The builder's package binding is settable per node (hq issue 085) #39

Merged
jschoubben merged 2 commits from feat/packages-port into main 2026-09-22 19:59:57 +00:00
Owner

Merge last, after mesh-controller.

The builder's package binding becomes a file the controller can lay a node's setting over, so where the forge answers is a fact about one machine rather than text in a manifest. The catalogue's default port is unchanged.

provision, from, at and as are protected: a setting here says where the forge answers, never who the binding is with, and never the host it dials — the builder sends its registry credential there.

Checked by mesh-controller's catalogue tests against these real manifests.

Merge last, after mesh-controller. The builder's package binding becomes a file the controller can lay a node's setting over, so where the forge answers is a fact about one machine rather than text in a manifest. The catalogue's default port is unchanged. `provision`, `from`, `at` and `as` are protected: a setting here says where the forge answers, never who the binding is with, and never the host it dials — the builder sends its registry credential there. Checked by mesh-controller's catalogue tests against these real manifests.
jschoubben added 2 commits 2026-09-22 19:58:09 +00:00
The forge is raised by hand at genesis, before any module provides
`package-registry`, so the builder carries a binding instead of resolving one —
and the port in it was rewritten, as text, by the installer. A later
registration of this manifest from the catalogue put 3000 back, silently, and
pointed the builder and its registry credential at whatever holds that port.

Made settable instead: the port is a per-node setting the controller holds, and
the catalogue's number is only its default. `provision`, `from` and `as` are
protected — a setting here is about where the forge answers, never about who the
binding is with.

novox/hq 04-ISSUES/085, ADR 0100
`at` was settable. A node setting could point the builder's package binding at
any host, and the builder sends its registry credential there as basic auth — so
a setting meant for a port was a way to hand the password to somebody else.

novox/hq 04-ISSUES/085
jschoubben merged commit 5706c00566 into main 2026-09-22 19:59:57 +00:00
jschoubben deleted branch feat/packages-port 2026-09-22 19:59:57 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#39