From 1b27ce319a3099648485cc3eda11734475ad068f Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 23:33:50 +0200 Subject: [PATCH] redis: its handlers, tools and provisioner run in the node's runtime (hq ADR 0198) The mesh-redis container goes with its Dockerfile, build bases, bus credential and the state directory only that credential lived in. The bundle reaches redis on the port this machine published rather than the container network's name. --- modules/redis/Dockerfile | 30 -------------------- modules/redis/module.json | 60 ++++++++++++--------------------------- 2 files changed, 18 insertions(+), 72 deletions(-) delete mode 100644 modules/redis/Dockerfile diff --git a/modules/redis/Dockerfile b/modules/redis/Dockerfile deleted file mode 100644 index 2338a69..0000000 --- a/modules/redis/Dockerfile +++ /dev/null @@ -1,30 +0,0 @@ -# redis's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own -# node_modules — the module is compiled against exactly the sdk it will run against. The compiler -# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image -# resolved away. -WORKDIR /app/modules/redis -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/redis/dist /app/modules/redis/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. A container that instead ran only its -# provisioner (`run`) served no tools and emitted no events; a container that named no command -# ran no provisioner at all. -ENV MESH_TOOL_MODULES=/app/modules/redis/dist/index.js,/app/modules/redis/dist/tools/index.js,/app/modules/redis/dist/provisioner/index.js diff --git a/modules/redis/module.json b/modules/redis/module.json index 646a8df..0736848 100644 --- a/modules/redis/module.json +++ b/modules/redis/module.json @@ -35,9 +35,6 @@ "secrets": { "secret": "${dir:state}/default.secret" }, - "own-secrets": { - "broker": "${dir:mesh-state}/broker" - }, "listens": [ { "name": "cache", @@ -48,12 +45,6 @@ } ], "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -103,44 +94,29 @@ "restart-on": [ "server-conf" ] - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-redis", - "network": "redis", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:grants}:/var/lib/redis-module/grants:ro", - "${dir:state}/default.secret:/run/secrets/default:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/redis-module/grants/mesh.json", - "MESH_PROVISION_REDIS": "redis:6379", - "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default" - }, - "artifact": "runtime" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "loads": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "env": { + "MESH_RECEIVES": "${dir:grants}/mesh.json", + "MESH_PROVISION_REDIS": "127.0.0.1:${port:6379}", + "MESH_PROVISION_PASSWORD_FILE": "${dir:state}/default.secret" + } } ] }