The builder's manifest with one change that matters: it claims node-build-agent, a node seat, so it is assignable to every machine with a container runtime, and every holder pulls one build at a time from the role's one work queue. A tier of many images is then built by as many machines as hold the seat and are online. The builder module stays until this is assigned where it was; then it goes.
build-agent
The mesh's build machine as a role every machine can hold (novox/hq ADR 0190). It holds the node seat
node-build-agent: every holder pulls one build at a time from the role's one work queue when it is
idle, so a tier of many images is built by as many machines as hold the seat and are online, and a
machine that is off builds nothing and blocks nothing. The controller asks the role, never a machine;
the outcome names the machine that built it.
What a holding machine needs is what the builder always needed, said here once: a container runtime
(the socket is mounted), the artifact store and the package registry as provisions, a workspace, and
the bus credential. The code is cmd/mesh-builder in the mesh-controller repository, compiled from
that repository's main (build.artifacts[].context); this module ships the packaging.
Assign it to every machine with a container runtime. It replaces builder, the one-holder form of the
same thing; retire that once this is assigned where it was.