The installer carries a builder and builds the control plane it raises

It carried the thing it was going to run; it now carries the thing that makes
it. One artifact either way — but a mesh raised this way holds a control plane
it built from a repository and a commit it can name, and can therefore build
again. A mesh handed a finished image could not, and had no way to find that
out until somebody needed it to.

A build step sits between load and bundle, because the bundle must name an
image and that image no longer arrives finished. Everything after it is
unchanged: a locally built image is named by the digest of its own
configuration, which is exactly what the carried one was named by.

Refused in preflight when nothing says what to build, so a run that cannot
finish says so before it has changed anything.
This commit is contained in:
2026-09-13 04:08:58 +02:00
parent cab83b61c8
commit e1a2fe7323
10 changed files with 312 additions and 37 deletions
+11 -5
View File
@@ -30,6 +30,12 @@ import (
// The saved image, replaced at release time by `make bootstrap`.
//
// **It is the builder, not the control plane** (novox/hq ADR 0073). The installer used to carry
// the thing it was going to run; it now carries the thing that makes it. One artifact either way —
// but a mesh raised by the second one holds a control plane it built from source, out of the same
// repository and path every later rebuild of it will use, and can therefore rebuild it. A mesh
// raised by the first held an artifact it could not reproduce and knew nothing about.
//
// What is committed here is a placeholder, for the same reason `internal/bundle` commits locks
// that are only comments: `go:embed` refuses to compile against a file that is not there, so a
// checkout with nothing embedded would not build at all — and someone reading this repository or
@@ -41,18 +47,18 @@ import (
// the length of one build and then puts the placeholder back — exactly what `make host` does with
// the bundle it embeds.
//
//go:embed control-plane.tar
//go:embed builder.tar
var saved []byte
// ErrEmpty means this installer carries no control-plane image.
// ErrEmpty means this installer carries no builder image.
//
// A separate error rather than a message, so the caller can refuse in preflight — before a
// machine has been touched — instead of discovering it at the load, after the runtime has been
// probed and a bundle has been written.
var ErrEmpty = errors.New(
"this mesh-bootstrap carries no control-plane image, so it cannot raise a mesh. A release " +
"build embeds one: `make bootstrap IMAGE=<image>` in the mesh-host repository, where " +
"<image> is a control-plane image already built from the mesh-control source")
"this mesh-bootstrap carries no builder image, so it cannot raise a mesh. A release build " +
"embeds one: `make bootstrap IMAGE=<image>` in the mesh-host repository, where <image> " +
"is a mesh-builder image already built from the mesh-control source")
// IsEmpty reports whether anything was built in.
//