mosquitto: the runtime serves its code, and its bootstrap is a run-once process (hq ADR 0198)
The mesh-mosquitto container goes with its Dockerfile, build bases and bus credential. mosquitto_ctrl comes from the mosquitto package, and the bootstrap step runs node on the bundle, reading the broker's published port from an env-file the mesh fills, because a process's env is not given ${port:…}.
This commit is contained in:
@@ -1,28 +0,0 @@
|
|||||||
# mosquitto's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/mosquitto
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc topics.ts client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
# mosquitto's client and bootstrap drive `mosquitto_ctrl`; the apt package carries it with its
|
|
||||||
# shared libraries — the musl binary from the eclipse image would not load on this glibc base.
|
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends mosquitto \
|
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
|
||||||
COPY --from=build /app/modules/mosquitto/dist /app/modules/mosquitto/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/mosquitto/dist/index.js,/app/modules/mosquitto/dist/tools/index.js,/app/modules/mosquitto/dist/provisioner/index.js
|
|
||||||
@@ -32,8 +32,7 @@
|
|||||||
"mqtt-topic": "${dir:grants}"
|
"mqtt-topic": "${dir:grants}"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:mesh-state}/admin",
|
"admin": "${dir:mesh-state}/admin"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -89,25 +88,28 @@
|
|||||||
"name": "mosquitto"
|
"name": "mosquitto"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "bootstrap",
|
"id": "bootstrap-env",
|
||||||
"type": "container",
|
"type": "file",
|
||||||
"name": "mosquitto-bootstrap",
|
"path": "${dir:state}/bootstrap.env",
|
||||||
"run-once": true,
|
"mode": "0600",
|
||||||
"volumes": [
|
"content": "MESH_PROVISION_MQTT=127.0.0.1:${port:1883}\nMESH_PROVISION_ADMIN_USER=mesh-admin\nMESH_PROVISION_PASSWORD_FILE=${dir:mesh-state}/admin\nMESH_DYNSEC_FILE=${dir:data}/dynamic-security.json\n"
|
||||||
"${dir:data}:/mosquitto/data",
|
|
||||||
"${dir:mesh-state}/admin:/run/secrets/admin:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
|
||||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin",
|
|
||||||
"MESH_DYNSEC_FILE": "/mosquitto/data/dynamic-security.json"
|
|
||||||
},
|
},
|
||||||
"args": [
|
{
|
||||||
"run",
|
"id": "bootstrap",
|
||||||
"/app/modules/mosquitto/dist/bootstrap/index.js"
|
"type": "process",
|
||||||
|
"name": "mosquitto-bootstrap",
|
||||||
|
"artifact": "code",
|
||||||
|
"run": [
|
||||||
|
"node",
|
||||||
|
"bootstrap/index.js"
|
||||||
],
|
],
|
||||||
"artifact": "runtime"
|
"run-once": true,
|
||||||
|
"env-file": [
|
||||||
|
"${dir:state}/bootstrap.env"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"bootstrap-env"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
@@ -125,43 +127,34 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "client",
|
||||||
"type": "container",
|
"type": "package",
|
||||||
"name": "mesh-mosquitto",
|
"package": "mosquitto"
|
||||||
"network": "mosquitto",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro",
|
|
||||||
"${dir:mesh-state}/admin:/run/secrets/admin:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
||||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
|
||||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js",
|
||||||
|
"bootstrap/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||||
|
"MESH_PROVISION_MQTT": "127.0.0.1:${port:1883}",
|
||||||
|
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:mesh-state}/admin"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user