The three modules name their base rather than pinning a copy of it

Each named a digest produced inside a lab that no longer exists, so none of them
could be built anywhere else. They say which module they stand on now, and there
is deliberately no default — a build nobody told stops at the declaration rather
than at a reference that resolves to nothing.
This commit is contained in:
2026-09-13 23:53:22 +02:00
parent 720e3706b2
commit 5ea88b149b
6 changed files with 39 additions and 9 deletions
+6 -3
View File
@@ -5,9 +5,12 @@
# other artifact. That is what makes this buildable by the mesh from a repository and a path # other artifact. That is what makes this buildable by the mesh from a repository and a path
# (novox/hq ADR 0069) rather than only on a workstation that happens to have the siblings. # (novox/hq ADR 0069) rather than only on a workstation that happens to have the siblings.
# #
# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag here # Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a
# would make the runtime's contents depend on what somebody last pushed under that name. # fingerprint written here would name one particular copy — the one on whichever machine the person
ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd # typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044).
# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told
# stops here rather than on a reference that resolves to nothing.
ARG RUNTIME_BASE
FROM ${RUNTIME_BASE} AS build FROM ${RUNTIME_BASE} AS build
# Compiled under /app/modules, so resolving `@novox/mesh-sdk` walks up to the base's own # Compiled under /app/modules, so resolving `@novox/mesh-sdk` walks up to the base's own
+7
View File
@@ -58,6 +58,13 @@
} }
], ],
"build": { "build": {
"on": [
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [ "artifacts": [
{ {
"name": "runtime", "name": "runtime",
+6 -3
View File
@@ -5,9 +5,12 @@
# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a # nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a
# repository and a path (novox/hq ADR 0069) rather than only on a workstation with the siblings. # repository and a path (novox/hq ADR 0069) rather than only on a workstation with the siblings.
# #
# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would # Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a
# make this runtime's contents depend on what somebody last pushed under that name. # fingerprint written here would name one particular copy — the one on whichever machine the person
ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd # typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044).
# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told
# stops here rather than on a reference that resolves to nothing.
ARG RUNTIME_BASE
FROM ${RUNTIME_BASE} AS build FROM ${RUNTIME_BASE} AS build
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
+7
View File
@@ -78,6 +78,13 @@
} }
], ],
"build": { "build": {
"on": [
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [ "artifacts": [
{ {
"name": "runtime", "name": "runtime",
+6 -3
View File
@@ -6,9 +6,12 @@
# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have # repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have
# the siblings. # the siblings.
# #
# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would # Named, not pinned. The mesh answers this with the copy of the runtime it holds, because a
# make this runtime's contents depend on what somebody last pushed under that name. # fingerprint written here would name one particular copy — the one on whichever machine the person
ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tools/runtime@sha256:44b5d8bc30107fdc3bffdaebc1ca2de97615053853f826dfccce253a01a163fd # typing it was using — and on any other mesh that copy has never existed (novox/hq issue 044).
# Declared in module.json's `build.on`; there is deliberately no default, so a build nobody told
# stops here rather than on a reference that resolves to nothing.
ARG RUNTIME_BASE
FROM ${RUNTIME_BASE} AS build FROM ${RUNTIME_BASE} AS build
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
+7
View File
@@ -122,6 +122,13 @@
} }
], ],
"build": { "build": {
"on": [
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [ "artifacts": [
{ {
"name": "runtime", "name": "runtime",