A module may mirror an image it did not write
A module usually runs software somebody else built: a database module ships configuration and a provisioner and does not build a database. It could name the upstream reference directly, and then every machine needs a route to a public registry and the reference is a tag somebody else can move — which is what pinning exists to prevent. So an artifact may be `upstream`: pulled by the reference the module names, pushed into the mesh's own registry, and pinned by the digest that registry assigns. This is what the bootstrap already does by hand; it is now something a module can say. Refused: an upstream reference with no tag or digest, because what gets mirrored would be whatever `latest` means today and a module pinned to that is not pinned. And the rule that a build reads only its own repository does not apply to it — applying it anyway refused every reference with a registry host in it, which the test caught. Written by trying to write a real postgres module and finding it could not be said. It can now: two directories, two containers pinned by digest, a superuser password sealed to the machine, and the grants manifest — six resources from one assignment, all accepted by the host's own parser. That exercise also found my manifest wrong rather than the host: a container declared `restart-on`, which is a service field, and the host refused it by name. It is right to. A container whose own definition changes is recreated, and a file it mounts is read by the process inside, which is that image's business.
This commit is contained in:
@@ -244,8 +244,22 @@ type Artifact struct {
|
||||
|
||||
// Kinds an artifact may be.
|
||||
const (
|
||||
ArtifactImage = "image"
|
||||
// ArtifactImage is built from a Dockerfile in this repository.
|
||||
ArtifactImage = "image"
|
||||
// ArtifactArchive is a directory in this repository, packed.
|
||||
ArtifactArchive = "archive"
|
||||
// ArtifactUpstream is an image somebody else built, mirrored into the mesh's own registry and
|
||||
// pinned by the digest it lands with.
|
||||
//
|
||||
// **Because a module usually runs software it did not write.** A database module ships
|
||||
// configuration and a provisioner and does not build a database. It could name the upstream
|
||||
// reference directly, and then every machine needs a route to a public registry and the
|
||||
// reference is a tag somebody else can move — which is what pinning exists to prevent
|
||||
// (novox/hq ADR 0006).
|
||||
//
|
||||
// Mirroring is what the bootstrap already does by hand: the lab stocks upstream images into
|
||||
// the registry a first node pulls from. This makes that a thing a module can say.
|
||||
ArtifactUpstream = "upstream"
|
||||
)
|
||||
|
||||
// NeedID is the resource identity of the file a module's own secret lands in.
|
||||
|
||||
Reference in New Issue
Block a user