Merge pull request 'The toolchain carries the SDK the mesh last published, and esbuild (hq issue 212, ADR 0193)' (#44) from feat/the-toolchain-follows-the-sdk-and-bundles into main

This commit was merged in pull request #44.
This commit is contained in:
2026-10-03 21:31:59 +00:00
3 changed files with 18 additions and 1 deletions
+11
View File
@@ -28,6 +28,14 @@ COPY node-tools/package.json ./
# credential travels no further than here. Development dependencies included: the compiler is one. # credential travels no further than here. Development dependencies included: the compiler is one.
COPY .npmrc ./.npmrc COPY .npmrc ./.npmrc
RUN npm install --no-audit --no-fund RUN npm install --no-audit --no-fund
# **The SDK this image carries is the one the mesh last published** (novox/hq issue 212). The range in
# package.json is resolved once and the layer above is cached, so a release reached no toolchain until
# that file changed. The exact version arrives as a build argument from the SDK module's published
# package (module.json `build.on`), so a new release is a new argument, this layer runs again — and
# the planner orders this module after the SDK, so a release rebuilds the toolchain and, after it,
# every bundle compiled in it (issue 211).
ARG MESH_SDK=@novox/mesh-sdk@latest
RUN npm install --no-audit --no-fund "${MESH_SDK}"
# ---- compiling: the runtime's own code built, WITHOUT the credential ------------------------- # ---- compiling: the runtime's own code built, WITHOUT the credential -------------------------
FROM ${NODE_BASE} AS compiling FROM ${NODE_BASE} AS compiling
@@ -45,6 +53,9 @@ FROM compiling AS lean
RUN npm prune --omit=dev RUN npm prune --omit=dev
# ---- toolchain: what a TypeScript bundle is compiled in --------------------------------------- # ---- toolchain: what a TypeScript bundle is compiled in ---------------------------------------
# The compiler, and esbuild (a development dependency) at /app/node_modules/esbuild: the builder
# bundles every entrypoint and launcher into one file with it (novox/hq ADR 0193), so a bundle
# carries what it imports and not this image's node_modules.
# Beside the compiler, at /app/runtime, what every TypeScript bundle runs with: the production # Beside the compiler, at /app/runtime, what every TypeScript bundle runs with: the production
# dependencies the SDK and the runtime need, and a package.json saying the compiled files are ES # dependencies the SDK and the runtime need, and a package.json saying the compiled files are ES
# modules. The builder copies this directory whole into a compiled bundle (novox/hq ADR 0188 §5), # modules. The builder copies this directory whole into a compiled bundle (novox/hq ADR 0188 §5),
+5
View File
@@ -21,6 +21,11 @@
{ {
"arg": "NODE_BASE", "arg": "NODE_BASE",
"image": "node@sha256:48e4b67d85f87bd551df43704e24d252f56cc5f8e9718841aace50f19948f0f9" "image": "node@sha256:48e4b67d85f87bd551df43704e24d252f56cc5f8e9718841aace50f19948f0f9"
},
{
"arg": "MESH_SDK",
"module": "mesh-sdk",
"artifact": "lib"
} }
] ]
}, },
+2 -1
View File
@@ -18,6 +18,7 @@
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.20.1", "@types/node": "^22.20.1",
"typescript": "^5.9.3" "typescript": "^5.9.3",
"esbuild": "^0.25.0"
} }
} }