The beds name images the way a machine would find them
Twenty-eight integration tests each carried their own copy of the same two helpers, which pointed a manifest and the substrate bundle at whatever the lab's registry had assigned. They now share two in the harness, and the difference is the point: ours is rewritten to the ID the machine holds it under, and everything else is left exactly as written so the machine pulls it. **The substrate bundle is where the fiction was most load-bearing.** mesh-host's `examples/substrate-first-node.lock` pins all three of its images at `192.0.2.250:5000/…`, which is the address the lab's registry served from — it was written for a target, and the target was the lab. Two of those are ordinary third-party images and become the digests mesh-catalog's own postgres and lavinmq modules pin, so the substrate's store and broker are literally the images the mesh runs. mesh-control exists in no registry at all and becomes the ID the machine was handed. **The bundle itself should be fixed in mesh-host and this substitution deleted with it.** Beds that wrote a manifest by hand named an image by repository and let the rewrite supply a digest. There is nothing to supply one now, so `onTheMachine` refuses an unpinned reference and hands back the digest the catalogue pins — a bed runs the image the mesh ships, and a bed that drifts from the catalogue is testing a different postgres. Three beds took a third-party image out of the raised list, which no longer contains one: certificates (pebble), objectstore (minio and its client) and provisioner (postgres) now name theirs and pull it. builds and mesh publish into the MESH's own artifact store — the `registry` module's image, on the node, on 5000 — rather than into scenery the lab raised. That is a different claim, and only one of them exists in production. New unit tests cover what a full raise would otherwise be the only way to check: the routes an egress machine gets (that its gateway is still the path to the rest of the scenario, that a range with no path is unreachable rather than leaked to the uplink, that each family gets its own next hop), which machine is handed which of our images, and the `images:` rule that refuses a third-party entry. The "shipped scenarios are valid" test now loads every scenario rather than two of them. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -45,8 +45,16 @@ const ROOT_PASSWORD_FILE = "/var/lib/objectstore/root.secret";
|
||||
const ENDPOINT = "http://127.0.0.1:9000";
|
||||
|
||||
let instanceId = "";
|
||||
/** The store's image, by digest, from the registry the scenario raised. */
|
||||
let storeImage = "";
|
||||
/**
|
||||
* The store and the vendor's client, pinned upstream and pulled by the machine over its uplink.
|
||||
*
|
||||
* The store is the digest the mesh's own minio module pins, so this is the store the mesh runs.
|
||||
* Both used to come from a registry the lab raised inside the scenario; no production mesh has
|
||||
* one, so a test that could only fetch from it was proving something about the lab.
|
||||
*/
|
||||
const storeImage =
|
||||
"minio/minio@sha256:aefec8a86702aff0b0dcfdd9284bd7ab7c5631cbf9be63275799e6edcb30dfa2";
|
||||
const clientImage = "minio/mc:RELEASE.2025-08-13T08-35-41Z";
|
||||
|
||||
function shellQuote(s: string): string {
|
||||
return `'${s.replaceAll("'", `'\\''`)}'`;
|
||||
@@ -141,18 +149,10 @@ before(async () => {
|
||||
const instance = await raise(scenario, {});
|
||||
instanceId = instance.instanceId;
|
||||
|
||||
// From the registry the scenario raised, by digest. There is no route to a public registry from
|
||||
// a documentation range, which is the point of the lab having its own.
|
||||
const store = instance.images.find((r) => r.includes("minio/minio"));
|
||||
const client = instance.images.find((r) => r.includes("minio/mc"));
|
||||
assert.ok(store, `the scenario stocked no store image: ${instance.images.join(", ")}`);
|
||||
assert.ok(client, `the scenario stocked no client image: ${instance.images.join(", ")}`);
|
||||
storeImage = store;
|
||||
|
||||
// The client, taken out of the vendor's own image onto the machine. The provisioner drives it,
|
||||
// so it has to be here — and taking it from the stocked image is what keeps this test off any
|
||||
// public network.
|
||||
await must(`docker create --name mc-source ${client}`);
|
||||
// so it has to be here. The machine pulls the image itself, over its uplink, the way it pulls
|
||||
// everything third-party.
|
||||
await must(`docker create --name mc-source ${clientImage}`);
|
||||
await must(`docker cp mc-source:/usr/bin/mc /usr/local/bin/mc && chmod 755 /usr/local/bin/mc`);
|
||||
await must(`docker rm mc-source`);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user