Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue. It is one of three PRs on feat/seats-are-a-closed-set, with novox/hq and novox/mesh-controller. Merge together with the controller PR: the controller's closed set is what admits the git and npm-package-registry claims below.
What changes
package-registry becomes npm-package-registry throughout (ADR 0109):
gitea provides and serves it;
verdaccio provides it;
the builder requires and binds it, and receives its secret under it.
gitea claims two mesh seats (ADR 0110): npm-package-registry, and git, which it now provides with the scheme and port a clone URL needs (ADR 0111).
verdaccio provides and claims nothing. It is the second provider the seat makes harmless: consumers resolve to the holder without a pin.
Not added: cargo or PyPI provisions (deferred by 0109), and a git clone credential (undecided by 0111). The mesh's own repositories are public.
A gap this surfaced, not fixed here
The provisioner reads its contributions path from $MESH_RECEIVES and names no host path itself. That path is still typed twice, though: the controller writes the file where the manifest's receives says, and the manifest author also copies that path into the MESH_RECEIVES environment variable. Nothing hands a process the path per provision, so a module with two provisioner registrations cannot be told where each file is. That needs a mechanism in the mesh, not a constant in a module.
Verified
The controller's tests read this catalogue, and they pass: every claim is a seat in the set, the forge holds both seats, and the builder requires what the npm seat delivers.
No lab bed names the old provision.
Not verified: a TypeScript build of gitea, whose dependencies resolve from the private registry.
Implements **novox/hq ADR 0109, 0110 and 0111** in the catalogue. It is one of three PRs on `feat/seats-are-a-closed-set`, with novox/hq and novox/mesh-controller. **Merge together with the controller PR**: the controller's closed set is what admits the `git` and `npm-package-registry` claims below.
## What changes
- **`package-registry` becomes `npm-package-registry` throughout** (ADR 0109):
- gitea provides and serves it;
- verdaccio provides it;
- the builder requires and binds it, and receives its secret under it.
gitea's contributions file becomes `grants/npm.json`.
- **gitea claims two mesh seats** (ADR 0110): `npm-package-registry`, and `git`, which it now provides with the scheme and port a clone URL needs (ADR 0111).
- **verdaccio provides and claims nothing.** It is the second provider the seat makes harmless: consumers resolve to the holder without a pin.
- **Not added:** cargo or PyPI provisions (deferred by 0109), and a git clone credential (undecided by 0111). The mesh's own repositories are public.
## A gap this surfaced, not fixed here
The provisioner reads its contributions path from `$MESH_RECEIVES` and names no host path itself. That path is still typed twice, though: the controller writes the file where the manifest's `receives` says, and the manifest author also copies that path into the `MESH_RECEIVES` environment variable. Nothing hands a process the path per provision, so a module with two provisioner registrations cannot be told where each file is. That needs a mechanism in the mesh, not a constant in a module.
## Verified
- The controller's tests read this catalogue, and they pass: every claim is a seat in the set, the forge holds both seats, and the builder requires what the npm seat delivers.
- No lab bed names the old provision.
- Not verified: a TypeScript build of gitea, whose dependencies resolve from the private registry.
Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue.
package-registry becomes npm-package-registry throughout (ADR 0109): gitea provides and serves it,
verdaccio provides it, the builder requires, binds and receives its secret under it. gitea's
contributions file is grants/npm.json, so a second ecosystem's file has an obvious name beside it.
gitea claims two mesh seats (ADR 0110): npm-package-registry, which it delivers, and git, which it
now provides with what a clone URL is composed from — http on the forge's web port (ADR 0111).
verdaccio provides npm-package-registry and claims nothing: it is the second provider the seat
exists to make harmless, since a consumer now resolves to the seat's holder without a pin.
No cargo or PyPI provision is added; ADR 0109 defers that. git mints no credential, so gitea's
provisioner registers nothing for it — the mesh's own repositories are public, and a clone
credential is undecided (ADR 0111).
The provisioner still reads where its contributions land from $MESH_RECEIVES, and names no path
itself. One variable carries one path, so a second registration in this module would need the mesh
to say where each provision's file is; that is not possible yet and is not faked here.
Verified: the controller's tests read this catalogue — every claim is a seat in the set, the forge
holds both seats and serves what a clone URL needs, the builder requires what the npm seat delivers
— and pass. Not verified here: a TypeScript build of gitea, whose dependencies resolve from the
private registry.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue. It is one of three PRs on
feat/seats-are-a-closed-set, with novox/hq and novox/mesh-controller. Merge together with the controller PR: the controller's closed set is what admits thegitandnpm-package-registryclaims below.What changes
package-registrybecomesnpm-package-registrythroughout (ADR 0109):gitea's contributions file becomes
grants/npm.json.gitea claims two mesh seats (ADR 0110):
npm-package-registry, andgit, which it now provides with the scheme and port a clone URL needs (ADR 0111).verdaccio provides and claims nothing. It is the second provider the seat makes harmless: consumers resolve to the holder without a pin.
Not added: cargo or PyPI provisions (deferred by 0109), and a git clone credential (undecided by 0111). The mesh's own repositories are public.
A gap this surfaced, not fixed here
The provisioner reads its contributions path from
$MESH_RECEIVESand names no host path itself. That path is still typed twice, though: the controller writes the file where the manifest'sreceivessays, and the manifest author also copies that path into theMESH_RECEIVESenvironment variable. Nothing hands a process the path per provision, so a module with two provisioner registrations cannot be told where each file is. That needs a mechanism in the mesh, not a constant in a module.Verified