From fdc61054e38be811e3c71492444637e041219b3f Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 04:26:01 +0200 Subject: [PATCH] Genesis carries a builder, and the document says so The section saying the change was decided and had not happened now contradicted the section below it. It also records the argument that failed, because a reader will otherwise ask the same question and reach the same wrong answer. --- 03-DESIGN/01-to-be/17-raising-a-mesh.md | 46 +++++++++++++++---------- 1 file changed, 28 insertions(+), 18 deletions(-) diff --git a/03-DESIGN/01-to-be/17-raising-a-mesh.md b/03-DESIGN/01-to-be/17-raising-a-mesh.md index c3d3680..a6b579c 100644 --- a/03-DESIGN/01-to-be/17-raising-a-mesh.md +++ b/03-DESIGN/01-to-be/17-raising-a-mesh.md @@ -36,34 +36,44 @@ Confusing the two is what produced a procedure that only ever worked in a fixtur raises four machines the same way has not tested genesis at all — it has tested joining, four times, with the first one hand-fed. -## Genesis is decided to change, and has not yet +## What changed, and what did not -*2026-09-12.* [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) settles -that the installer carries an **init builder** rather than the control plane's image, and that the -core modules — control plane, catalogue, builder — are **built on the machine** before a mesh exists -to install anything. One thing is carried, and it is a builder rather than a result, which is what -gives the builder and the catalogue a route they did not have. +*2026-09-13.* The installer carries a builder now, and builds the control plane it raises. Three +records settle it: [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) that +genesis builds rather than carries, [ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md) +where it clones from, and [ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md) how +the builder arrives — which also records an argument that failed. It was put that a produced image +must be published before anything can fetch it, so the registry would have to come up before the +control plane. It does not: the machine that builds the image is the machine that runs it, and a +local image is named by the digest of its own configuration exactly as a carried one is. **Building +changes where the bytes came from, not where they are.** -**The section below describes what the installer does today**, which is to carry the control plane's -image and publish it once there is a registry. It is kept as written because it is true of the -program that exists, and replacing it with the intention would leave nothing describing the thing -anybody actually runs. The order changes when the init builder is built; the pivot does not. +So the pivot is unchanged, the registry is where it was, and one step was added before the bundle is +written. What follows describes the program that exists. ## Genesis -The installer is a single program carrying the control plane's image inside it. That is what makes -genesis possible without a network to fetch from and without a registry to name: the image is -present because the installer is present. +The installer is a single program carrying **the builder** inside it — not the control plane +([ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md)). What cannot be fetched is +the thing that does the fetching, so that is what is carried; everything else is made here. It proceeds in one direction, and every step is safe to run again. **First it refuses to start if the machine is not ready.** A container runtime, the ability to -write where it must write, the host binary where it expects it. A machine that is not ready is told -what is missing rather than half-changed. +write where it must write, the host binary where it expects it — and a repository and a commit to +build from, because an installer told nothing would raise a store and a broker and then have +nothing to raise a control plane from. A machine that is not ready is told what is missing rather +than half-changed. -**Then it loads the carried image and describes what the machine will become.** The image is named -by the digest of its own configuration — content-addressed and unforgeable, and requiring nothing -to have served it. This is legal precisely where nothing could have served one, and nowhere else. +**Then it loads the carried builder and builds the control plane with it**, from a repository on a +mesh that already exists and a named commit ([ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md)). +This is the same repository and path every later rebuild of the control plane will use, so what +raises the mesh is the same thing that will maintain it. + +**Then it describes what the machine will become.** The image it just made is named by the digest +of its own configuration — content-addressed and unforgeable, and requiring nothing to have served +it. That is legal precisely where nothing could have served one, and it is why building here needs +no registry: the machine that made the image is the machine that will run it. **Then it raises the substrate and a temporary control plane, and waits for that control plane to answer.** At this point the machine is a mesh of one node with nothing joined to it.