build(image): compile the Zenoh adapter into the relay image
`Dockerfile:70` and `REMAPPING/cicd/Dockerfile:103` built
`-p meridian-relay --bin meridian-relay` with no `--features zenoh`, and the
adapter sits behind `zenoh = ["meridian-pubsub/zenoh"]`, off by default. So in
every image this repo can build, `bus_backend_from_str` in
`crates/meridian-relay/src/config.rs` takes its `#[cfg(not(feature = "zenoh"))]`
arm and answers `MERIDIAN_BUS=zenoh|shadow` with
MERIDIAN_BUS=`zenoh` needs a relay built with the `zenoh` feature;
this binary constructs `redis` only
That is a boot failure, not a bus. Verified against both binaries built from
this tree: the feature-off relay prints exactly the line above and exits 1; the
feature-on relay accepts the name and moves on to demand
`MERIDIAN_ZENOH_ENDPOINTS`, and its accepted set is `redis, zenoh, shadow`
rather than `redis`. Found by the Provenance Auditor seat, Security & Identity
council, and recorded as meridian-nok3.
The flag goes on `cargo chef cook` as well as `cargo build`, because the two
layers must agree. Measured with `cargo tree -e normal,build` on this lockfile:
the feature takes the workspace graph the cook layer builds from 565 to 642
packages (+77) and the three-package selection from 505 to 596 (+91), and every
one of those lands in the source layer — invalidated by any edit under
`crates/` — if only the build line carries it. The symptom would be a build that
got slow rather than one that broke, which is why it is a comment between the
two lines rather than a note in a commit nobody re-reads.
Package-qualified (`meridian-relay/zenoh`) because three packages are selected;
a bare `--features zenoh` does not say which one it belongs to. `cargo chef`
0.1.71 — the version both Dockerfiles pin — forwards `--features` verbatim to
`cargo build`, and its skeleton preserves member `[features]` tables, so the
qualified name resolves there too.
Both published targets derive from this stage (`runtime` via
`stripped-binaries`, and `runtime-debug`), so both carry the adapter.
`MERIDIAN_BUS` still defaults to `redis`: this commit makes the variable
readable, not active.
Gates: just zenoh-check 0, just check-docker-context 0.
Signed-off-by: Joshua Belke <admin@aipowergrid.io>
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
This commit is contained in:
parent
f4e6265aa4
commit
c99ed00692
2 changed files with 44 additions and 4 deletions
24
Dockerfile
24
Dockerfile
|
|
@ -65,11 +65,31 @@ ENV CARGO_PROFILE_RELEASE_DEBUG=line-tables-only
|
|||
COPY --from=planner /build/recipe.json recipe.json
|
||||
# Cook the full workspace recipe — relay deps include workspace siblings, so
|
||||
# scoping to -p meridian-relay misses transitive deps and re-builds them later.
|
||||
RUN cargo chef cook --release --recipe-path recipe.json
|
||||
#
|
||||
# The feature list here MUST match the one on `cargo build` below. Measured
|
||||
# with `cargo tree -e normal,build` on this lockfile: the feature takes the
|
||||
# workspace graph this layer cooks from 565 to 642 packages (+77), and the
|
||||
# three-package selection built below from 505 to 596 (+91). Cook without it
|
||||
# and every one of those compiles in the source layer instead, where any edit
|
||||
# under crates/ invalidates them. The failure is a build that got slow, not a
|
||||
# build that broke, so it is the kind that survives review — hence both lines,
|
||||
# and this note between them.
|
||||
RUN cargo chef cook --release --recipe-path recipe.json --features meridian-relay/zenoh
|
||||
COPY . .
|
||||
# `--features meridian-relay/zenoh` is load-bearing, not an optimisation.
|
||||
# `MERIDIAN_BUS=zenoh|shadow` is a HARD startup error in a relay built without
|
||||
# it — see `bus_backend_from_str` in crates/meridian-relay/src/config.rs, whose
|
||||
# `#[cfg(not(feature = "zenoh"))]` arm answers ConfigError::InvalidValue rather
|
||||
# than falling back to Redis. Shipping a deploy artifact that names a variable
|
||||
# this binary cannot read is a guaranteed crash loop, so the image carries the
|
||||
# adapter even while `MERIDIAN_BUS` defaults to `redis`.
|
||||
#
|
||||
# Package-qualified because three packages are selected here; a bare
|
||||
# `--features zenoh` does not name which one it belongs to.
|
||||
RUN cargo build --release --locked -p meridian-relay --bin meridian-relay \
|
||||
-p meridian-admin --bin meridian-admin \
|
||||
-p meridian-pair-relay --bin meridian-pair-relay
|
||||
-p meridian-pair-relay --bin meridian-pair-relay \
|
||||
--features meridian-relay/zenoh
|
||||
|
||||
# Derive the normal release binaries from the same optimized ELF files as the
|
||||
# debug image so the two variants cannot drift at code-generation time.
|
||||
|
|
|
|||
|
|
@ -98,11 +98,31 @@ ENV CARGO_PROFILE_RELEASE_DEBUG=line-tables-only
|
|||
COPY --from=planner /build/recipe.json recipe.json
|
||||
# Cook the full workspace recipe — relay deps include workspace siblings, so
|
||||
# scoping to -p meridian-relay misses transitive deps and re-builds them later.
|
||||
RUN cargo chef cook --release --recipe-path recipe.json
|
||||
#
|
||||
# The feature list here MUST match the one on `cargo build` below. Measured
|
||||
# with `cargo tree -e normal,build` on this lockfile: the feature takes the
|
||||
# workspace graph this layer cooks from 565 to 642 packages (+77), and the
|
||||
# three-package selection built below from 505 to 596 (+91). Cook without it
|
||||
# and every one of those compiles in the source layer instead, where any edit
|
||||
# under crates/ invalidates them. The failure is a build that got slow, not a
|
||||
# build that broke, so it is the kind that survives review — hence both lines,
|
||||
# and this note between them.
|
||||
RUN cargo chef cook --release --recipe-path recipe.json --features meridian-relay/zenoh
|
||||
COPY . .
|
||||
# `--features meridian-relay/zenoh` is load-bearing, not an optimisation.
|
||||
# `MERIDIAN_BUS=zenoh|shadow` is a HARD startup error in a relay built without
|
||||
# it — see `bus_backend_from_str` in crates/meridian-relay/src/config.rs, whose
|
||||
# `#[cfg(not(feature = "zenoh"))]` arm answers ConfigError::InvalidValue rather
|
||||
# than falling back to Redis. Shipping a deploy artifact that names a variable
|
||||
# this binary cannot read is a guaranteed crash loop, so the image carries the
|
||||
# adapter even while `MERIDIAN_BUS` defaults to `redis`.
|
||||
#
|
||||
# Package-qualified because three packages are selected here; a bare
|
||||
# `--features zenoh` does not name which one it belongs to.
|
||||
RUN cargo build --release --locked -p meridian-relay --bin meridian-relay \
|
||||
-p meridian-admin --bin meridian-admin \
|
||||
-p meridian-pair-relay --bin meridian-pair-relay
|
||||
-p meridian-pair-relay --bin meridian-pair-relay \
|
||||
--features meridian-relay/zenoh
|
||||
|
||||
# Derive the normal release binaries from the same optimized ELF files as the
|
||||
# debug image so the two variants cannot drift at code-generation time.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue