The control plane, as far as identity
Tier 2 exists now. It holds one context of seven, inventory, and does one thing with it: brings its schema up to date. That is step 3 of the substrate bootstrap -- the step the first node cannot get past. Verified against a real PostgreSQL, with the built binary: applied 0001-nodes, reported 'already up to date' on the second run, and the node table is there with the index and the unique constraint the migration asks for. Written in Go, and the image is FROM scratch holding one file. Confirmed by unpacking it. That is the whole argument of ADR 0024: the bundle pins this image by digest and runs it where nothing can check it, so everything in it is something a person has to audit before trusting a first node. Exclusive store ownership is built as a rule about credentials rather than about intentions. There is no mesh-wide connection setting and no way to ask for one -- a context reads MESH_STORE_<ITS OWN NAME> and holds nothing else, so reaching another context's store needs a new variable, which is visible in the declaration that runs it. The migration runner is mostly refusals: an edited migration that already ran, a migration numbered below one that has run, duplicate numbers, misnamed files, empty files. All stop rather than warn, because at the moment any of them is true nobody knows what the database holds. It stops before identity, deliberately. What a node presents to prove who it is has not been decided anywhere, and a migration is the most expensive place in this system to guess. Two tests did not defend what they claimed, and both are fixed rather than removed. One asked only whether Open returned an error, which it did either way -- a bad context name and a missing credential both fail, so deleting the name check changed nothing. The other claimed to prove the migration runs in a transaction, but PostgreSQL already wraps a multi-statement query in one of its own, so it passed with the transaction taken out. What the transaction actually buys is that the schema change and the row recording it commit together, and there is now a test for that which fails when they are split.
This commit is contained in:
+34
@@ -0,0 +1,34 @@
|
||||
# The control plane's image.
|
||||
#
|
||||
# novox/hq ADR 0024: this image is pinned by digest in the bundle the host carries, fetched on a
|
||||
# machine where no mesh exists yet, and run before there is anything to check it against. So it
|
||||
# holds the program and nothing else — no shell, no package manager, no libc, nothing with a CVE
|
||||
# feed of its own. What a person has to audit before trusting a first node is one binary.
|
||||
#
|
||||
# There are no CA certificates in here on purpose. Nothing it does today makes an outbound TLS
|
||||
# connection to a public name: it reaches PostgreSQL on the machine it was raised on, and the
|
||||
# broker is verified against a fingerprint pinned in a token rather than against a public root
|
||||
# (novox/hq ADR 0004). Adding them "just in case" would put a trust store in the one image whose
|
||||
# whole argument is that it contains nothing to reason about.
|
||||
|
||||
FROM golang:1.25-alpine AS build
|
||||
WORKDIR /src
|
||||
|
||||
# Dependencies first, so a change to the source does not refetch them.
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY . .
|
||||
ARG VERSION=development
|
||||
RUN CGO_ENABLED=0 go build -trimpath \
|
||||
-ldflags "-s -w -X main.version=${VERSION}" \
|
||||
-o /mesh-control ./cmd/mesh-control
|
||||
|
||||
FROM scratch
|
||||
COPY --from=build /mesh-control /mesh-control
|
||||
|
||||
# Numeric because there is no /etc/passwd to look a name up in. Nothing here needs to be root:
|
||||
# it opens outbound connections and writes nothing to its own filesystem.
|
||||
USER 65534:65534
|
||||
|
||||
ENTRYPOINT ["/mesh-control"]
|
||||
Reference in New Issue
Block a user