From 35e8a3fe19bcef26e64a98c9e0c96e79a67771fb Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:55:49 +0200 Subject: [PATCH] minio: repin to pgsty's fork, build the runtime sidecar, move data off HAL's live drive MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit minio/minio and minio/mc were pulled from all public registries on 2026-09-11; pgsty's fork is the working replacement (hq issue 113). The runtime sidecar had no Dockerfile and no build section at all — added, following the same tsc-over-client/tools/provisioner shape every other converted module uses. The data resource pointed straight at /services/minio/data/data1-1, one of HAL's live 8-drive erasure-coded array — starting this module would have written into production storage the mesh doesn't own. Moved to a fresh, empty, mesh-owned directory; the actual data migration happens over the S3 API (rclone), not by sharing a disk path. --- modules/minio/Dockerfile | 28 ++++++++++++++++++++++++++++ modules/minio/module.json | 33 +++++++++++++++++++++++++++------ 2 files changed, 55 insertions(+), 6 deletions(-) create mode 100644 modules/minio/Dockerfile diff --git a/modules/minio/Dockerfile b/modules/minio/Dockerfile new file mode 100644 index 0000000..e5588e6 --- /dev/null +++ b/modules/minio/Dockerfile @@ -0,0 +1,28 @@ +# minio's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/minio +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/minio/dist /app/modules/minio/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. +ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js diff --git a/modules/minio/module.json b/modules/minio/module.json index 4fcb31d..bbca5d2 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -68,7 +68,7 @@ { "id": "data", "type": "directory", - "path": "/services/minio/data/data1-1", + "path": "/var/lib/minio-store", "mode": "0700" }, { @@ -80,7 +80,7 @@ "id": "server", "type": "container", "name": "minio", - "image": "quay.io/minio/minio@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e", + "image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372", "network": "minio", "args": [ "server", @@ -95,7 +95,7 @@ "9000" ], "volumes": [ - "/services/minio/data/data1-1:/data", + "/var/lib/minio-store:/data", "/var/lib/minio/root.secret:/run/secrets/root:ro" ], "env": { @@ -106,7 +106,6 @@ "id": "runtime", "type": "container", "name": "mesh-minio", - "image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "minio", "volumes": [ "/var/lib/mesh/minio/broker:/run/secrets/broker:ro", @@ -119,7 +118,29 @@ "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/minio/grants/mesh.json" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } }