Delete the lab's registry, and bootstrap the anchor through the installer #19

Merged
jschoubben merged 14 commits from feat/bed-bootstraps-through-the-installer into main 2026-09-11 19:57:05 +00:00
Showing only changes of commit 7875145c0e - Show all commits
+19 -10
View File
@@ -89,15 +89,22 @@ const UPSTREAM = new Map<string, string>([
/** /**
* What a manifest's image reference becomes on the machine. * What a manifest's image reference becomes on the machine.
* *
* Three cases, and the middle one is the whole change: * Four cases, and the second one is the whole change:
* *
* - **Ours** becomes the ID the machine holds it under. Nothing serves it, and nothing needs to. * - **Ours** becomes the ID the machine holds it under. Nothing serves it, and nothing needs to.
* - **Anything already pinned by digest** is returned exactly as written. The machine pulls it * - **Anything already pinned by digest** is returned exactly as written. The machine pulls it
* from the internet, over its uplink, which is what a real machine does and what the lab spent * from the internet, over its uplink, which is what a real machine does and what the lab spent
* a long time serving from a registry of its own instead. * a long time serving from a registry of its own instead.
* - **A bare repository or tag** is one of ours in spirit — a bed naming an image by hand — and * - **A bare repository a bed names by hand** is given the digest mesh-catalog pins for it, so a
* is given the digest the catalogue pins. A tag would be refused by mesh-host anyway, and * bed runs the image the mesh ships. A tag would be refused by mesh-host anyway.
* refusing here says why rather than failing on the machine. * - **A tag this harness has never heard of** is passed through untouched, and said out loud.
*
* That last case is not politeness, it is a finding the lab's registry was hiding. Seven catalogue
* modules name `registry-api.…/novox/…:latest` — a TAG, which ADR 0006 forbids and mesh-host
* refuses. It never showed, because the rewrite replaced every reference with a digest the lab's
* registry had assigned, tag or not. There is nothing to replace it with now, and the honest
* outcome is that those modules fail to apply, saying exactly why, on the node that carries them —
* rather than an assertion here taking the whole bed down before it starts.
*/ */
export function onTheMachine(reference: string, held: HeldImage[]): string { export function onTheMachine(reference: string, held: HeldImage[]): string {
if (isMeshBuilt(reference)) { if (isMeshBuilt(reference)) {
@@ -112,13 +119,15 @@ export function onTheMachine(reference: string, held: HeldImage[]): string {
if (reference.includes("@sha256:")) return reference; if (reference.includes("@sha256:")) return reference;
const upstream = UPSTREAM.get(repositoryOf(reference)); const upstream = UPSTREAM.get(repositoryOf(reference));
assert.ok( if (upstream) return upstream;
upstream,
`${reference} is not pinned and this harness does not know an upstream digest for it. ` + console.log(
`Add the one mesh-catalog pins, or write the reference out in full — a tag moves, and the ` + `UNPINNED: ${reference} names a tag, not a digest. The host will refuse it (novox/hq ` +
`host refuses one.`, `ADR 0006). The lab's own registry used to paper over this by assigning a digest to ` +
`whatever was pushed; nothing does now. Fix the manifest, or add its digest to the ` +
`harness's UPSTREAM table.`,
); );
return upstream; return reference;
} }
export interface Capability { export interface Capability {