diff --git a/modules/minio/Dockerfile b/modules/minio/Dockerfile new file mode 100644 index 0000000..e5588e6 --- /dev/null +++ b/modules/minio/Dockerfile @@ -0,0 +1,28 @@ +# minio's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/minio +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/minio/dist /app/modules/minio/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. +ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js diff --git a/modules/minio/module.json b/modules/minio/module.json index 4fcb31d..bbca5d2 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -68,7 +68,7 @@ { "id": "data", "type": "directory", - "path": "/services/minio/data/data1-1", + "path": "/var/lib/minio-store", "mode": "0700" }, { @@ -80,7 +80,7 @@ "id": "server", "type": "container", "name": "minio", - "image": "quay.io/minio/minio@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e", + "image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372", "network": "minio", "args": [ "server", @@ -95,7 +95,7 @@ "9000" ], "volumes": [ - "/services/minio/data/data1-1:/data", + "/var/lib/minio-store:/data", "/var/lib/minio/root.secret:/run/secrets/root:ro" ], "env": { @@ -106,7 +106,6 @@ "id": "runtime", "type": "container", "name": "mesh-minio", - "image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "minio", "volumes": [ "/var/lib/mesh/minio/broker:/run/secrets/broker:ro", @@ -119,7 +118,29 @@ "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/minio/grants/mesh.json" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } }