Issue 113 and research 015: the object store's images are gone upstream, not access-restricted #103
@@ -75,9 +75,19 @@ necessary.
|
||||
The instance is harmless; the standing condition is not.
|
||||
|
||||
1. **No new node can ever provision this module.** Every node that does not already hold the
|
||||
images is permanently unable to obtain them. The mesh's claim that a node can be rebuilt from
|
||||
its declarations is false for this module, and will be false the same way for any module whose
|
||||
images is permanently unable to obtain them, and the same will be true of any module whose
|
||||
upstream withdraws an image.
|
||||
|
||||
This is the failure mode of a deliberate design choice, which is why it is worth recording
|
||||
rather than patching. The foundation design chooses **references over payload** — *"the bundle
|
||||
names images by digest and the host fetches them"* — on the stated grounds that
|
||||
*"reproducibility comes from pinning the identity of a thing rather than carrying its bytes"*
|
||||
([to-be 07](../../03-DESIGN/01-to-be/07-the-foundation.md)). That reasoning is sound. It holds
|
||||
only while a pinned identity stays **resolvable**, and nothing in the mesh's control guarantees
|
||||
that for an image in somebody else's registry. The passage is about
|
||||
the foundation bundle, and this module is not in it; but the pattern — pin the identity, fetch
|
||||
the bytes on demand — is how every module gets its third-party images, so the exposure is
|
||||
general even though the sentence is local.
|
||||
2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is
|
||||
archived, and no security fix will ever reach it.
|
||||
3. **Nothing detects this class of failure.** The condition is invisible until a node without the
|
||||
@@ -94,8 +104,9 @@ mesh currently learns it has lost one only by trying to use it.
|
||||
|
||||
- Should the mesh **hold** the images it depends on — mirroring third-party images into its own
|
||||
registry at adoption, so a module's installability does not depend on an upstream's continued
|
||||
goodwill? That is the fix that generalises, and it costs storage and a policy about what to
|
||||
mirror.
|
||||
goodwill? That is the fix that generalises. It costs storage and a policy about what to mirror,
|
||||
and it is a deliberate move **away** from references-over-payload for third-party images
|
||||
specifically — so it should be decided as such, not smuggled in as a fix.
|
||||
- Should a module's images be pinned **by digest** rather than by tag? It makes the artifact
|
||||
exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone.
|
||||
- What **checks** that every module in the catalogue is still obtainable from a node that holds
|
||||
|
||||
Reference in New Issue
Block a user