A build declares the vendor image it stands on, and a recipe fetches nothing undeclared

build.on takes {arg, image@sha256:…} beside {arg, module, artifact}: the image is
copied into the mesh's registry before the build (ADR 0096) and the recipe reads the
copy from the argument. A FROM or COPY --from naming a registry image the manifest
did not declare is refused before the build, naming it and the remedy; stages,
declared arguments and scratch are not fetches (novox/hq 04-ISSUES/064, ADR 0097).
This commit is contained in:
2026-09-21 20:45:36 +02:00
parent 412599de9a
commit 6f6e1244d4
3 changed files with 201 additions and 9 deletions
+9 -3
View File
@@ -411,14 +411,20 @@ type Build struct {
On []BuildsOn `json:"on,omitempty"`
}
// BuildsOn is one base a build needs, and the name the recipe knows it by.
// BuildsOn is one base a build needs, and the name the recipe knows it by: another module's
// artifact, or an image published elsewhere.
type BuildsOn struct {
// Arg is the build argument the recipe reads it from.
Arg string `json:"arg"`
// Module is whose artifact it is.
Module string `json:"module"`
Module string `json:"module,omitempty"`
// Artifact is which of that module's artifacts, by its own name for it.
Artifact string `json:"artifact"`
Artifact string `json:"artifact,omitempty"`
// Image is an image published elsewhere, pinned by digest, that the build copies out of — a
// vendor's tool, a base nobody in the mesh builds. Declared, the mesh copies it into its own
// registry before the build and hands the recipe the copy (novox/hq 04-ISSUES/064, ADR 0097);
// a recipe fetching from a public registry on its own is refused.
Image string `json:"image,omitempty"`
}
// Artifact is one thing built from a module's source.