Genesis carries a builder, and the document says so
The section saying the change was decided and had not happened now contradicted the section below it. It also records the argument that failed, because a reader will otherwise ask the same question and reach the same wrong answer.
This commit is contained in:
@@ -36,34 +36,44 @@ Confusing the two is what produced a procedure that only ever worked in a fixtur
|
||||
raises four machines the same way has not tested genesis at all — it has tested joining, four
|
||||
times, with the first one hand-fed.
|
||||
|
||||
## Genesis is decided to change, and has not yet
|
||||
## What changed, and what did not
|
||||
|
||||
*2026-09-12.* [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) settles
|
||||
that the installer carries an **init builder** rather than the control plane's image, and that the
|
||||
core modules — control plane, catalogue, builder — are **built on the machine** before a mesh exists
|
||||
to install anything. One thing is carried, and it is a builder rather than a result, which is what
|
||||
gives the builder and the catalogue a route they did not have.
|
||||
*2026-09-13.* The installer carries a builder now, and builds the control plane it raises. Three
|
||||
records settle it: [ADR 0070](../../02-DECISIONS/0070-the-catalogue-owns-the-module-graph.md) that
|
||||
genesis builds rather than carries, [ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md)
|
||||
where it clones from, and [ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md) how
|
||||
the builder arrives — which also records an argument that failed. It was put that a produced image
|
||||
must be published before anything can fetch it, so the registry would have to come up before the
|
||||
control plane. It does not: the machine that builds the image is the machine that runs it, and a
|
||||
local image is named by the digest of its own configuration exactly as a carried one is. **Building
|
||||
changes where the bytes came from, not where they are.**
|
||||
|
||||
**The section below describes what the installer does today**, which is to carry the control plane's
|
||||
image and publish it once there is a registry. It is kept as written because it is true of the
|
||||
program that exists, and replacing it with the intention would leave nothing describing the thing
|
||||
anybody actually runs. The order changes when the init builder is built; the pivot does not.
|
||||
So the pivot is unchanged, the registry is where it was, and one step was added before the bundle is
|
||||
written. What follows describes the program that exists.
|
||||
|
||||
## Genesis
|
||||
|
||||
The installer is a single program carrying the control plane's image inside it. That is what makes
|
||||
genesis possible without a network to fetch from and without a registry to name: the image is
|
||||
present because the installer is present.
|
||||
The installer is a single program carrying **the builder** inside it — not the control plane
|
||||
([ADR 0073](../../02-DECISIONS/0073-the-installer-carries-a-builder.md)). What cannot be fetched is
|
||||
the thing that does the fetching, so that is what is carried; everything else is made here.
|
||||
|
||||
It proceeds in one direction, and every step is safe to run again.
|
||||
|
||||
**First it refuses to start if the machine is not ready.** A container runtime, the ability to
|
||||
write where it must write, the host binary where it expects it. A machine that is not ready is told
|
||||
what is missing rather than half-changed.
|
||||
write where it must write, the host binary where it expects it — and a repository and a commit to
|
||||
build from, because an installer told nothing would raise a store and a broker and then have
|
||||
nothing to raise a control plane from. A machine that is not ready is told what is missing rather
|
||||
than half-changed.
|
||||
|
||||
**Then it loads the carried image and describes what the machine will become.** The image is named
|
||||
by the digest of its own configuration — content-addressed and unforgeable, and requiring nothing
|
||||
to have served it. This is legal precisely where nothing could have served one, and nowhere else.
|
||||
**Then it loads the carried builder and builds the control plane with it**, from a repository on a
|
||||
mesh that already exists and a named commit ([ADR 0071](../../02-DECISIONS/0071-where-genesis-gets-its-source.md)).
|
||||
This is the same repository and path every later rebuild of the control plane will use, so what
|
||||
raises the mesh is the same thing that will maintain it.
|
||||
|
||||
**Then it describes what the machine will become.** The image it just made is named by the digest
|
||||
of its own configuration — content-addressed and unforgeable, and requiring nothing to have served
|
||||
it. That is legal precisely where nothing could have served one, and it is why building here needs
|
||||
no registry: the machine that made the image is the machine that will run it.
|
||||
|
||||
**Then it raises the substrate and a temporary control plane, and waits for that control plane to
|
||||
answer.** At this point the machine is a mesh of one node with nothing joined to it.
|
||||
|
||||
Reference in New Issue
Block a user