gitea provides the package registry; the builder gets its npm credential
gitea gains the package-registry provision: serves/receives/grants, an admin own-secret, a postgres-shaped build, and a provisioner that creates a gitea user per consumer with the mesh-minted password and seals nothing (hq ADR 0048). The builder takes its registry credential as an own-secret rather than a resolved provision, because gitea-as-module needs the base to build its provisioner and so cannot resolve before the base — a cycle the own-secret avoids. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -43,8 +43,22 @@
|
||||
"why": "git over ssh. Not 22: the machine's own daemon holds that, and a module does not take it"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"package-registry": {
|
||||
"scheme": "http",
|
||||
"port": 3000,
|
||||
"npm-path": "/api/packages/novox/npm/"
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"package-registry": "/var/lib/gitea/grants/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"package-registry": "/var/lib/gitea/grants"
|
||||
},
|
||||
"own-secrets": {
|
||||
"internal-token": "/var/lib/gitea/internal-token.secret",
|
||||
"admin": "/var/lib/gitea/admin.secret",
|
||||
"broker": "/var/lib/mesh/gitea/broker"
|
||||
},
|
||||
"resources": [
|
||||
@@ -60,6 +74,12 @@
|
||||
"path": "/var/lib/gitea",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/gitea/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
@@ -95,6 +115,30 @@
|
||||
"/services/gitea/gitea:/data"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "admin-bootstrap",
|
||||
"type": "container",
|
||||
"name": "mesh-gitea-admin",
|
||||
"image": "gitea/gitea@sha256:dfc61e347c8b582df918f4556401bf2cecdfbdb56c5282ae9488dd76fca3e41c",
|
||||
"run-once": true,
|
||||
"env": {
|
||||
"USER_UID": "1000",
|
||||
"USER_GID": "1000",
|
||||
"MESH_GITEA_ADMIN_USER": "mesh-admin"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/gitea/server.env"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/gitea/gitea:/data",
|
||||
"/var/lib/gitea/admin.secret:/run/secrets/admin:ro"
|
||||
],
|
||||
"args": [
|
||||
"/bin/sh",
|
||||
"-c",
|
||||
"su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
@@ -107,17 +151,26 @@
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "mesh-gitea",
|
||||
"image": "mesh-runtime-gitea@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/gitea/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/gitea/config.json:/run/config/config.json:ro"
|
||||
"/var/lib/mesh/gitea/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/gitea/grants:/var/lib/gitea/grants:ro",
|
||||
"/var/lib/gitea/admin.secret:/run/secrets/admin:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_GITEA_URL": "http://127.0.0.1:3000",
|
||||
"MESH_GITEA_CONFIG_FILE": "/run/config/config.json"
|
||||
"MESH_GITEA_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_GITEA_ADMIN_USER": "mesh-admin",
|
||||
"MESH_GITEA_ADMIN_PASSWORD_FILE": "/run/secrets/admin",
|
||||
"MESH_RECEIVES": "/var/lib/gitea/grants/mesh.json"
|
||||
},
|
||||
"artifact": "runtime",
|
||||
"args": [
|
||||
"run",
|
||||
"/app/modules/gitea/dist/provisioner/index.js"
|
||||
],
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
]
|
||||
@@ -128,5 +181,26 @@
|
||||
"name": "package-registry",
|
||||
"scope": "mesh"
|
||||
}
|
||||
]
|
||||
],
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
"arg": "BUILD_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "build"
|
||||
},
|
||||
{
|
||||
"arg": "RUNTIME_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "runtime",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user