From d63f006cb87177f6e3f25cc22ecc4629a335d146 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 21:39:54 +0200 Subject: [PATCH] The builder's package binding takes its port from the node, not from the manifest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The forge is raised by hand at genesis, before any module provides `package-registry`, so the builder carries a binding instead of resolving one — and the port in it was rewritten, as text, by the installer. A later registration of this manifest from the catalogue put 3000 back, silently, and pointed the builder and its registry credential at whatever holds that port. Made settable instead: the port is a per-node setting the controller holds, and the catalogue's number is only its default. `provision`, `from` and `as` are protected — a setting here is about where the forge answers, never about who the binding is with. novox/hq 04-ISSUES/085, ADR 0100 --- modules/builder/module.json | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/modules/builder/module.json b/modules/builder/module.json index e7fa8dd..adf5dc7 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -45,6 +45,12 @@ "type": "file", "path": "/var/lib/mesh/builder/package-registry.json", "mode": "0600", + "merge": "json", + "protected": [ + "provision", + "from", + "as" + ], "content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n" }, {