ADR 0069 had already placed the controller's manifest in its own repository, and the raising design called the catalogue copy a thing to remove. The installer's step 3 was handed that manifest by the build and step 9 read a second copy anyway.
2.4 KiB
Diagnosis — 2026-09-21
- The two documents were compared. They differ in exactly one place: the repository's names its server container by a build artifact and carries the build section that produces it; the catalogue's names a placeholder image digest and carries no build section. Everything else was equal on the day of reading, which is the only day that can be said of.
- Who reads which. The mesh's own builder reads the repository's, whenever the control plane is rebuilt from source, and registers the manifest it built with the artifact resolved to the image — that is what replaced the mesh's record. The installer's step 9 read the catalogue's, pinned its placeholder to the image the registry assigned, and registered that. Nothing else read the catalogue's copy.
- The decision was already taken. ADR 0069 says the control plane's manifest belongs in its own repository, not the catalogue, and the raising design names the catalogue copy as "a thing that can be removed rather than a thing that must be designed". It was not removed because step 9 had no other source — at genesis the installer carries the builder, not the control plane, and reads manifests off a checkout put on the machine by hand.
- But step 3 already had it. The installer builds the control plane from its repository and a commit, and the builder's one-shot result carries the manifest it built — the repository's, its artifact resolved to the image the machine now holds. Step 9 was reading a second copy of a document it had been handed six steps earlier.
Located in: mesh-host internal/bootstrap (steps 3 and 9), and the catalogue's copy. The fix
keeps the built manifest from step 3, registers it at step 9 with the built image's bare id
re-pinned to the registry's reference, and deletes the catalogue's copy. The builder module's
manifest is still the catalogue's and still pinned from a placeholder — ADR 0069 puts it in the
control plane's repository too, and it is not there yet; that is a smaller instance of the same
gap, left open here and named in the lab's genesis check. Ruled out: teaching the two copies to
stay equal (a check across two repositories that only fires after somebody edits one), and reading
the manifest out of the built image (a change to the control plane's image for a document the
build already reports).