A module may declare that an artifact is an image published elsewhere, to be copied into the mesh's own registry so machines fetch it by a digest this mesh assigned rather than by a name somebody else controls. That path fails, and nothing reaches the registry.
Five things were tried and observed rather than assumed: fetching the image leaves a multi-architecture index in the runtime's store; asking for a platform at fetch time does not change that; resolving the index and fetching the one manifest for this architecture by its own digest does not change it either; naming the platform at push time only changes the message; and the tooling that copies between registries without any of this is not installed.
A fix along those lines was written, tested, and reverted. It did not make the mirror work, and leaving index-resolving machinery that does not achieve what it was added for would have been complexity plus a comment claiming something untrue.
One module uses this today, so nothing that was working is broken — and that is also why it went unnoticed. It matters because it is the shape most of a migration wants: the services being moved are overwhelmingly third-party images, and mirroring is the only thing that makes one the mesh's own rather than a name on the internet that every machine re-fetches independently for ever.
Found while migrating the first module.
A module may declare that an artifact is an image published elsewhere, to be copied into the mesh's own registry so machines fetch it by a digest this mesh assigned rather than by a name somebody else controls. That path fails, and nothing reaches the registry.
Five things were tried and observed rather than assumed: fetching the image leaves a multi-architecture index in the runtime's store; asking for a platform at fetch time does not change that; resolving the index and fetching the one manifest for this architecture by its own digest does not change it either; naming the platform at push time only changes the message; and the tooling that copies between registries without any of this is not installed.
A fix along those lines was written, tested, and reverted. It did not make the mirror work, and leaving index-resolving machinery that does not achieve what it was added for would have been complexity plus a comment claiming something untrue.
One module uses this today, so nothing that was working is broken — and that is also why it went unnoticed. It matters because it is the shape most of a migration wants: the services being moved are overwhelmingly third-party images, and mirroring is the only thing that makes one the mesh's own rather than a name on the internet that every machine re-fetches independently for ever.
Found while migrating the first module. Five approaches were tried and observed
to fail, including resolving the index and naming the platform at both ends; a
speculative fix was written and reverted rather than shipped, because it did not
make the mirror work.
One module uses this today, which is why it went unnoticed — and it is the shape
most of a migration wants, because the services being moved are third-party.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while migrating the first module.
A module may declare that an artifact is an image published elsewhere, to be copied into the mesh's own registry so machines fetch it by a digest this mesh assigned rather than by a name somebody else controls. That path fails, and nothing reaches the registry.
Five things were tried and observed rather than assumed: fetching the image leaves a multi-architecture index in the runtime's store; asking for a platform at fetch time does not change that; resolving the index and fetching the one manifest for this architecture by its own digest does not change it either; naming the platform at push time only changes the message; and the tooling that copies between registries without any of this is not installed.
A fix along those lines was written, tested, and reverted. It did not make the mirror work, and leaving index-resolving machinery that does not achieve what it was added for would have been complexity plus a comment claiming something untrue.
One module uses this today, so nothing that was working is broken — and that is also why it went unnoticed. It matters because it is the shape most of a migration wants: the services being moved are overwhelmingly third-party images, and mirroring is the only thing that makes one the mesh's own rather than a name on the internet that every machine re-fetches independently for ever.