The bed checks the control plane was built, not carried
The pivot checks proved the running control plane is pinned to a digest this mesh's registry serves, which a carried image satisfies just as well. What the installer now exists to make true is that a build happened, from the commit the bed asked for — and that was printed and not checked.
This commit is contained in:
@@ -175,6 +175,25 @@ export async function genesis(o: GenesisOptions): Promise<GenesisResult> {
|
|||||||
`digest assigned by ${registry}.`);
|
`digest assigned by ${registry}.`);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// 3a. THE CONTROL PLANE WAS BUILT, not carried.
|
||||||
|
//
|
||||||
|
// **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an
|
||||||
|
// image it was handed cannot rebuild the thing that runs it, and looks identical from the
|
||||||
|
// outside to one that can — same container, same digest, same registry. The difference is
|
||||||
|
// whether a build happened, and the only place that is visible is the installer saying so.
|
||||||
|
//
|
||||||
|
// Checked against the commit this bed asked for, not merely that some build occurred: an
|
||||||
|
// installer that quietly built something else would satisfy a weaker check and raise a mesh
|
||||||
|
// nobody asked for.
|
||||||
|
const wanted = o.sourceRef.slice(0, 8);
|
||||||
|
if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) {
|
||||||
|
return stop("after the last step",
|
||||||
|
`the installer never said it built mesh-control from ${wanted}. What runs may have been ` +
|
||||||
|
`carried rather than made here, which is a mesh that cannot rebuild its own control plane. ` +
|
||||||
|
`The installer said:\n${said.split("\n").filter((l) => /built|build/.test(l)).join("\n") || "(nothing about building)"}`);
|
||||||
|
}
|
||||||
|
report.push(` built here mesh-control from ${wanted}, by the carried builder`);
|
||||||
|
|
||||||
// 3b. And the registry really serves it. A reference is a claim; a tag list is the registry agreeing.
|
// 3b. And the registry really serves it. A reference is a claim; a tag list is the registry agreeing.
|
||||||
const tags = await on(`curl -s --max-time 10 http://${registry}/v2/mesh-control/tags/list`);
|
const tags = await on(`curl -s --max-time 10 http://${registry}/v2/mesh-control/tags/list`);
|
||||||
report.push(` registry holds ${tags.out.trim() || "nothing"}`);
|
report.push(` registry holds ${tags.out.trim() || "nothing"}`);
|
||||||
|
|||||||
@@ -644,6 +644,20 @@ async function genesis(images: HeldImage[]): Promise<GenesisResult> {
|
|||||||
`digest assigned by ${MESH_REGISTRY}.`);
|
`digest assigned by ${MESH_REGISTRY}.`);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// 3a. THE CONTROL PLANE WAS BUILT, not carried.
|
||||||
|
//
|
||||||
|
// **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an
|
||||||
|
// image it was handed cannot rebuild the thing that runs it, and looks identical from the
|
||||||
|
// outside to one that can — same container, same digest, same registry. The difference is
|
||||||
|
// whether a build happened, and the only place that is visible is the installer saying so.
|
||||||
|
const wanted = sourceRef.slice(0, 8);
|
||||||
|
if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) {
|
||||||
|
return stop("after the last step",
|
||||||
|
`the installer never said it built mesh-control from ${wanted}. What runs may have been ` +
|
||||||
|
`carried rather than made here, which is a mesh that cannot rebuild its own control plane.`);
|
||||||
|
}
|
||||||
|
report.push(` built here mesh-control from ${wanted}, by the carried builder`);
|
||||||
|
|
||||||
// 3b. And the registry really serves it, asked of the registry rather than of the container. A
|
// 3b. And the registry really serves it, asked of the registry rather than of the container. A
|
||||||
// reference is a claim; a tag list is the registry agreeing.
|
// reference is a claim; a tag list is the registry agreeing.
|
||||||
const tags = await on(CONTROL,
|
const tags = await on(CONTROL,
|
||||||
|
|||||||
Reference in New Issue
Block a user