From 256884e671c52a14b1f7ca388d48c82cd5b065e1 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 14 Sep 2026 12:34:26 +0200 Subject: [PATCH] Installing ends with a builder, and the record says so MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The design said how the builder arrives was unsettled and that nothing installed it — the one gap stopping a fresh mesh from producing anything. Both are now false. What is still true is narrower and worth keeping separate: nothing asks a raised mesh for the rest of the catalogue, and no bed asserts that it could. --- 03-DESIGN/01-to-be/17-raising-a-mesh.md | 25 ++++++++++++++----------- 1 file changed, 14 insertions(+), 11 deletions(-) diff --git a/03-DESIGN/01-to-be/17-raising-a-mesh.md b/03-DESIGN/01-to-be/17-raising-a-mesh.md index 069f4de..847df54 100644 --- a/03-DESIGN/01-to-be/17-raising-a-mesh.md +++ b/03-DESIGN/01-to-be/17-raising-a-mesh.md @@ -104,11 +104,15 @@ names what its artifacts are and nothing has made them. So installing continues: -**The builder arrives.** It is a module like any other and is assigned to a machine like any other, -but it cannot be built by the thing it is — see +**The builder arrives, and installing is what brings it.** It is a module like any other and is +assigned to a machine like any other, but it cannot be built by the thing it is — see [`12-a-module-repository`](12-a-module-repository.md#the-three-the-loop-cannot-build-and-there-are-only-three). -**How it arrives is unsettled**, and it is the one gap that stops everything after this paragraph -from being possible on a machine nobody is sitting at. +So it is carried, and it is already here: it is what built the control plane. The last step of +installing publishes it into the mesh's own registry, installs it as an ordinary module pinned to +that digest, and issues it a broker account — the same two acts the control plane went through, +plus the one thing only a builder needs. The account is issued before the machine is sent anything, +because a builder that arrives without its credential starts, finds nothing it may read, and waits, +which looks exactly like a builder with no work. **The core modules are built.** Each is named by a repository and a path ([ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md)), and the builder is @@ -159,11 +163,10 @@ needs a toolchain and a working tree, which is most of the burden the installer **A mesh cannot say how it was raised.** Nothing afterwards can contradict a claim that a machine was brought up the supported way, so the rule that it must be is, today, unenforced. -**The builder's own module is not installed by genesis.** The installer carries a builder and uses -it, so a fresh mesh is raised on something it built; but nothing afterwards installs that builder as -an ordinary module on the machine, so the mesh cannot yet be asked to build anything else. The -paragraphs above describing the core modules being built can start now — a builder exists and has -somewhere to publish — and nothing yet starts them. +**Nothing asks for the core modules yet.** Installing ends with a builder that works — a raised +machine will build the shared base and a module on top of it when asked — and nothing asks. The +paragraphs above describing the catalogue being built are a thing somebody now types, rather than a +thing that cannot happen. **A module's declaration still has to be copied onto the machine by hand.** The installer reads the registry's and the control plane's manifests from a checkout somebody put there. The control plane's @@ -184,7 +187,7 @@ pulling problem, not a genesis one. | Every step may be run again | The installer is re-run against a raised machine and must change nothing and report why. | | An image is named exactly | A machine refuses a bundle naming an image by tag. The refusal is exercised, not assumed. | | The installer is what installed this | **Nothing.** See above. | -| The builder can arrive on a fresh mesh | The installer carries it, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. | +| The builder can arrive on a fresh mesh | The installer carries it and installs it as its last step, and the genesis bed raises a machine by running the installer. A bed that raises one any other way fails its own acceptance check. | | The control plane a mesh runs is one it built | The genesis bed asserts the running control plane is pinned to a digest this mesh's own registry serves, for an image built from a named repository and commit — not one the installer carried. | | A core module is built rather than only carried | The control plane is rebuilt from its own repository and path, and the running mesh is upgraded to the result — the same path any module takes. | -| Installing produced a mesh that can produce | After installing, a module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. | +| Installing produced a mesh that can produce | A module with source of its own is asked for and comes back pinned to a digest this mesh's registry assigned, not to a placeholder. **Done by hand on a raised machine, not yet by a bed** — it built the shared base and then a module naming that base. Nothing automated asserts it, which makes this the weakest check on this page. |