Providers: broker-bound runtime container replaces the old provisioner (ADR 0052/0053)
Each provider's separate provisioner container becomes a runtime container that serves the module's tools and runs its provisioner under the module's scoped broker account: mesh-runtime-<module>, on the backend's own network (reaching the backend by name and the broker by NAT), with MESH_BROKER_FILE + MESH_RECEIVES replacing GRANTS. umami gains the broker own-secret it lacked. cloudflare-dns's adapter is re-pointed at the ADR 0053 contract (a data provision, like umami — its record return is the scoped-out concern). Proven: provider-on-backend-network green — redis's runtime, on the private redis network, binds the broker and provisions a consumer with the mesh's credential. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -52,23 +52,26 @@
|
||||
"mode": "0600"
|
||||
},
|
||||
{
|
||||
"id": "provisioner",
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "mesh-provision-cloudflare-dns",
|
||||
"image": "mesh-provision-cloudflare-dns@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"name": "mesh-cloudflare-dns",
|
||||
"image": "mesh-runtime-cloudflare-dns@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"network": "host",
|
||||
"env": {
|
||||
"GRANTS": "/grants",
|
||||
"MESH_CLOUDFLARE_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_CLOUDFLARE_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"volumes": [
|
||||
"/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/cloudflare-dns/grants:/grants",
|
||||
"/var/lib/cloudflare-dns/token:/run/secrets/token:ro",
|
||||
"/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro"
|
||||
]
|
||||
],
|
||||
"env": {
|
||||
"MESH_CLOUDFLARE_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_CLOUDFLARE_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_RECEIVES": "/var/lib/cloudflare-dns/grants/mesh.json"
|
||||
}
|
||||
}
|
||||
],
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1,35 +1,36 @@
|
||||
// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface
|
||||
// (novox/hq ADR 0049). The reconcile loop, sealing and grant-file handling are the sdk harness's;
|
||||
// this writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing
|
||||
// it at the mesh's ingress, and remove it when the grant is withdrawn.
|
||||
// (novox/hq ADR 0049). The reconcile loop and the contributions file are the sdk harness's; this
|
||||
// writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing it
|
||||
// at the mesh's ingress, and remove it when the consumer is withdrawn (ADR 0053).
|
||||
//
|
||||
// The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly
|
||||
// and what it resolves to. It is not a secret (a DNS record is public), so nothing is sealed beyond
|
||||
// what the harness seals; the only secret is this module's own Cloudflare token, which never leaves.
|
||||
// and what it resolves to. Like umami's analytics it is a *data* provision, not a credential one:
|
||||
// nothing the mesh mints is set here (a DNS record is public, and the only secret is this module's
|
||||
// own Cloudflare token, which never leaves). So the password the harness carries is unused; the name
|
||||
// is derived from the login the mesh gave the consumer, which the consumer can derive too. Delivering
|
||||
// the record back to the consumer is the data-provision return path ADR 0053 leaves out of scope.
|
||||
|
||||
import { runProvisioner, type Grant, type Credential } from "@novox/mesh-sdk/provisioner";
|
||||
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||
import { emit } from "@novox/mesh-sdk/events";
|
||||
import { CloudflareClient } from "../client.js";
|
||||
|
||||
const cloudflare = CloudflareClient.fromEnv();
|
||||
|
||||
runProvisioner("public-dns", {
|
||||
async create(grant: Grant): Promise<Credential> {
|
||||
const fqdn = cloudflare.nameFor(grant.consumer);
|
||||
async create(p: Provision): Promise<void> {
|
||||
const fqdn = cloudflare.nameFor(p.as);
|
||||
await cloudflare.upsert(fqdn);
|
||||
await announce("module.cloudflare-dns.record.created", {
|
||||
name: fqdn,
|
||||
target: cloudflare.ingress,
|
||||
consumer: grant.consumer,
|
||||
node: grant.node,
|
||||
consumer: p.consumer ?? "",
|
||||
});
|
||||
return { fields: { fqdn, target: cloudflare.ingress, ttl: "300" } };
|
||||
},
|
||||
|
||||
async remove(grant: Grant): Promise<void> {
|
||||
const fqdn = cloudflare.nameFor(grant.consumer);
|
||||
async remove(p: { as: string }): Promise<void> {
|
||||
const fqdn = cloudflare.nameFor(p.as);
|
||||
await cloudflare.remove(fqdn);
|
||||
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: grant.consumer, node: grant.node });
|
||||
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: p.as });
|
||||
},
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user