From 5ea88b149b48dd8833a712f8bcee1bd19c2ad874 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 23:53:22 +0200 Subject: [PATCH] The three modules name their base rather than pinning a copy of it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Each named a digest produced inside a lab that no longer exists, so none of them could be built anywhere else. They say which module they stand on now, and there is deliberately no default — a build nobody told stops at the declaration rather than at a reference that resolves to nothing. --- modules/amqp-ping/Dockerfile | 9 ++++++--- modules/amqp-ping/module.json | 7 +++++++ modules/mesh-catalog/Dockerfile | 9 ++++++--- modules/mesh-catalog/module.json | 7 +++++++ modules/postgres/Dockerfile | 9 ++++++--- modules/postgres/module.json | 7 +++++++ 6 files changed, 39 insertions(+), 9 deletions(-) diff --git a/modules/amqp-ping/Dockerfile b/modules/amqp-ping/Dockerfile index 3f4a7b1..8072911 100644 --- a/modules/amqp-ping/Dockerfile +++ b/modules/amqp-ping/Dockerfile @@ -5,9 +5,12 @@ # other artifact. That is what makes this buildable by the mesh from a repository and a path # (novox/hq ADR 0069) rather than only on a workstation that happens to have the siblings. # -# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag here -# would make the runtime's contents depend on what somebody last pushed under that name. -ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd +# Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a +# fingerprint written here would name one particular copy — the one on whichever machine the person +# typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044). +# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told +# stops here rather than on a reference that resolves to nothing. +ARG RUNTIME_BASE FROM ${RUNTIME_BASE} AS build # Compiled under /app/modules, so resolving `@novox/mesh-sdk` walks up to the base's own diff --git a/modules/amqp-ping/module.json b/modules/amqp-ping/module.json index 5e7184c..f50d554 100644 --- a/modules/amqp-ping/module.json +++ b/modules/amqp-ping/module.json @@ -58,6 +58,13 @@ } ], "build": { + "on": [ + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], "artifacts": [ { "name": "runtime", diff --git a/modules/mesh-catalog/Dockerfile b/modules/mesh-catalog/Dockerfile index 5331f6b..9f1bd60 100644 --- a/modules/mesh-catalog/Dockerfile +++ b/modules/mesh-catalog/Dockerfile @@ -5,9 +5,12 @@ # nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a # repository and a path (novox/hq ADR 0069) rather than only on a workstation with the siblings. # -# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would -# make this runtime's contents depend on what somebody last pushed under that name. -ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd +# Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a +# fingerprint written here would name one particular copy — the one on whichever machine the person +# typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044). +# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told +# stops here rather than on a reference that resolves to nothing. +ARG RUNTIME_BASE FROM ${RUNTIME_BASE} AS build # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own diff --git a/modules/mesh-catalog/module.json b/modules/mesh-catalog/module.json index 6165f8b..b6f0047 100644 --- a/modules/mesh-catalog/module.json +++ b/modules/mesh-catalog/module.json @@ -78,6 +78,13 @@ } ], "build": { + "on": [ + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], "artifacts": [ { "name": "runtime", diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile index aa74659..5851eed 100644 --- a/modules/postgres/Dockerfile +++ b/modules/postgres/Dockerfile @@ -6,9 +6,12 @@ # repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have # the siblings. # -# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would -# make this runtime's contents depend on what somebody last pushed under that name. -ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd +# Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a +# fingerprint written here would name one particular copy — the one on whichever machine the person +# typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044). +# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told +# stops here rather than on a reference that resolves to nothing. +ARG RUNTIME_BASE FROM ${RUNTIME_BASE} AS build # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own diff --git a/modules/postgres/module.json b/modules/postgres/module.json index a161300..20ec55f 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -122,6 +122,13 @@ } ], "build": { + "on": [ + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], "artifacts": [ { "name": "runtime",