An example may not name an image nothing builds
Found by reading the manifests rather than by running them. Two of the provisioner images the examples name had no way to be produced: the object store's had a Dockerfile and no target, and Keycloak's did not exist at all — no image, no Dockerfile, no program. A module naming an image nothing produces resolves, plans, pushes and stops on the machine at `docker pull`, which is the fault arriving as far from its cause as it can get. The object store's target is added. Keycloak's provisioner is removed from its manifest, because writing a manifest for a program that does not exist is the same mistake as the .env files: it parses, it resolves, and it could never work. That makes keycloak's manifest true about today — a server the mesh runs, with its database and its admin credential — and it makes the gap loud. Keycloak no longer claims to provide oidc-client, so a consumer asking for one is refused at plan time by name, rather than resolving cleanly and never having a client created. The check covers only images beginning `mesh-`. Postgres and the rest come from a registry and are somebody else's to build; what this bounds is the set this repository is responsible for and might forget.
This commit is contained in:
@@ -53,6 +53,17 @@ provisioner-image:
|
||||
@echo
|
||||
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||
|
||||
# The object store's provisioner, for the same reason: a bucket and a policy are not files, and
|
||||
# the mesh cannot make them -- it discarded the credential it would have to use.
|
||||
OBJECTSTORE_IMAGE ?= mesh-provision-objectstore:$(VERSION)
|
||||
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
||||
|
||||
objectstore-image:
|
||||
docker build -f examples/objectstore-provisioner/Dockerfile \
|
||||
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
||||
@echo
|
||||
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||
|
||||
# The proxy that turns a route grant into traffic reaching a workload.
|
||||
PROXY_IMAGE ?= mesh-route-proxy:$(VERSION)
|
||||
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
||||
|
||||
Reference in New Issue
Block a user