Offer to install what is missing, rather than refusing over it
Refusing because Docker is absent is not help. It is a chore handed back to the operator, who will then install it however the first search result says to -- which is how machines end up with a third-party apt repository and a signing key nobody chose. So the installer offers. It says what it would do, in the same words the plan uses, and does it only when told: --install-deps during a run, or "inbuxa deps --install" on its own for someone preparing a machine before they have a domain to give it. What it installs, and from where, is the part worth arguing about: - the Docker daemon: the distribution's own package. One package from an archive the machine already trusts beats a new source. - the Compose plugin: Debian's docker.io ships no compose v2 at all, so this is Docker's official static build, pinned by version with its checksum in the source beside it. - Node: the official tarball into /opt/inbuxa/node, deliberately off PATH so it runs the webmail's unit and nothing else. Every download is checked before it is put in place; a checksum that does not match stops the step rather than warning and carrying on. Tested from a bare Debian 13 in the lab: 25 checks, ending with docker and compose answering, node 22 where the unit will look for it, and the installer agreeing that nothing is missing any more. The last of those failed the first time -- the survey looked for node on PATH only, and so could not see the one it had just installed.
This commit is contained in:
@@ -22,6 +22,12 @@ This is early. What is built:
|
||||
- **`install --dry-run`** -- the whole plan: every file, unit, container,
|
||||
port, DNS record and credential, and a refusal with a reason when the
|
||||
machine cannot carry out what was asked.
|
||||
- **`deps`** -- what a shape needs that this machine has not got, and, with
|
||||
`--install`, the doing of it: the Docker daemon from the distribution's own
|
||||
archive, the Compose plugin and Node from their official builds, both
|
||||
pinned by version and checked against a checksum in the source before
|
||||
anything is put in place. `install --install-deps` does the same as part of
|
||||
a run. A missing dependency is an offer, not a refusal.
|
||||
|
||||
Not built yet: applying the plan, the terminal interface, `join`, `status`,
|
||||
`upgrade`, `uninstall`. The design is in the inbuxa specification (§6.1 and
|
||||
|
||||
Reference in New Issue
Block a user