The builder resolves the SDK from the mesh registry, and can publish packages

A new 'package' artifact kind builds a module's own code on a public base image
and publishes it to the mesh's package registry by version (hq ADR 0076) — the
SDK above all, which the toolchain is built from and so cannot be built in the
toolchain. The credential a build needs to resolve or publish packages is
rendered as an .npmrc (basic auth, hq ADR 0048) and given to an image build as a
buildkit secret, never a layer, so a token is not baked into the toolchain image.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 10:27:26 +02:00
parent 2fb700d61b
commit 4b9bc50aad
10 changed files with 588 additions and 26 deletions
+7
View File
@@ -463,6 +463,13 @@ const (
// Mirroring is what the bootstrap already does by hand: the lab stocks upstream images into
// the registry a first node pulls from. This makes that a thing a module can say.
ArtifactUpstream = "upstream"
// ArtifactPackage is this module's own code, compiled and published to the mesh's package
// registry by version, for other modules to consume when they are built — the SDK above all
// (novox/hq ADR 0076). Like a bundle it is built from the module's own directory and names a
// language; unlike a bundle it is not a resource on any machine, it is a build input. It is
// compiled on a PUBLIC base, never the mesh toolchain, because the toolchain is built from it.
ArtifactPackage = "package"
)
// ArtifactStoreProvision is the name a module offers when it is the mesh's store for what modules