A provider keeps one grant file per holder, with the local name in its id and path

The lab's vault refused a declaration naming two files with one identity: the
two secrets of one consumer. The holder's suffix is in the resource id and the path now.
This commit is contained in:
2026-09-21 20:41:19 +02:00
parent 3e5c010c5e
commit 5049d201c6
3 changed files with 46 additions and 6 deletions
+17 -4
View File
@@ -324,14 +324,27 @@ func one(ctx context.Context, run Runner, publish Publisher,
switch a.Kind {
case catalogue.ArtifactUpstream:
// Mirrored, not built. Pulled by the reference the module names and pushed under a name
// of the mesh's own, so what a machine fetches is pinned by a digest this registry
// assigned rather than by a tag somebody else can move.
// Mirrored, not built: copied under a name of the mesh's own, so what a machine fetches is
// pinned by a digest this registry assigned rather than by a tag somebody else can move.
//
// **Between registries, never through this machine's image store** (novox/hq
// 04-ISSUES/046, ADR 0096). A published image is an index over several architectures;
// pulled, the store keeps the index and refuses to push one platform out of it, and
// every variant of pull-then-push failed the same way. A copy moves what is there.
if mirror, can := publish.(Mirrorer); can {
say("mirror", "copying %s into the mesh's registry", a.From)
reference, err := mirror.MirrorImage(ctx, a.From, module+"/"+a.Name)
if err != nil {
return catalogue.Built{}, fmt.Errorf("%s: %w", module, err)
}
return catalogue.Built{Name: a.Name, Kind: a.Kind, Reference: reference}, nil
}
// Genesis has no registry to copy into: the image stays in this machine's store, named by
// its own id, as every artifact does before there is anywhere to publish.
say("mirror", "pulling %s", a.From)
if _, err := run(ctx, tree, "docker", "pull", a.From); err != nil {
return catalogue.Built{}, fmt.Errorf("%s: cannot fetch %s: %w", module, a.From, err)
}
say("mirror", "publishing under the mesh's own name")
reference, err := publish.PublishImage(ctx, a.From, module+"/"+a.Name)
if err != nil {
return catalogue.Built{}, err