Issue 092: genesis publishes to a registry the container runtime does not yet trust #79

Merged
jschoubben merged 2 commits from issue/092-genesis-registry-trust into main 2026-09-23 23:38:47 +00:00
Owner

Found on the first real genesis, on a machine in use, and then twice more within the hour on the same machine.

Genesis pushes the control plane's image into the registry it just raised, six steps before the module that tells the container runtime to trust that registry. The mesh's registry speaks plain HTTP by design, so the push fails. The lab cannot see this: its base image writes that trust before any bed starts.

The two repeats are the interesting part. The builder pushes to the registry by its mesh name, which the runtime had no reason to trust either, so arranging the numeric address is not enough. And the trust the mesh writes itself names the registry's default port while the node was given another — an address with a port that does not follow the node's setting, the same fault as issue 088.

Worked around by hand on the machine each time, the way the mesh itself writes such a file: every existing key kept, and the runtime reloaded rather than restarted, so nothing it was running stopped.

Found on the first real genesis, on a machine in use, and then twice more within the hour on the same machine. Genesis pushes the control plane's image into the registry it just raised, six steps before the module that tells the container runtime to trust that registry. The mesh's registry speaks plain HTTP by design, so the push fails. The lab cannot see this: its base image writes that trust before any bed starts. The two repeats are the interesting part. The builder pushes to the registry by its **mesh name**, which the runtime had no reason to trust either, so arranging the numeric address is not enough. And the trust the mesh writes itself names the registry's **default** port while the node was given another — an address with a port that does not follow the node's setting, the same fault as issue 088. Worked around by hand on the machine each time, the way the mesh itself writes such a file: every existing key kept, and the runtime reloaded rather than restarted, so nothing it was running stopped.
jschoubben added 2 commits 2026-09-22 21:37:15 +00:00
jschoubben merged commit 7f438d049f into main 2026-09-23 23:38:47 +00:00
jschoubben deleted branch issue/092-genesis-registry-trust 2026-09-23 23:38:47 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#79