Resolve the SDK by version; mesh-controller/foundation rename #9

Merged
jschoubben merged 3 commits from feat/a-bed-that-hands-over-nothing into main 2026-09-16 21:25:45 +00:00
3 Commits
Author SHA1 Message Date
jschoubben 813f2e0db3 Rename mesh-control -> mesh-controller, substrate -> foundation
One name per thing, per the HQ glossary: the module/container/image/binary/repo
becomes mesh-controller, the seat the-controller, and the store+broker pair the
foundation (embedded base bundles, default template and example lock renamed with
their go:embed directives). No behaviour change — a pure vocabulary rename.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 18:40:40 +02:00
jschoubben b00468d4c0 Resolve the SDK in a throwaway deps stage, not with a buildkit secret
A machine's docker may carry no buildx, so --mount=type=secret cannot be relied
on. Instead a deps stage copies in the builder-written .npmrc, resolves
node_modules from the mesh's registry, and the toolchain stage copies those
node_modules out without the credential — so it is in no published layer.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 11:48:16 +02:00
jschoubben b618057fb1 Resolve the SDK by version from the registry, not from a git URL
package.json names @novox/mesh-sdk by version and the install is a
buildkit-secret-mounted resolve from the mesh's package registry, closing the
git-URL half of issue 053. The lock is regenerated against the registry (a
follow-up switches install to ci with a committed lock).

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 10:27:26 +02:00