From ca263d2a8bdf2efe589327f110d230a9dc82a450 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 23:16:26 +0200 Subject: [PATCH] The trust lands before anything builds The networking module delivers the registry trust, so the bed pushes both machines after assigning it and waits for each runtime to actually hold the trust (file present AND the daemon reloaded) before the first build pushes to anchor.internal:5000. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- .../integration/built-store-cross-node.test.ts | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/test/integration/built-store-cross-node.test.ts b/test/integration/built-store-cross-node.test.ts index 7f95ac1..b5f2235 100644 --- a/test/integration/built-store-cross-node.test.ts +++ b/test/integration/built-store-cross-node.test.ts @@ -236,6 +236,24 @@ test("a joined node's consumers open the store and broker the mesh built and ado await mesh(`assign ${CONTROL} networking`); await mesh(`assign ${NODE} networking`); + // The networking module carries the registry trust (ADR 0082): a merged daemon.json naming the + // store's internal name, and a docker restart when it first lands. It must be ON both machines + // before anything builds or pulls — the builder pushes to anchor.internal:5000 the moment the + // first build finishes. Pushed and WAITED for, because the restart bounces the runtime and an + // apply in flight retries. + for (const machine of [CONTROL, NODE]) { + await mesh(`push ${machine}`, 600_000); + const deadline = Date.now() + 300_000; + let trusted = false; + while (Date.now() < deadline) { + const got = await on(machine, `grep -s "anchor.internal:5000" /etc/docker/daemon.json && docker info --format '{{json .RegistryConfig.IndexConfigs}}' 2>/dev/null | grep -q "anchor.internal:5000" && echo TRUSTED`); + if (/TRUSTED/.test(got.out)) { trusted = true; break; } + await new Promise((r) => setTimeout(r, 5_000)); + } + assert.ok(trusted, `${machine}'s runtime never learned the registry trust:\n` + + (await on(machine, `cat /etc/docker/daemon.json 2>&1; docker info 2>&1 | tail -20`)).out); + } + // The shared base first — every module with code of its own stands on it. await registerModule(BASE.module, baseManifest); const base = await mesh(`build ${forgeUrl(BASE.repo)} --ref ${refFor(BASE.repo)} --wait 1200s`, 1_500_000);