Convert baserow, letta, invoicing to mesh catalog DB consumers

Mirror the postgres-consumer shape (keycloak/nextcloud): requires the
backing service(s), binds/secrets for the delivered credential, and a
server container that reads it from an interpolated env file.

- baserow: consumes postgres-database + redis-cache; tooled (dormant
  until an account is configured, like gitea's token).
- letta: consumes postgres-database; tooled, live via a mesh-minted
  server-password injected into both server and runtime.
- invoicing: consumes mongodb-database + s3-bucket; plain two-container
  service (app + api), no tools.

Digests pinned for baserow and letta; invoicing keeps private-registry
tags (DIGEST-UNRESOLVED). redis-cache and mongodb-database consumer
shapes are inferred (no prior consumer in the catalog).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-06 01:12:50 +02:00
parent 3b5f214f3d
commit 515b1e79c7
11 changed files with 660 additions and 0 deletions
+98
View File
@@ -0,0 +1,98 @@
{
"module": "invoicing",
"version": "1",
"capabilities": [
"container-runtime"
],
"requires": [
"mongodb-database",
"s3-bucket"
],
"contributes": {
"mongodb-database": {
"name": "invoicing"
},
"s3-bucket": {
"bucket": "invoicing"
}
},
"binds": {
"mongodb-database": "/var/lib/invoicing/database.json",
"s3-bucket": "/var/lib/invoicing/store.json"
},
"secrets": {
"mongodb-database": "/var/lib/invoicing/database.secret",
"s3-bucket": "/var/lib/invoicing/store.secret"
},
"listens": [
{
"port": 80,
"protocol": "tcp",
"from": "mesh",
"why": "the invoicing web frontend; a public name is a route grant later"
},
{
"port": 9000,
"protocol": "tcp",
"from": "mesh",
"why": "the invoicing REST API the frontend and integrations call"
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"path": "/var/lib/mesh/invoicing",
"mode": "0700"
},
{
"id": "state",
"type": "directory",
"path": "/var/lib/invoicing",
"mode": "0700"
},
{
"id": "api-env",
"type": "file",
"path": "/var/lib/invoicing/api.env",
"mode": "0600",
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/invoicing?authSource=admin\nMINIO_BUCKET=invoicing\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n"
},
{
"id": "net",
"type": "network",
"name": "invoicing"
},
{
"id": "app",
"type": "container",
"name": "invoicing-app",
"image": "registry-api.example/novox/invoicing-app:latest",
"network": "invoicing",
"env": {
"UID": "2201",
"GID": "2201"
},
"ports": [
"80"
]
},
{
"id": "api",
"type": "container",
"name": "invoicing-api",
"image": "registry-api.example/novox/invoicing-api:latest",
"network": "invoicing",
"env": {
"UID": "2201",
"GID": "2201"
},
"env-file": [
"/var/lib/invoicing/api.env"
],
"ports": [
"9000"
]
}
]
}