The npm registry is a seat gitea holds, and gitea holds the git seat a build's source can live on #69

Merged
jschoubben merged 2 commits from feat/seats-are-a-closed-set into main 2026-09-26 12:31:11 +00:00
Owner

Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue. It is one of three PRs on feat/seats-are-a-closed-set, with novox/hq and novox/mesh-controller. Merge together with the controller PR: the controller's closed set is what admits the git and npm-package-registry claims below.

What changes

  • package-registry becomes npm-package-registry throughout (ADR 0109):

    • gitea provides and serves it;
    • verdaccio provides it;
    • the builder requires and binds it, and receives its secret under it.

    gitea's contributions file becomes grants/npm.json.

  • gitea claims two mesh seats (ADR 0110): npm-package-registry, and git, which it now provides with the scheme and port a clone URL needs (ADR 0111).

  • verdaccio provides and claims nothing. It is the second provider the seat makes harmless: consumers resolve to the holder without a pin.

  • Not added: cargo or PyPI provisions (deferred by 0109), and a git clone credential (undecided by 0111). The mesh's own repositories are public.

A gap this surfaced, not fixed here

The provisioner reads its contributions path from $MESH_RECEIVES and names no host path itself. That path is still typed twice, though: the controller writes the file where the manifest's receives says, and the manifest author also copies that path into the MESH_RECEIVES environment variable. Nothing hands a process the path per provision, so a module with two provisioner registrations cannot be told where each file is. That needs a mechanism in the mesh, not a constant in a module.

Verified

  • The controller's tests read this catalogue, and they pass: every claim is a seat in the set, the forge holds both seats, and the builder requires what the npm seat delivers.
  • No lab bed names the old provision.
  • Not verified: a TypeScript build of gitea, whose dependencies resolve from the private registry.
Implements **novox/hq ADR 0109, 0110 and 0111** in the catalogue. It is one of three PRs on `feat/seats-are-a-closed-set`, with novox/hq and novox/mesh-controller. **Merge together with the controller PR**: the controller's closed set is what admits the `git` and `npm-package-registry` claims below. ## What changes - **`package-registry` becomes `npm-package-registry` throughout** (ADR 0109): - gitea provides and serves it; - verdaccio provides it; - the builder requires and binds it, and receives its secret under it. gitea's contributions file becomes `grants/npm.json`. - **gitea claims two mesh seats** (ADR 0110): `npm-package-registry`, and `git`, which it now provides with the scheme and port a clone URL needs (ADR 0111). - **verdaccio provides and claims nothing.** It is the second provider the seat makes harmless: consumers resolve to the holder without a pin. - **Not added:** cargo or PyPI provisions (deferred by 0109), and a git clone credential (undecided by 0111). The mesh's own repositories are public. ## A gap this surfaced, not fixed here The provisioner reads its contributions path from `$MESH_RECEIVES` and names no host path itself. That path is still typed twice, though: the controller writes the file where the manifest's `receives` says, and the manifest author also copies that path into the `MESH_RECEIVES` environment variable. Nothing hands a process the path per provision, so a module with two provisioner registrations cannot be told where each file is. That needs a mechanism in the mesh, not a constant in a module. ## Verified - The controller's tests read this catalogue, and they pass: every claim is a seat in the set, the forge holds both seats, and the builder requires what the npm seat delivers. - No lab bed names the old provision. - Not verified: a TypeScript build of gitea, whose dependencies resolve from the private registry.
jschoubben added 1 commit 2026-09-25 18:49:14 +00:00
Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue.

package-registry becomes npm-package-registry throughout (ADR 0109): gitea provides and serves it,
verdaccio provides it, the builder requires, binds and receives its secret under it. gitea's
contributions file is grants/npm.json, so a second ecosystem's file has an obvious name beside it.

gitea claims two mesh seats (ADR 0110): npm-package-registry, which it delivers, and git, which it
now provides with what a clone URL is composed from — http on the forge's web port (ADR 0111).
verdaccio provides npm-package-registry and claims nothing: it is the second provider the seat
exists to make harmless, since a consumer now resolves to the seat's holder without a pin.

No cargo or PyPI provision is added; ADR 0109 defers that. git mints no credential, so gitea's
provisioner registers nothing for it — the mesh's own repositories are public, and a clone
credential is undecided (ADR 0111).

The provisioner still reads where its contributions land from $MESH_RECEIVES, and names no path
itself. One variable carries one path, so a second registration in this module would need the mesh
to say where each provision's file is; that is not possible yet and is not faked here.

Verified: the controller's tests read this catalogue — every claim is a seat in the set, the forge
holds both seats and serves what a clone URL needs, the builder requires what the npm seat delivers
— and pass. Not verified here: a TypeScript build of gitea, whose dependencies resolve from the
private registry.
jschoubben added 1 commit 2026-09-26 12:30:51 +00:00
jschoubben merged commit 08e947e4c8 into main 2026-09-26 12:31:11 +00:00
jschoubben deleted branch feat/seats-are-a-closed-set 2026-09-26 12:31:11 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#69