Installation sets up the builder, so a raised mesh can produce

Genesis ended with a mesh that runs and cannot make anything: every module in
the catalogue names artifacts and nothing had built them, so the first thing
anybody had to do was install a builder by hand.

The installer already carries one — it is what built the control plane — so
this is the same two acts the control plane goes through, in the same order:
publish it, so the mesh names it by a digest its own registry assigned rather
than a local identity nothing else can fetch, then install it as an ordinary
module pinned to that. And then the part only it needs, a broker account, issued
before the push so it arrives with the declaration rather than after it.

Verified on a bare machine: the install ends with a builder running, and that
mesh then built the shared base images and a module on top of them with nobody
helping it.
This commit is contained in:
2026-09-14 12:31:43 +02:00
parent 3dfe574e46
commit 8eeb28f00b
4 changed files with 138 additions and 10 deletions
+6 -3
View File
@@ -47,7 +47,7 @@ const (
const usage = `mesh-bootstrap — make a bare machine into a mesh
bootstrap the ten steps below (the default)
bootstrap the twelve steps below (the default)
version
1 preflight what has to be true before anything is changed
@@ -61,6 +61,8 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
9 publish push the control plane's image into it, for its first digest
10 control reinstall the control plane as an ordinary module, pinned to that digest
11 retire drop the temporary control plane; the host removes it
12 builder publish the carried builder and install it, so this mesh can
make the rest of the catalogue rather than be handed it
--bundle the substrate template to build this machine's bundle from
(default ` + defaultTemplate + `)
@@ -74,8 +76,9 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
controls, and what is cloned here is the trust anchor for
everything this mesh will ever run
--source-path the module's directory inside that repository, if not its root
--catalog a checkout of the mesh's catalogue, holding the registry's and the
control plane's manifests. Without it this stops after step 6
--catalog a checkout of the mesh's catalogue, holding the registry's, the
control plane's and the builder's manifests. Without it this stops
after step 6
--node the name this machine is known by (default: its hostname)
--registry where this mesh keeps its own images (default ` + defaultRegistry + `)
every node pulls the control plane from this, so on a mesh of more