A module's tools bundle reaches the machine as an archive where the runtime runs (hq ADR 0175, to-be 38 WP2.2)
The resolved manifest now carries what the build compiled — each bundle's source, digest, language and entrypoints — because a tools bundle is named by no resource of the module's own: the node's runtime loads it, and until this the mesh held no trace of the one artifact that runtime needs. A repository manifest that writes `bundles` beside its build is refused: the mesh derives it. Where the runtime module is in a node's set, every assigned module's bundle with entrypoints is composed as an archive under the mesh's own directory, routed through the artifact store like any image or archive the mesh built. A bundle without entrypoints is run rather than loaded and is delivered by the process that runs it. A node without the runtime is sent exactly what it was.
This commit is contained in:
@@ -512,6 +512,13 @@ func (r Resolution) compose(with Rendering, owner map[string]string,
|
||||
"id": NeedID(name), "type": "file", "path": m.OwnSecrets[name].Path, "sealed": sealed,
|
||||
}))
|
||||
}
|
||||
// This module's tools bundles, where the machine runs the node's tool runtime (novox/hq
|
||||
// ADR 0175, to-be 38 WP2). Mesh-computed like everything above it, and before the module's
|
||||
// own resources for the same reason: the runtime's process names the files inside these
|
||||
// and is restarted when one changes, so they are on the machine before it is.
|
||||
if r.runtimeHere() {
|
||||
first = append(first, bundleArchives(m)...)
|
||||
}
|
||||
// Operator-owned paths this module is granted use of (novox/hq ADR 0051). Written before
|
||||
// the module's own resources, and so before the container that mounts them: the host must
|
||||
// find each present — refusing clearly if the operator has not provided it — before it
|
||||
|
||||
Reference in New Issue
Block a user