10 @@ code: - mesh-host cmd/mesh-bootstrap - mesh-host internal/bootstrap - mesh-lab test/integration/whole-mesh-full.test.ts -updated: 2026-09-12 +updated: 2026-09-21 decisions: - 02-DECISIONS/0067-genesis-is-a-pivot.md + - 02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md - 02-DECISIONS/0006-the-substrate-and-the-control-plane.md - 02-DECISIONS/0005-the-node-host.md - 02-DECISIONS/0010-delivery.md @@ -170,9 +171,13 @@ paragraphs above describing the catalogue being built are a thing somebody now t thing that cannot happen. **A module's declaration still has to be copied onto the machine by hand.** The installer reads the -registry's and the controller's manifests from a checkout somebody put there. The controller's -now lives in the controller's own repository, which the installer clones anyway, so this is a -thing that can be removed rather than a thing that must be designed. +registry's and the builder's manifests from a checkout somebody put there. The controller's is no +longer among them: it lives in the controller's own repository +([ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md)), the build the +installer runs reports it with the artifact resolved, and genesis registers that +([issue 072](../../04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md)). The +builder's manifest belongs in the same repository and is still read from the catalogue; that is +the last of this. **A machine has no account for a registry that asks for one.** The mesh grants a consumer a credential for a database; it does not yet do so for the store its own images live in. Genesis diff --git a/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md b/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md index da50482..cb998cf 100644 --- a/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md +++ b/04-ISSUES/072-the-controllers-manifest-exists-twice/00-report.md @@ -1,9 +1,9 @@ --- status: located opened: 2026-09-21 -located-in: [mesh-controller module.json, mesh-catalog modules/mesh-controller/module.json, mesh-host internal/bootstrap] +located-in: [mesh-host internal/bootstrap, mesh-catalog modules/mesh-controller/module.json] fixed-by: -amended-design: +amended-design: 03-DESIGN/01-to-be/17-raising-a-mesh.md --- # The controller's manifest exists twice, and nothing keeps the copies equal diff --git a/04-ISSUES/072-the-controllers-manifest-exists-twice/01-diagnosis.md b/04-ISSUES/072-the-controllers-manifest-exists-twice/01-diagnosis.md new file mode 100644 index 0000000..0cc7d10 --- /dev/null +++ b/04-ISSUES/072-the-controllers-manifest-exists-twice/01-diagnosis.md @@ -0,0 +1,31 @@ +# Diagnosis — 2026-09-21 + +1. The two documents were compared. They differ in exactly one place: the repository's names its + server container by a build artifact and carries the build section that produces it; the + catalogue's names a placeholder image digest and carries no build section. Everything else was + equal on the day of reading, which is the only day that can be said of. +2. Who reads which. The mesh's own builder reads the repository's, whenever the control plane is + rebuilt from source, and registers the manifest it built with the artifact resolved to the + image — that is what replaced the mesh's record. The installer's step 9 read the catalogue's, + pinned its placeholder to the image the registry assigned, and registered that. Nothing else + read the catalogue's copy. +3. The decision was already taken. [ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md) + says the control plane's manifest belongs in its own repository, not the catalogue, and the + raising design names the catalogue copy as "a thing that can be removed rather than a thing + that must be designed". It was not removed because step 9 had no other source — at genesis the + installer carries the builder, not the control plane, and reads manifests off a checkout put on + the machine by hand. +4. But step 3 already had it. The installer builds the control plane from its repository and a + commit, and the builder's one-shot result carries the manifest it built — the repository's, its + artifact resolved to the image the machine now holds. Step 9 was reading a second copy of a + document it had been handed six steps earlier. + +**Located in:** mesh-host `internal/bootstrap` (steps 3 and 9), and the catalogue's copy. The fix +keeps the built manifest from step 3, registers it at step 9 with the built image's bare id +re-pinned to the registry's reference, and deletes the catalogue's copy. The builder module's +manifest is still the catalogue's and still pinned from a placeholder — ADR 0069 puts it in the +control plane's repository too, and it is not there yet; that is a smaller instance of the same +gap, left open here and named in the lab's genesis check. Ruled out: teaching the two copies to +stay equal (a check across two repositories that only fires after somebody edits one), and reading +the manifest out of the built image (a change to the control plane's image for a document the +build already reports).