apply: pull a scheduled container's image at apply, without running it #7

Merged
jschoubben merged 1 commits from feat/schedule-pull into main 2026-09-07 00:48:43 +00:00
Owner

A scheduled step's image was never fetched until its first cadence tick — so anything probing for the image right after apply (a bed's imageId, or an operator) found nothing. This adds a minimal ensureImage (inspect → pull-if-absent → read-back, ADR 0018) and calls it for a scheduled step before recording it. The container is still never started at apply — the no-run invariant of ADR 0053 holds (verified by an extended and a new test). 236 tests pass.

A scheduled step's image was never fetched until its first cadence tick — so anything probing for the image right after apply (a bed's `imageId`, or an operator) found nothing. This adds a minimal `ensureImage` (inspect → pull-if-absent → read-back, ADR 0018) and calls it for a scheduled step before recording it. The container is still never started at apply — the no-run invariant of ADR 0053 holds (verified by an extended and a new test). 236 tests pass.
jschoubben added 1 commit 2026-09-07 00:27:01 +00:00
A schedule: container (ADR 0053) is installed as present state and never run at apply — the
Scheduler fires it later on its cadence. But a service or run-once container only gets its
image as a side effect of docker run, so a scheduled step's image was not pulled until its
first scheduled fire: absent from the node right after a successful apply, so the first run
paid the whole pull latency and tooling that expects the image present after apply found it
missing.

applyContainer now probes the runtime and ensures the pinned image present for a scheduled
step before recording it. A new ensureImage helper inspects the image and pulls it only if
absent, then reads back (ADR 0018). Ensuring an image is not running it: no docker run fires
the container, so the no-run invariant of ADR 0053 holds. The runtime probe, previously
skipped for a schedule, now runs because a pull needs it — the schedule.go comment is updated
to match.

Tests: the install-does-not-run test is extended to allow the image-ensure while asserting no
fire and no needless pull; a new test applies a scheduled container whose image is absent and
asserts it is pulled and still not started. go build, go vet, go test ./... all pass.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit 46cc06847d into main 2026-09-07 00:48:43 +00:00
jschoubben deleted branch feat/schedule-pull 2026-09-07 00:48:43 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#7