The network carries the registry trust (ADR 0082, issues 042/048)

Being on the private network is what grants a machine the right to pull from the mesh's
artifact store, so the module that puts a machine on the network writes the runtime's
trust — a merged /etc/docker/daemon.json naming the store's internal name under
insecure-registries, and a docker.service restart when that fact first lands. The registry
speaks plain HTTP because every path to it is already inside the overlay's encryption; the
provider is found, not configured — whichever module serves artifact-store, on whichever
machine holds it — and with no store on the network nothing is written, which is genesis.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-17 23:05:23 +02:00
parent 39dc927a6f
commit 0e9035d479
3 changed files with 133 additions and 1 deletions
+45
View File
@@ -152,6 +152,15 @@ func network(ctx context.Context, inv *inventory.Inventory, on map[string]bool,
return overlay.Empty(), nil
}
g, err := overlay.From(nodes, overlayCIDR(), "")
if g != nil {
// The artifact store, as this network reaches it. Found rather than configured: the
// provider is whichever module offers it, on whichever machine holds that module — and if
// nothing does yet (genesis raises the registry before the catalogue knows it), there is
// no trust to write and nothing is written (novox/hq ADR 0082).
if at, port, found := artifactStoreOnNetwork(ctx, inv, on); found {
g.TrustRegistry(overlay.InternalName(at) + ":" + port)
}
}
if err != nil && len(refused) > 0 {
// The network is missing something, and some machines could not be resolved at all. Those
// are almost always the same fact: a node that does not resolve contributes nothing, so
@@ -383,3 +392,39 @@ func namesInTheMesh(ctx context.Context, inv *inventory.Inventory) (map[string]s
}
return out, nil
}
// artifactStoreOnNetwork is the machine and port the mesh's artifact store answers on, when a
// module providing it is assigned to a machine that is on the private network.
func artifactStoreOnNetwork(ctx context.Context, inv *inventory.Inventory,
on map[string]bool) (node, port string, found bool) {
shelf, err := inv.Catalogue(ctx)
if err != nil || shelf == nil {
return "", "", false
}
providers := map[string]string{} // module -> served port
for name, m := range shelf {
served, offers := m.Serves[catalogue.ArtifactStoreProvision]
if !offers {
continue
}
if p, ok := served["port"]; ok {
providers[name] = fmt.Sprintf("%v", p)
}
}
if len(providers) == 0 {
return "", "", false
}
for machine := range on {
assigned, err := inv.Assigned(ctx, machine)
if err != nil {
continue
}
for _, a := range assigned {
if p, ok := providers[a]; ok {
return machine, p, true
}
}
}
return "", "", false
}