redis: its handlers, tools and provisioner run in the node's runtime (hq ADR 0198)

The mesh-redis container goes with its Dockerfile, build bases, bus credential and the state directory only that credential lived in. The bundle reaches redis on the port this machine published rather than the container network's name.
This commit is contained in:
jochen
2026-10-03 23:33:50 +02:00
parent 7563569c8a
commit 1b27ce319a
2 changed files with 18 additions and 72 deletions
+18 -42
View File
@@ -35,9 +35,6 @@
"secrets": {
"secret": "${dir:state}/default.secret"
},
"own-secrets": {
"broker": "${dir:mesh-state}/broker"
},
"listens": [
{
"name": "cache",
@@ -48,12 +45,6 @@
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"mode": "0700",
"place": "mesh"
},
{
"id": "state",
"type": "directory",
@@ -103,44 +94,29 @@
"restart-on": [
"server-conf"
]
},
{
"id": "runtime",
"type": "container",
"name": "mesh-redis",
"network": "redis",
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:grants}:/var/lib/redis-module/grants:ro",
"${dir:state}/default.secret:/run/secrets/default:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/redis-module/grants/mesh.json",
"MESH_PROVISION_REDIS": "redis:6379",
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
},
"artifact": "runtime"
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"loads": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"env": {
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_PROVISION_REDIS": "127.0.0.1:${port:6379}",
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/default.secret"
}
}
]
}