Publish the image this mesh built, not the one the installer carried

The carried image is the builder now. The publish step still pushed it, so the
registry got a builder under the control plane's name and the mesh installed it
as the control plane — which presented as a control plane that started, printed
a builder's usage, exited cleanly, and did it again. Caught by the lab on the
first genesis run, at the step that waits for it to answer.
This commit is contained in:
2026-09-13 04:24:18 +02:00
parent e1a2fe7323
commit 432e3edcfd
+11 -4
View File
@@ -311,6 +311,8 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
if err != nil {
return result, failed(StepLoad, err)
}
// These describe the CARRIED image, which is the builder. What the control plane ends up
// being is reported separately, by the build below.
result.Image, result.ImageTags, result.ImageHeld = loaded.ID, loaded.Tags, loaded.Held
result.ImageArchive, result.ImageTag = loaded.Archive, loaded.Tag
result.ImagePredicted = loaded.Predicted
@@ -402,9 +404,9 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
// inside a pull that cannot succeed, three steps from the cause.
if loaded.Predicted {
return result, failed(StepBundle, fmt.Errorf(
"the control plane's image id was never confirmed against this machine's runtime, and "+
"the bundle was about to be written with it. This is a fault in the installer, not "+
"in the machine"))
"the builder's image id was never confirmed against this machine's runtime, and the "+
"build was about to be run with it. This is a fault in the installer, not in the "+
"machine"))
}
if err := writeBundleFile(o.Out, rewritten.Bundle); err != nil {
@@ -477,7 +479,12 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
// ---- 8. publish -----------------------------------------------------------------------
say("publish — the control plane's image gets its first manifest digest")
published, err := PublishControlPlane(ctx, o, d, loaded.ID, say)
// **The image this mesh built, not the one the installer carried.** The carried one is the
// builder; publishing it here would put a builder in the registry under the control plane's
// name and install it as the control plane — which is exactly what happened the first time
// this ran, and presented as a control plane that started, printed a builder's usage, and
// exited cleanly over and over.
published, err := PublishControlPlane(ctx, o, d, controlPlaneImage, say)
result.PublishedAs, result.PublishedAlready = published.Reference, published.Already
if err != nil {
return result, failed(StepPublish, err)