From 92442d377c3aacfa3a6d4fb47fd04b875fc6a651 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 5 Oct 2026 22:46:57 +0200 Subject: [PATCH] The registry-trust test reads the runtime's module, which now writes the trust (ADR 0222) --- cmd/mesh-controller/addresses_test.go | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/cmd/mesh-controller/addresses_test.go b/cmd/mesh-controller/addresses_test.go index 6e82466..dad8dce 100644 --- a/cmd/mesh-controller/addresses_test.go +++ b/cmd/mesh-controller/addresses_test.go @@ -111,6 +111,14 @@ func TestTheRegistryTrustAndEveryImageFollowThePortTheNodeGaveTheStore(t *testin if _, err := assign(ctx, open, "laptop", "app"); err != nil { t.Fatal(err) } + // The runtime's trust is the runtime's module's to write (novox/hq ADR 0222): a stand-in for it + // asks where this machine reaches the store, as the docker module does. + register(t, open, catalogue.Manifest{Module: "runtime", Version: "1", + Resources: []map[string]any{{"id": "daemon", "type": "file", "path": "/etc/docker/daemon.json", + "into": "json", "content": `{"insecure-registries": ["${seat:mesh-artifact-store:reach}"]}` + "\n"}}}) + if _, err := assign(ctx, open, "laptop", "runtime"); err != nil { + t.Fatal(err) + } on := map[string]bool{"anchor": true, "laptop": true} node, port, found, err := artifactStoreOnNetwork(ctx, open.inventory, on)