ADR 0069 had already placed the controller's manifest in its own repository, and the raising design called the catalogue copy a thing to remove. The installer's step 3 was handed that manifest by the build and step 9 read a second copy anyway.
32 lines
2.4 KiB
Markdown
32 lines
2.4 KiB
Markdown
# Diagnosis — 2026-09-21
|
|
|
|
1. The two documents were compared. They differ in exactly one place: the repository's names its
|
|
server container by a build artifact and carries the build section that produces it; the
|
|
catalogue's names a placeholder image digest and carries no build section. Everything else was
|
|
equal on the day of reading, which is the only day that can be said of.
|
|
2. Who reads which. The mesh's own builder reads the repository's, whenever the control plane is
|
|
rebuilt from source, and registers the manifest it built with the artifact resolved to the
|
|
image — that is what replaced the mesh's record. The installer's step 9 read the catalogue's,
|
|
pinned its placeholder to the image the registry assigned, and registered that. Nothing else
|
|
read the catalogue's copy.
|
|
3. The decision was already taken. [ADR 0069](../../02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md)
|
|
says the control plane's manifest belongs in its own repository, not the catalogue, and the
|
|
raising design names the catalogue copy as "a thing that can be removed rather than a thing
|
|
that must be designed". It was not removed because step 9 had no other source — at genesis the
|
|
installer carries the builder, not the control plane, and reads manifests off a checkout put on
|
|
the machine by hand.
|
|
4. But step 3 already had it. The installer builds the control plane from its repository and a
|
|
commit, and the builder's one-shot result carries the manifest it built — the repository's, its
|
|
artifact resolved to the image the machine now holds. Step 9 was reading a second copy of a
|
|
document it had been handed six steps earlier.
|
|
|
|
**Located in:** mesh-host `internal/bootstrap` (steps 3 and 9), and the catalogue's copy. The fix
|
|
keeps the built manifest from step 3, registers it at step 9 with the built image's bare id
|
|
re-pinned to the registry's reference, and deletes the catalogue's copy. The builder module's
|
|
manifest is still the catalogue's and still pinned from a placeholder — ADR 0069 puts it in the
|
|
control plane's repository too, and it is not there yet; that is a smaller instance of the same
|
|
gap, left open here and named in the lab's genesis check. Ruled out: teaching the two copies to
|
|
stay equal (a check across two repositories that only fires after somebody edits one), and reading
|
|
the manifest out of the built image (a change to the control plane's image for a document the
|
|
build already reports).
|