Providers: broker-bound runtime container replaces the old provisioner (ADR 0052/0053)
Each provider's separate provisioner container becomes a runtime container that serves the module's tools and runs its provisioner under the module's scoped broker account: mesh-runtime-<module>, on the backend's own network (reaching the backend by name and the broker by NAT), with MESH_BROKER_FILE + MESH_RECEIVES replacing GRANTS. umami gains the broker own-secret it lacked. cloudflare-dns's adapter is re-pointed at the ADR 0053 contract (a data provision, like umami — its record return is the scoped-out concern). Proven: provider-on-backend-network green — redis's runtime, on the private redis network, binds the broker and provisions a consumer with the mesh's credential. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -52,23 +52,26 @@
|
|||||||
"mode": "0600"
|
"mode": "0600"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisioner",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-provision-cloudflare-dns",
|
"name": "mesh-cloudflare-dns",
|
||||||
"image": "mesh-provision-cloudflare-dns@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-runtime-cloudflare-dns@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "host",
|
"network": "host",
|
||||||
"env": {
|
|
||||||
"GRANTS": "/grants",
|
|
||||||
"MESH_CLOUDFLARE_TOKEN_FILE": "/run/secrets/token",
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_CLOUDFLARE_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro",
|
"/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro",
|
||||||
"/var/lib/cloudflare-dns/grants:/grants",
|
"/var/lib/cloudflare-dns/grants:/grants",
|
||||||
"/var/lib/cloudflare-dns/token:/run/secrets/token:ro",
|
"/var/lib/cloudflare-dns/token:/run/secrets/token:ro",
|
||||||
"/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro"
|
"/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro"
|
||||||
]
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_CLOUDFLARE_TOKEN_FILE": "/run/secrets/token",
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
|
"MESH_CLOUDFLARE_CONFIG_FILE": "/run/config/config.json",
|
||||||
|
"MESH_RECEIVES": "/var/lib/cloudflare-dns/grants/mesh.json"
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"capabilities": [
|
||||||
|
"container-runtime"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,35 +1,36 @@
|
|||||||
// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface
|
// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface
|
||||||
// (novox/hq ADR 0049). The reconcile loop, sealing and grant-file handling are the sdk harness's;
|
// (novox/hq ADR 0049). The reconcile loop and the contributions file are the sdk harness's; this
|
||||||
// this writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing
|
// writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing it
|
||||||
// it at the mesh's ingress, and remove it when the grant is withdrawn.
|
// at the mesh's ingress, and remove it when the consumer is withdrawn (ADR 0053).
|
||||||
//
|
//
|
||||||
// The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly
|
// The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly
|
||||||
// and what it resolves to. It is not a secret (a DNS record is public), so nothing is sealed beyond
|
// and what it resolves to. Like umami's analytics it is a *data* provision, not a credential one:
|
||||||
// what the harness seals; the only secret is this module's own Cloudflare token, which never leaves.
|
// nothing the mesh mints is set here (a DNS record is public, and the only secret is this module's
|
||||||
|
// own Cloudflare token, which never leaves). So the password the harness carries is unused; the name
|
||||||
|
// is derived from the login the mesh gave the consumer, which the consumer can derive too. Delivering
|
||||||
|
// the record back to the consumer is the data-provision return path ADR 0053 leaves out of scope.
|
||||||
|
|
||||||
import { runProvisioner, type Grant, type Credential } from "@novox/mesh-sdk/provisioner";
|
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||||
import { emit } from "@novox/mesh-sdk/events";
|
import { emit } from "@novox/mesh-sdk/events";
|
||||||
import { CloudflareClient } from "../client.js";
|
import { CloudflareClient } from "../client.js";
|
||||||
|
|
||||||
const cloudflare = CloudflareClient.fromEnv();
|
const cloudflare = CloudflareClient.fromEnv();
|
||||||
|
|
||||||
runProvisioner("public-dns", {
|
runProvisioner("public-dns", {
|
||||||
async create(grant: Grant): Promise<Credential> {
|
async create(p: Provision): Promise<void> {
|
||||||
const fqdn = cloudflare.nameFor(grant.consumer);
|
const fqdn = cloudflare.nameFor(p.as);
|
||||||
await cloudflare.upsert(fqdn);
|
await cloudflare.upsert(fqdn);
|
||||||
await announce("module.cloudflare-dns.record.created", {
|
await announce("module.cloudflare-dns.record.created", {
|
||||||
name: fqdn,
|
name: fqdn,
|
||||||
target: cloudflare.ingress,
|
target: cloudflare.ingress,
|
||||||
consumer: grant.consumer,
|
consumer: p.consumer ?? "",
|
||||||
node: grant.node,
|
|
||||||
});
|
});
|
||||||
return { fields: { fqdn, target: cloudflare.ingress, ttl: "300" } };
|
|
||||||
},
|
},
|
||||||
|
|
||||||
async remove(grant: Grant): Promise<void> {
|
async remove(p: { as: string }): Promise<void> {
|
||||||
const fqdn = cloudflare.nameFor(grant.consumer);
|
const fqdn = cloudflare.nameFor(p.as);
|
||||||
await cloudflare.remove(fqdn);
|
await cloudflare.remove(fqdn);
|
||||||
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: grant.consumer, node: grant.node });
|
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: p.as });
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
+12
-10
@@ -98,21 +98,23 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisioner",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-provision-objectstore",
|
