A machine in the mesh builds a module, and the catalogue records it
The chain this closes: a repository exists, the mesh asks for it, a build machine takes the work, publishes what it made, and the catalogue then says what the module is, which commit it came from, and — after the source moves — that it is behind. Three assertions, against a real broker and registry, because what is under test is four processes agreeing over a wire: - the mesh asks, a machine builds, and the artifact is really in the registry at the digest the manifest names - a build that cannot succeed says why and records nothing. A failure that is silent is indistinguishable from a builder that is not running - the source moving makes the catalogue say "behind", and rebuilding catches it up git is now in the base image, with the same reasoning as docker and wireguard-tools: a machine that builds modules clones them, and a sealed scenario cannot install anything. Read back from `git --version` rather than from the package manager — an installed package is not a capability, and a build machine whose clone fails does so three minutes into a scenario with the failure reported as a build problem rather than a lab one.
This commit is contained in:
@@ -65,6 +65,12 @@ export async function buildBaseImage(
|
||||
log(" installing the tools for the private network");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "wireguard-tools"], 600_000);
|
||||
|
||||
// And git, for the same reason again: a machine that builds modules clones them, and a sealed
|
||||
// scenario cannot install it. On a real build machine the mesh installs it as a package like
|
||||
// anything else — the lab is the special case, because its machines reach no mirror.
|
||||
log(" installing git, so a machine can build modules");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "git"], 600_000);
|
||||
|
||||
// Trust the documentation ranges as plain-HTTP registries.
|
||||
//
|
||||
// A scenario's registry is scenery inside the scenario, serving over HTTP, and a runtime
|
||||
@@ -90,6 +96,18 @@ export async function buildBaseImage(
|
||||
}
|
||||
log(` ${wg.trim()}`);
|
||||
|
||||
// The same, for git. An installed package is not a capability, and this is the one place to
|
||||
// catch it — a build machine whose clone fails does so three minutes into a scenario, with
|
||||
// the failure reported as a build problem rather than a lab one.
|
||||
const git = await incusOk(["exec", BUILDER, "--", "git", "--version"], 60_000);
|
||||
if (!git?.trim()) {
|
||||
throw new BaseImageError(
|
||||
`git was installed in ${BUILDER} and \`git --version\` does not answer. Publishing ` +
|
||||
`this would give every scenario a machine that cannot build a module.`,
|
||||
);
|
||||
}
|
||||
log(` ${git.trim()}`);
|
||||
|
||||
// Read back from the runtime, not from the package manager. An installed package is not a
|
||||
// capability (novox/hq 04-ISSUES/007), and this is the one place to catch that — after
|
||||
// publishing, every scenario pays for it instead.
|
||||
|
||||
Reference in New Issue
Block a user