/** * Which docker image the RUNTIME-side tools pull, and the guard that keeps a * runtime image out of the compiler-side tools. * * Three flavors ship, but only two of them are reachable as an IMAGE, which is * why this file names two: * * - compiler flavor (JVM): carries the `discoverSources` / link pipeline * units, so it is the only build that can run `@apps/compiler`. Shipped as * `log10x/compiler-10x`, and also inside `log10x/pipeline-10x` (whose * TENX_BIN is `/opt/tenx-cloud/bin/tenx-cloud`; `tenx --version` there * reports `flavor: 'compiler'`). * - runtime flavor (GraalVM native): carries the run/tokenize/group units * that `@apps/mcp` needs, and nothing else. Shipped as `log10x/edge-10x`. * - runtime-jvm flavor: the same runtime capabilities, JVM-packaged, and a * HOST package rather than an image, it ships as the .deb/.rpm/.msi/.dmg * in each release, and exists because Windows has no native runtime binary. * Nothing below resolves to it: it reaches this server through * LOG10X_TENX_PATH in local mode, never through an image ref. The compile * gate refuses it there exactly as it refuses the native runtime (see * `NotCompilerFlavorError`), running on a JVM is not what makes a build a * compiler. * * The run-path default stays `log10x/pipeline-10x:latest` — changing a default * image silently changes what every existing install downloads. Opting into the * native runtime is an explicit env var, `LOG10X_RUNTIME_IMAGE`, which accepts * either a full image ref or the alias `native` (391 MB vs 926 MB on 1.1.38, * identical `@apps/mcp` output). * * `LOG10X_RUNTIME_IMAGE` exists as a knob SEPARATE from `LOG10X_TENX_IMAGE` * because `LOG10X_TENX_IMAGE` is shared: `log10x_compile` falls back to it when * `LOG10X_COMPILER_IMAGE` is unset. Pointing the shared var at a runtime image * to get the native run path therefore also aims the compiler at it, and that * fails four seconds into the container with a Jackson mapping error naming a * missing `discoverSources` factory. See * `assertNotRuntimeImage`, which turns that into an immediate, readable refusal. */ /** Run-path default. Compiler-flavor JVM image; unchanged from 1.23.0. */ export declare const DEFAULT_RUNTIME_IMAGE = "log10x/pipeline-10x:latest"; /** What the `native` / `runtime` alias resolves to. */ export declare const NATIVE_RUNTIME_IMAGE = "log10x/edge-10x:latest"; /** * The tag written into MANIFESTS WE HAND THE USER, which is a different problem * from the two constants above and is why it is pinned when they are not. * * The run-path defaults keep `:latest` deliberately: they name what THIS server * pulls on the user's own machine, changing one silently changes what every * existing install downloads, and the run path already compensates by probing * the container and reporting `docker: ()` so a moving * tag cannot hide which build actually ran. * * A manifest is the opposite case. It is an artifact the user applies into * their cluster with `helm upgrade` and keeps, there is no probe on their side, * and nothing records which build got installed. Two applies a week apart can * install different software with no signal. The documentation says exactly * this — `apps/receiver/deploy.md` sends the reader to Image tags "for why a * deployed manifest should never carry `:latest`" — so emitting one that did * contradicted our own advice. * * Bump this when cutting a release, once the images for that version are * actually PUSHED. A GitHub release is not enough on its own: 1.1.75 was * released 2026-09-03 and no images were published for it, which is why this * sat at 1.1.74 for a fortnight. 1.1.79 carries the OpenTelemetry * return-path fix the ClickHouse offload recipe requires, and its images are * pullable: edge-10x, compiler-10x, pipeline-10x, quarkus-10x and lambda-10x * all answer at 1.1.79 on Docker Hub, checked 2026-09-15. Pin to what is * pullable, not to what is tagged in git. */ export declare const EDGE_MANIFEST_IMAGE = "log10x/edge-10x:1.1.79"; /** * Resolve the image the run-path (`@apps/mcp`) docker backend should use. * * Precedence: LOG10X_RUNTIME_IMAGE (alias-expanded) → LOG10X_TENX_IMAGE → * DEFAULT_RUNTIME_IMAGE. */ export declare function resolveRuntimeImage(env?: NodeJS.ProcessEnv): string; /** True when an image ref names a repository known to ship the runtime flavor. */ export declare function isKnownRuntimeImage(image: string): boolean; /** * Thrown when the compiler path resolved to an image that ships the runtime * flavor. Docker mode has no flavor probe (the compiler image is compiler-flavor * by contract, and probing costs a container start on every compile), so without * this the run gets as far as loading `compile/pipeline.yaml` and dies on a * missing unit factory. */ export declare class RuntimeImageOnCompilerPathError extends Error { readonly image: string; constructor(image: string, viaSharedVar: boolean); } /** * Refuse a known-runtime image on the compiler path. `viaSharedVar` records * whether the value arrived through the shared LOG10X_TENX_IMAGE, so the * message names the variable the user actually set. */ export declare function assertNotRuntimeImage(image: string, viaSharedVar: boolean): void;