The builder's package-registry grant — the first this provider ever received — has been retry-looping for a day, logging only that an edit 404'd. Two faults underneath:
Gitea's API refuses an email without a dotted domain, so ${as}@localhost failed validation at create. (The CLI that bootstrapped mesh-admin accepts @localhost, which is exactly why the admin exists and no consumer ever did.) The address is now @noreply.localhost — gitea's own hidden-address convention.
ensureUser read the create's 422 as "already exists" and went on to PATCH a user that was never made — burying the create's own error message, the one that says what is actually wrong. The edit path is now taken only when the user actually exists; otherwise the create's failure is reported as itself.
Once merged and rolled out, the provisioner's standing retry loop should converge on its own: the user is created, the minted password applies, and mesh_novox_builder can finally authenticate — which the builder's credentialed git-clone work (in flight) depends on.
The builder's package-registry grant — the first this provider ever received — has been retry-looping for a day, logging only that an edit 404'd. Two faults underneath:
1. **Gitea's API refuses an email without a dotted domain**, so `${as}@localhost` failed validation at create. (The CLI that bootstrapped `mesh-admin` accepts `@localhost`, which is exactly why the admin exists and no consumer ever did.) The address is now `@noreply.localhost` — gitea's own hidden-address convention.
2. **`ensureUser` read the create's 422 as "already exists"** and went on to PATCH a user that was never made — burying the create's own error message, the one that says what is actually wrong. The edit path is now taken only when the user actually exists; otherwise the create's failure is reported as itself.
Once merged and rolled out, the provisioner's standing retry loop should converge on its own: the user is created, the minted password applies, and `mesh_novox_builder` can finally authenticate — which the builder's credentialed git-clone work (in flight) depends on.
The builder's package-registry grant — the first this provider ever
received — retried for a day saying only that an edit 404'd. Two faults
under it: the API refuses an email without a dotted domain, so
`@localhost` failed validation at create (the CLI that made mesh-admin
accepts it, which is why the admin exists and no consumer did); and
ensureUser read that 422 as 'already exists' and went on to edit a user
that was never made, burying the create's own message. The address is now
gitea's own hidden-address shape, and the edit path is taken only for a
user that is actually there.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The builder's package-registry grant — the first this provider ever received — has been retry-looping for a day, logging only that an edit 404'd. Two faults underneath:
${as}@localhostfailed validation at create. (The CLI that bootstrappedmesh-adminaccepts@localhost, which is exactly why the admin exists and no consumer ever did.) The address is now@noreply.localhost— gitea's own hidden-address convention.ensureUserread the create's 422 as "already exists" and went on to PATCH a user that was never made — burying the create's own error message, the one that says what is actually wrong. The edit path is now taken only when the user actually exists; otherwise the create's failure is reported as itself.Once merged and rolled out, the provisioner's standing retry loop should converge on its own: the user is created, the minted password applies, and
mesh_novox_buildercan finally authenticate — which the builder's credentialed git-clone work (in flight) depends on.