File 009: a digest-pinned image cannot be placed in the lab
Two accepted decisions collide, and testing found it rather than review. 0046 pins images by digest and has the host refuse anything unpinned. The lab places images by exporting them from the workstation, because a sealed scenario cannot reach a registry -- and that loses the digest, since a repo digest only exists for an image a registry served. Measured: the load says 'Loaded image ID:' rather than 'Loaded image:', and the image lands dangling. So a tag is refused by the host and a digest is unusable in the lab. There is currently no declaration the lab can raise that exercises the container shape, which matters because the container shape IS the substrate -- every bootstrap step past the runtime is one. The resolution is a registry inside the scenario, and that is not a workaround: 0048 already names an OCI registry as substrate and every node after the first pulls from the mesh's own. It also removes the lab's export-and-push mechanism rather than repairing it. 0046 now carries a pointer, since its own consequence is where the collision was predicted -- half of it is closed and the other half turned out to be harder than 'not solved here' suggested.
This commit is contained in:
@@ -60,6 +60,12 @@ would be the tail wagging the dog.
|
||||
- **The lab needs a way to place images**, and the machine it places them into needs a container
|
||||
runtime, which a sealed scenario cannot install either. Both are lab-installation concerns and
|
||||
neither is solved here.
|
||||
**The runtime half is now done** — the lab builds a base image on a machine with a network and
|
||||
raises sealed machines from it. **The image half turned out to collide with this record**: an
|
||||
image placed from an archive cannot keep its digest, and this record has the host refuse
|
||||
anything unpinned, so the lab can satisfy neither form. See
|
||||
[04-ISSUES/009](../04-ISSUES/009-a-digest-pinned-image-cannot-be-placed-in-the-lab/00-report.md);
|
||||
the resolution is a registry inside the scenario, which is what a real node pulls from anyway.
|
||||
- **The build-time-versus-apply-time reframing in
|
||||
[research 012](../01-RESEARCH/012-the-minimum-viable-node/00-overview.md) narrows.** It still
|
||||
holds for what a *tailored installer* contains — the missing pieces for a given machine — but
|
||||
|
||||
Reference in New Issue
Block a user