Genesis carries a builder, and the document says so

The section saying the change was decided and had not happened now contradicted
the section below it. It also records the argument that failed, because a reader
will otherwise ask the same question and reach the same wrong answer.
This commit is contained in:
2026-09-13 04:26:01 +02:00
parent aabaaf2bb4
commit fdc61054e3
+28 -18
View File
@@ -36,34 +36,44 @@ Confusing the two is what produced a procedure that only ever worked in a fixtur
raises four machines the same way has not tested genesis at all — it has tested joining, four
times, with the first one hand-fed.
## Genesis is decided to change, and has not yet
## What changed, and what did not
*2026-09-12.* [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) settles
that the installer carries an **init builder** rather than the control plane's image, and that the
core modules — control plane, catalogue, builder — are **built on the machine** before a mesh exists
to install anything. One thing is carried, and it is a builder rather than a result, which is what
gives the builder and the catalogue a route they did not have.
*2026-09-13.* The installer carries a builder now, and builds the control plane it raises. Three
records settle it: [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) that
genesis builds rather than carries, [ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md)
where it clones from, and [ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md) how
the builder arrives — which also records an argument that failed. It was put that a produced image
must be published before anything can fetch it, so the registry would have to come up before the
control plane. It does not: the machine that builds the image is the machine that runs it, and a
local image is named by the digest of its own configuration exactly as a carried one is. **Building
changes where the bytes came from, not where they are.**
**The section below describes what the installer does today**, which is to carry the control plane's
image and publish it once there is a registry. It is kept as written because it is true of the
program that exists, and replacing it with the intention would leave nothing describing the thing
anybody actually runs. The order changes when the init builder is built; the pivot does not.
So the pivot is unchanged, the registry is where it was, and one step was added before the bundle is
written. What follows describes the program that exists.
## Genesis
The installer is a single program carrying the control plane's image inside it. That is what makes
genesis possible without a network to fetch from and without a registry to name: the image is
present because the installer is present.
The installer is a single program carrying **the builder** inside it — not the control plane
([ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md)). What cannot be fetched is
the thing that does the fetching, so that is what is carried; everything else is made here.
It proceeds in one direction, and every step is safe to run again.
**First it refuses to start if the machine is not ready.** A container runtime, the ability to
write where it must write, the host binary where it expects it. A machine that is not ready is told
what is missing rather than half-changed.
write where it must write, the host binary where it expects it — and a repository and a commit to
build from, because an installer told nothing would raise a store and a broker and then have
nothing to raise a control plane from. A machine that is not ready is told what is missing rather
than half-changed.
**Then it loads the carried image and describes what the machine will become.** The image is named
by the digest of its own configuration — content-addressed and unforgeable, and requiring nothing
to have served it. This is legal precisely where nothing could have served one, and nowhere else.
**Then it loads the carried builder and builds the control plane with it**, from a repository on a
mesh that already exists and a named commit ([ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md)).
This is the same repository and path every later rebuild of the control plane will use, so what
raises the mesh is the same thing that will maintain it.
**Then it describes what the machine will become.** The image it just made is named by the digest
of its own configuration — content-addressed and unforgeable, and requiring nothing to have served
it. That is legal precisely where nothing could have served one, and it is why building here needs
no registry: the machine that made the image is the machine that will run it.
**Then it raises the substrate and a temporary control plane, and waits for that control plane to
answer.** At this point the machine is a mesh of one node with nothing joined to it.