The base image carries the network tools, and a scenario that grows

A sealed scenario cannot install wireguard-tools any more than it can install a
container runtime, so a lab without them cannot test connectivity at all --
which is most of what the mesh does between machines. Installed and not
started: what a node runs is the mesh's decision, and a lab that brought the
interface up itself would be testing its own setup.

growing-mesh exists to be grown. The point is not the third machine, it is that
adding one changes every other node's peer list -- so each has to be told
again, or the newcomer is on a network nobody else can see.
This commit is contained in:
2026-08-29 18:04:17 +02:00
parent 185c414884
commit c79b83c1bc
2 changed files with 53 additions and 0 deletions
+20
View File
@@ -55,6 +55,16 @@ export async function buildBaseImage(
log(" installing a container runtime");
await incus(["exec", BUILDER, "--", "pacman", "-Sy", "--noconfirm", "docker"], 600_000);
// And the tools for the private network, for the same reason as the runtime: a sealed
// scenario cannot install them, so a lab that omits them cannot test connectivity at all —
// which is most of what the mesh does between machines.
//
// Installed here and NOT started. What a node runs is the mesh's decision, delivered as a
// declaration; a lab that brought the interface up itself would be testing its own setup
// rather than the mesh's.
log(" installing the tools for the private network");
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "wireguard-tools"], 600_000);
// Trust the documentation ranges as plain-HTTP registries.
//
// A scenario's registry is scenery inside the scenario, serving over HTTP, and a runtime
@@ -70,6 +80,16 @@ export async function buildBaseImage(
await incus(["exec", BUILDER, "--", "systemctl", "enable", "docker"], 60_000);
await incus(["exec", BUILDER, "--", "systemctl", "start", "docker"], 120_000);
// Read back from the tool, not from the package manager (novox/hq 04-ISSUES/007).
const wg = await incusOk(["exec", BUILDER, "--", "wg", "--version"], 60_000);
if (!wg?.trim()) {
throw new BaseImageError(
`wireguard-tools was installed in ${BUILDER} and \`wg\` does not answer. Publishing ` +
`this would give every scenario a machine that cannot join a private network.`,
);
}
log(` ${wg.trim()}`);
// Read back from the runtime, not from the package manager. An installed package is not a
// capability (novox/hq 04-ISSUES/007), and this is the one place to catch that — after
// publishing, every scenario pays for it instead.