The bed checks the control plane was built, not carried
The pivot checks proved the running control plane is pinned to a digest this mesh's registry serves, which a carried image satisfies just as well. What the installer now exists to make true is that a build happened, from the commit the bed asked for — and that was printed and not checked.
This commit is contained in:
@@ -644,6 +644,20 @@ async function genesis(images: HeldImage[]): Promise<GenesisResult> {
|
||||
`digest assigned by ${MESH_REGISTRY}.`);
|
||||
}
|
||||
|
||||
// 3a. THE CONTROL PLANE WAS BUILT, not carried.
|
||||
//
|
||||
// **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an
|
||||
// image it was handed cannot rebuild the thing that runs it, and looks identical from the
|
||||
// outside to one that can — same container, same digest, same registry. The difference is
|
||||
// whether a build happened, and the only place that is visible is the installer saying so.
|
||||
const wanted = sourceRef.slice(0, 8);
|
||||
if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) {
|
||||
return stop("after the last step",
|
||||
`the installer never said it built mesh-control from ${wanted}. What runs may have been ` +
|
||||
`carried rather than made here, which is a mesh that cannot rebuild its own control plane.`);
|
||||
}
|
||||
report.push(` built here mesh-control from ${wanted}, by the carried builder`);
|
||||
|
||||
// 3b. And the registry really serves it, asked of the registry rather than of the container. A
|
||||
// reference is a claim; a tag list is the registry agreeing.
|
||||
const tags = await on(CONTROL,
|
||||
|
||||
Reference in New Issue
Block a user