gitea provides the package registry; the builder gets its npm credential
gitea gains the package-registry provision: serves/receives/grants, an admin own-secret, a postgres-shaped build, and a provisioner that creates a gitea user per consumer with the mesh-minted password and seals nothing (hq ADR 0048). The builder takes its registry credential as an own-secret rather than a resolved provision, because gitea-as-module needs the base to build its provisioner and so cannot resolve before the base — a cycle the own-secret avoids. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -17,7 +17,8 @@
|
||||
"module.builder.built"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/builder/broker"
|
||||
"broker": "/var/lib/mesh/builder/broker",
|
||||
"npm-password": "/var/lib/mesh/builder/npm-password"
|
||||
},
|
||||
"resources": [
|
||||
{
|
||||
@@ -37,7 +38,14 @@
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/builder/builder.env",
|
||||
"mode": "0600",
|
||||
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=127.0.0.1:${bound:artifact-store:port}\nMESH_WORKSPACE=/workspace\n"
|
||||
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=127.0.0.1:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/workspace\n"
|
||||
},
|
||||
{
|
||||
"id": "package-binding",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/builder/package-registry.json",
|
||||
"mode": "0600",
|
||||
"content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
@@ -53,7 +61,9 @@
|
||||
"/var/run/docker.sock:/var/run/docker.sock"
|
||||
],
|
||||
"restart-on": [
|
||||
"builder-env"
|
||||
"builder-env",
|
||||
"package-binding",
|
||||
"needs-npm-password"
|
||||
]
|
||||
}
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user