"name": "mesh-minio",
|
||||||
"image": "mesh-provision-objectstore@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "minio",
|
"network": "minio",
|
||||||
"env": {
|
|
||||||
"GRANTS": "/var/lib/minio/grants",
|
|
||||||
"MESH_MINIO_ENDPOINT": "http://minio:9000",
|
|
||||||
"MESH_MINIO_ROOT_USER": "meshroot",
|
|
||||||
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root"
|
|
||||||
},
|
|
||||||
"volumes": [
|
"volumes": [
|
||||||
|
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
|
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
|
||||||
"/var/lib/minio/root.secret:/run/secrets/root:ro"
|
"/var/lib/minio/root.secret:/run/secrets/root:ro"
|
||||||
]
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_MINIO_ENDPOINT": "http://minio:9000",
|
||||||
|
"MESH_MINIO_ROOT_USER": "meshroot",
|
||||||
|
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
|
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -97,20 +97,22 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisioner",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-provision-postgres",
|
"name": "mesh-postgres",
|
||||||
"image": "mesh-provision-postgres@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-runtime-postgres@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "postgres",
|
"network": "postgres",
|
||||||
"env": {
|
|
||||||
"GRANTS": "/var/lib/postgres/grants",
|
|
||||||
"MESH_PROVISION_POSTGRES": "postgres://postgres@postgres:5432/postgres?sslmode=disable",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser"
|
|
||||||
},
|
|
||||||
"volumes": [
|
"volumes": [
|
||||||
|
"/var/lib/mesh/postgres/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/postgres/grants:/var/lib/postgres/grants:ro",
|
"/var/lib/postgres/grants:/var/lib/postgres/grants:ro",
|
||||||
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
|
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
|
||||||
]
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_PROVISION_POSTGRES": "postgres://postgres@postgres:5432/postgres?sslmode=disable",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
|
"MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -96,20 +96,22 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisioner",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-provision-redis",
|
"name": "mesh-redis",
|
||||||
"image": "mesh-provision-redis@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-runtime-redis@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "redis",
|
"network": "redis",
|
||||||
"env": {
|
|
||||||
"GRANTS": "/var/lib/redis-module/grants",
|
|
||||||
"MESH_PROVISION_REDIS": "redis:6379",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
|
|
||||||
},
|
|
||||||
"volumes": [
|
"volumes": [
|
||||||
|
"/var/lib/mesh/redis/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
|
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
|
||||||
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
|
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
|
||||||
]
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
|
"MESH_RECEIVES": "/var/lib/redis-module/grants/mesh.json",
|
||||||
|
"MESH_PROVISION_REDIS": "redis:6379",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
+19
-12
@@ -4,7 +4,6 @@
|
|||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
|
|
||||||
"requires": [
|
"requires": [
|
||||||
"postgres-database"
|
"postgres-database"
|
||||||
],
|
],
|
||||||
@@ -19,7 +18,6 @@
|
|||||||
"secrets": {
|
"secrets": {
|
||||||
"postgres-database": "/var/lib/umami/database.secret"
|
"postgres-database": "/var/lib/umami/database.secret"
|
||||||
},
|
},
|
||||||
|
|
||||||
"provides": [
|
"provides": [
|
||||||
{
|
{
|
||||||
"name": "analytics",
|
"name": "analytics",
|
||||||
@@ -35,12 +33,11 @@
|
|||||||
"grants": {
|
"grants": {
|
||||||
"analytics": "/var/lib/umami/grants"
|
"analytics": "/var/lib/umami/grants"
|
||||||
},
|
},
|
||||||
|
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"app-secret": "/var/lib/umami/app.secret",
|
"app-secret": "/var/lib/umami/app.secret",
|
||||||
"admin": "/var/lib/umami/admin.secret"
|
"admin": "/var/lib/umami/admin.secret",
|
||||||
|
"broker": "/var/lib/mesh/umami/broker"
|
||||||
},
|
},
|
||||||
|
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
@@ -49,8 +46,13 @@
|
|||||||
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to — so the port itself must be reachable from anywhere"
|
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to — so the port itself must be reachable from anywhere"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|
||||||
"resources": [
|
"resources": [
|
||||||
|
{
|
||||||
|
"id": "mesh-state",
|
||||||
|
"type": "directory",
|
||||||
|
"path": "/var/lib/mesh/umami",
|
||||||
|
"mode": "0700"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -96,17 +98,22 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisioner",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-provision-umami-analytics",
|
"name": "mesh-umami",
|
||||||
"image": "mesh-provision-umami-analytics@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-runtime-umami@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "umami",
|
"network": "umami",
|
||||||
"env-file": [
|
|
||||||
"/var/lib/umami/provisioner.env"
|
|
||||||
],
|
|
||||||
"volumes": [
|
"volumes": [
|
||||||
|
"/var/lib/mesh/umami/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/umami/grants:/var/lib/umami/grants",
|
"/var/lib/umami/grants:/var/lib/umami/grants",
|
||||||
"/var/lib/umami/admin.secret:/run/secrets/admin:ro"
|
"/var/lib/umami/admin.secret:/run/secrets/admin:ro"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
|
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json"
|
||||||
|
},
|
||||||
|
"env-file": [
|
||||||
|
"/var/lib/umami/provisioner.env"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
Reference in New Issue
Block a user