The bed checks the control plane was built, not carried

The pivot checks proved the running control plane is pinned to a digest this
mesh's registry serves, which a carried image satisfies just as well. What the
installer now exists to make true is that a build happened, from the commit the
bed asked for — and that was printed and not checked.
This commit is contained in:
2026-09-13 04:28:54 +02:00
parent 607ea241c7
commit fb18807000
2 changed files with 33 additions and 0 deletions
+14
View File
@@ -644,6 +644,20 @@ async function genesis(images: HeldImage[]): Promise<GenesisResult> {
`digest assigned by ${MESH_REGISTRY}.`);
}
// 3a. THE CONTROL PLANE WAS BUILT, not carried.
//
// **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an
// image it was handed cannot rebuild the thing that runs it, and looks identical from the
// outside to one that can — same container, same digest, same registry. The difference is
// whether a build happened, and the only place that is visible is the installer saying so.
const wanted = sourceRef.slice(0, 8);
if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) {
return stop("after the last step",
`the installer never said it built mesh-control from ${wanted}. What runs may have been ` +
`carried rather than made here, which is a mesh that cannot rebuild its own control plane.`);
}
report.push(` built here mesh-control from ${wanted}, by the carried builder`);
// 3b. And the registry really serves it, asked of the registry rather than of the container. A
// reference is a claim; a tag list is the registry agreeing.
const tags = await on(CONTROL,