Issue 046 — an upstream image cannot be mirrored into the mesh's registry #40

Merged
jschoubben merged 1 commits from issue/mirroring-an-upstream-image into main 2026-09-14 11:28:00 +00:00
Owner

Found while migrating the first module.

A module may declare that an artifact is an image published elsewhere, to be copied into the mesh's own registry so machines fetch it by a digest this mesh assigned rather than by a name somebody else controls. That path fails, and nothing reaches the registry.

Five things were tried and observed rather than assumed: fetching the image leaves a multi-architecture index in the runtime's store; asking for a platform at fetch time does not change that; resolving the index and fetching the one manifest for this architecture by its own digest does not change it either; naming the platform at push time only changes the message; and the tooling that copies between registries without any of this is not installed.

A fix along those lines was written, tested, and reverted. It did not make the mirror work, and leaving index-resolving machinery that does not achieve what it was added for would have been complexity plus a comment claiming something untrue.

One module uses this today, so nothing that was working is broken — and that is also why it went unnoticed. It matters because it is the shape most of a migration wants: the services being moved are overwhelmingly third-party images, and mirroring is the only thing that makes one the mesh's own rather than a name on the internet that every machine re-fetches independently for ever.

Found while migrating the first module. A module may declare that an artifact is an image published elsewhere, to be copied into the mesh's own registry so machines fetch it by a digest this mesh assigned rather than by a name somebody else controls. That path fails, and nothing reaches the registry. Five things were tried and observed rather than assumed: fetching the image leaves a multi-architecture index in the runtime's store; asking for a platform at fetch time does not change that; resolving the index and fetching the one manifest for this architecture by its own digest does not change it either; naming the platform at push time only changes the message; and the tooling that copies between registries without any of this is not installed. A fix along those lines was written, tested, and reverted. It did not make the mirror work, and leaving index-resolving machinery that does not achieve what it was added for would have been complexity plus a comment claiming something untrue. One module uses this today, so nothing that was working is broken — and that is also why it went unnoticed. It matters because it is the shape most of a migration wants: the services being moved are overwhelmingly third-party images, and mirroring is the only thing that makes one the mesh's own rather than a name on the internet that every machine re-fetches independently for ever.
jschoubben added 1 commit 2026-09-14 11:27:54 +00:00
Found while migrating the first module. Five approaches were tried and observed
to fail, including resolving the index and naming the platform at both ends; a
speculative fix was written and reverted rather than shipped, because it did not
make the mirror work.

One module uses this today, which is why it went unnoticed — and it is the shape
most of a migration wants, because the services being moved are third-party.
jschoubben merged commit 9359542990 into main 2026-09-14 11:28:00 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#40