The recipe started FROM the upstream server's digest directly, and the build machine refuses that: every base is declared under build.on and copied into the mesh's own store before a build, so a build never reaches out to a registry the mesh does not run (novox/hq ADR 0097). Found the first time the module was built on a real mesh. Same digest, now declared as NATS_BASE and arriving as a build argument; the Dockerfile says where it comes from and why the digest is the index's.
22 lines
1.3 KiB
Docker
22 lines
1.3 KiB
Docker
# nats's server image: the upstream server, plus an entrypoint that reloads it in place when the
|
|
# mesh rewrites its configuration. See entrypoint.sh for why that belongs here and not in the host.
|
|
#
|
|
# **Pinned to the multi-architecture index digest, not a platform's.** `docker manifest inspect`
|
|
# reports a platform manifest per architecture and the index that lists them; pinning a platform's
|
|
# digest builds on this workstation and fails on any node of another architecture, with an error
|
|
# that names a manifest rather than the mistake. This is the index — `docker pull` reports the same
|
|
# one, and `RepoDigests` confirms it.
|
|
#
|
|
# Unlike every other module's Dockerfile, this builds no TypeScript and uses no mesh base image:
|
|
# the module's code is the server, which upstream already built. There is no BUILD_BASE here on
|
|
# purpose — nothing is compiled. The upstream image is declared in the manifest under build.on and
|
|
# arrives as NATS_BASE, like every other base the mesh copies into its own store before a build
|
|
# (novox/hq ADR 0097); the digest above is the index one for the reason given.
|
|
ARG NATS_BASE
|
|
FROM ${NATS_BASE}
|
|
|
|
COPY entrypoint.sh /usr/local/bin/mesh-nats-entrypoint
|
|
RUN chmod 0755 /usr/local/bin/mesh-nats-entrypoint
|
|
|
|
ENTRYPOINT ["/usr/local/bin/mesh-nats-entrypoint"]
|