The bed bootstraps through the installer, not around it

ADR 0067's own acceptance check said the lab must raise its anchor by running the
program a bare machine runs. It did not: whole-mesh-full applied the substrate bundle
by hand and then looped enrolment over all four machines as one continuous operation.
That gets the order right by accident and models the wrong shape — and an install
procedure that exists only as a test fixture is exercised by whoever writes tests and
never by whoever installs, which is why every bootstrap fault this year was found late.

Two acts now, and the first gates the second.

  GENESIS is novox running mesh-bootstrap: the installer is built from source before
  the raise (make bootstrap, carrying the control-plane image built in the same run),
  placed beside the host binary, given the two manifests it reads, and run. The bed
  then asserts a WORKING MESH OF ONE — the control plane answers, the registry replies
  on /v2/, the container called mesh-control is running from a registry-pinned digest
  rather than an image id, the registry agrees it serves it, temp-mesh-control is gone,
  and the mesh has heard from its node. The image-id check is ADR 0067's "the pivot
  completed" verbatim: if it is still an id, nothing was published and this mesh can
  never roll out its own upgrades.

  JOINING is ace, shanks and g14: host binary, token, enrol, run. novox is NOT enrolled
  again — the installer already did it, and a second identity is one the mesh does not
  know.

If genesis stops, the bed prints which of the installer's ten steps it stopped at and
goes no further. A second machine joining a mesh that is not ready is a different
failure, and running it would bury this one underneath it.

The anchor is no longer handed mesh-control:development. Its absence is the point: the
installer carries that image inside itself, and handing it over as well would make the
load say "already held" and leave the carrying untested — the same class of fiction the
lab's own registry used to hide. A unit test asserts the scenario keeps it out.

The registry is reached at 127.0.0.1:5000, which is a finding rather than a shortcut: a
runtime refuses a plain-HTTP registry at any address but a loopback one, so the digest
the control-plane module is pinned to is one only the anchor can pull. Enough here,
because only the anchor runs a control plane. Written down in the bed.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-11 11:46:42 +02:00
parent 6c09ddb528
commit 555401a787
7 changed files with 519 additions and 72 deletions
+48 -1
View File
@@ -1,7 +1,8 @@
import { test } from "node:test";
import assert from "node:assert/strict";
import { planned } from "../src/rebuild.ts";
import { planned, controlPlaneImage } from "../src/rebuild.ts";
import { repositories } from "../src/repos.ts";
import { loadScenario } from "../src/declaration/parse.ts";
// The control plane's image and the builder are one step, not two.
//
@@ -39,6 +40,52 @@ test("every image the lab runs is rebuilt, not only the control plane's", () =>
}
});
// The installer is built, and it is built AFTER the image it carries.
//
// `make bootstrap` embeds the output of `docker save <image>`, so an installer built before the
// control plane's image is one carrying whatever was lying around — 04-ISSUES/005 again, this time
// sealed inside a binary where nothing would ever notice. The bed raises its anchor by running this
// program (novox/hq ADR 0067), so a stale one is a bed proving something about last week.
test("the installer is built, carrying the image built in the same run", () => {
const builds = planned({
MESH_LAB_HOST_BINARY: "/repo/host/mesh-host",
MESH_LAB_MODULES: "/repo/control/examples/modules",
MESH_LAB_BOOTSTRAP_BINARY: "/repo/host/mesh-bootstrap",
});
const what = builds.map((b) => b.what);
assert.ok(what.includes("installer"), "the installer is never built, so the bed carries a stale one");
assert.ok(
what.indexOf("images") < what.indexOf("installer"),
`the installer is built before the image it embeds: ${what.join(", ")}`,
);
const installer = builds.find((b) => b.what === "installer")!;
assert.equal(installer.in, "/repo/host");
assert.ok(installer.argv.includes(`IMAGE=${controlPlaneImage({})}`), installer.argv.join(" "));
assert.ok(installer.argv.includes("BOOTSTRAP_OUT=/repo/host/mesh-bootstrap"), installer.argv.join(" "));
});
// The anchor must NOT be handed the control plane's image.
//
// The installer carries it, which is the whole reason a machine that can reach no registry can
// raise a mesh (novox/hq ADR 0067). Hand it over from the workstation as well and the installer's
// load says "already held", the carrying is never exercised, and the bed goes green on a fiction —
// the same class of thing the lab's own registry used to hide. Asserted on the file rather than
// remembered, because a list of images is exactly the kind of thing somebody tops up.
test("the whole-mesh bed hands its anchor no control-plane image", () => {
const scenario = loadScenario("scenarios/whole-mesh-full.yml");
const named = [
...(scenario.images ?? []),
...Object.values(scenario.machines).flatMap((m) => m.images ?? []),
];
assert.deepEqual(
named.filter((i) => i.startsWith("mesh-control")),
[],
"the anchor is handed mesh-control, so genesis would never find out whether the installer " +
"really carries it",
);
});
// A repository this run was not pointed at is not built, and not claimed.
test("only what this run was pointed at is built", () => {
assert.deepEqual(planned({}), []);