Providers: broker-bound runtime container replaces the old provisioner (ADR 0052/0053)

Each provider's separate provisioner container becomes a runtime container that
serves the module's tools and runs its provisioner under the module's scoped broker
account: mesh-runtime-<module>, on the backend's own network (reaching the backend
by name and the broker by NAT), with MESH_BROKER_FILE + MESH_RECEIVES replacing
GRANTS. umami gains the broker own-secret it lacked. cloudflare-dns's adapter is
re-pointed at the ADR 0053 contract (a data provision, like umami — its record
return is the scoped-out concern).

Proven: provider-on-backend-network green — redis's runtime, on the private redis
network, binds the broker and provisions a consumer with the mesh's credential.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 00:52:09 +02:00
parent 3b03fcd8f7
commit 08bdd0e456
6 changed files with 81 additions and 64 deletions
+15 -14
View File
@@ -1,35 +1,36 @@
// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface
// (novox/hq ADR 0049). The reconcile loop, sealing and grant-file handling are the sdk harness's;
// this writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing
// it at the mesh's ingress, and remove it when the grant is withdrawn.
// (novox/hq ADR 0049). The reconcile loop and the contributions file are the sdk harness's; this
// writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing it
// at the mesh's ingress, and remove it when the consumer is withdrawn (ADR 0053).
//
// The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly
// and what it resolves to. It is not a secret (a DNS record is public), so nothing is sealed beyond
// what the harness seals; the only secret is this module's own Cloudflare token, which never leaves.
// and what it resolves to. Like umami's analytics it is a *data* provision, not a credential one:
// nothing the mesh mints is set here (a DNS record is public, and the only secret is this module's
// own Cloudflare token, which never leaves). So the password the harness carries is unused; the name
// is derived from the login the mesh gave the consumer, which the consumer can derive too. Delivering
// the record back to the consumer is the data-provision return path ADR 0053 leaves out of scope.
import { runProvisioner, type Grant, type Credential } from "@novox/mesh-sdk/provisioner";
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
import { emit } from "@novox/mesh-sdk/events";
import { CloudflareClient } from "../client.js";
const cloudflare = CloudflareClient.fromEnv();
runProvisioner("public-dns", {
async create(grant: Grant): Promise<Credential> {
const fqdn = cloudflare.nameFor(grant.consumer);
async create(p: Provision): Promise<void> {
const fqdn = cloudflare.nameFor(p.as);
await cloudflare.upsert(fqdn);
await announce("module.cloudflare-dns.record.created", {
name: fqdn,
target: cloudflare.ingress,
consumer: grant.consumer,
node: grant.node,
consumer: p.consumer ?? "",
});
return { fields: { fqdn, target: cloudflare.ingress, ttl: "300" } };
},
async remove(grant: Grant): Promise<void> {
const fqdn = cloudflare.nameFor(grant.consumer);
async remove(p: { as: string }): Promise<void> {
const fqdn = cloudflare.nameFor(p.as);
await cloudflare.remove(fqdn);
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: grant.consumer, node: grant.node });
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: p.as });
},
});