Convert baserow, letta, invoicing to mesh catalog DB consumers

Mirror the postgres-consumer shape (keycloak/nextcloud): requires the
backing service(s), binds/secrets for the delivered credential, and a
server container that reads it from an interpolated env file.

- baserow: consumes postgres-database + redis-cache; tooled (dormant
  until an account is configured, like gitea's token).
- letta: consumes postgres-database; tooled, live via a mesh-minted
  server-password injected into both server and runtime.
- invoicing: consumes mongodb-database + s3-bucket; plain two-container
  service (app + api), no tools.

Digests pinned for baserow and letta; invoicing keeps private-registry
tags (DIGEST-UNRESOLVED). redis-cache and mongodb-database consumer
shapes are inferred (no prior consumer in the catalog).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-06 01:12:50 +02:00
parent 3b5f214f3d
commit 515b1e79c7
11 changed files with 660 additions and 0 deletions
+85
View File
@@ -0,0 +1,85 @@
// The Letta API client — letta's own code, living in the module (novox/hq ADR 0039). Its tools
// import it; nothing outside letta does.
//
// Letta authenticates with a single server password, presented as a Bearer token. That password is
// a mesh own-secret, minted once and handed to both the server (LETTA_SERVER_PASSWORD) and this
// client (MESH_LETTA_PASSWORD) — so the module's tools are live without anything configured by hand.
// The runtime config file may still override the URL or password.
import { readFileSync } from "node:fs";
export interface LettaAgent {
id: string;
name: string;
}
export interface LettaMessage {
id?: string;
role?: string;
text?: string;
[key: string]: unknown;
}
function meshConfig(file?: string): Record<string, string> {
if (!file) return {};
try {
return JSON.parse(readFileSync(file, "utf8")) as Record<string, string>;
} catch {
return {};
}
}
export class LettaClient {
readonly baseUrl: string;
constructor(
url: string,
private readonly password: string,
) {
this.baseUrl = url.replace(/\/+$/, "");
}
/**
* Build from the module's resolved environment. URL and password come from the runtime config
* file first (MESH_LETTA_CONFIG_FILE), then the mesh's own names, then the bare LETTA_* names. A
* password is required — Letta rejects unauthenticated calls when SECURE is on — so this throws
* rather than hand back a client that fails on first use.
*/
static fromEnv(env: NodeJS.ProcessEnv = process.env): LettaClient {
const cfg = meshConfig(env.MESH_LETTA_CONFIG_FILE);
const url = cfg.url ?? env.MESH_LETTA_URL ?? env.LETTA_URL ?? "http://127.0.0.1:8283";
const password = cfg.password ?? env.MESH_LETTA_PASSWORD ?? env.LETTA_SERVER_PASSWORD;
if (!password) throw new Error("no Letta password — set MESH_LETTA_PASSWORD");
return new LettaClient(url, password);
}
private async request<T = unknown>(path: string, options: RequestInit = {}): Promise<T> {
const res = await fetch(`${this.baseUrl}${path}`, {
...options,
headers: {
"Content-Type": "application/json",
Authorization: `Bearer ${this.password}`,
...(options.headers as Record<string, string> | undefined),
},
});
if (!res.ok) throw new Error(`letta ${path}: ${res.status} ${await res.text()}`);
if (res.status === 204) return null as T;
const text = await res.text();
return (text ? JSON.parse(text) : null) as T;
}
async listAgents(): Promise<LettaAgent[]> {
return (await this.request<LettaAgent[]>(`/v1/agents/`)) ?? [];
}
async getMessages(agentId: string, limit = 20): Promise<LettaMessage[]> {
return (await this.request<LettaMessage[]>(`/v1/agents/${agentId}/messages?limit=${limit}`)) ?? [];
}
async sendMessage(agentId: string, text: string): Promise<unknown> {
return this.request(`/v1/agents/${agentId}/messages`, {
method: "POST",
body: JSON.stringify({ messages: [{ role: "user", content: text }] }),
});
}
}
+109
View File
@@ -0,0 +1,109 @@
{
"module": "letta",
"version": "1",
"capabilities": [
"container-runtime"
],
"requires": [
"postgres-database"
],
"contributes": {
"postgres-database": {
"name": "letta"
}
},
"binds": {
"postgres-database": "/var/lib/letta/database.json"
},
"secrets": {
"postgres-database": "/var/lib/letta/database.secret"
},
"own-secrets": {
"server-password": "/var/lib/letta/server-password.secret",
"broker": "/var/lib/mesh/letta/broker"
},
"listens": [
{
"port": 8283,
"protocol": "tcp",
"from": "mesh",
"why": "the Letta agent server REST API and web UI; a public name is a route grant later"
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"path": "/var/lib/mesh/letta",
"mode": "0700"
},
{
"id": "state",
"type": "directory",
"path": "/var/lib/letta",
"mode": "0700"
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/letta/server.env",
"mode": "0600",
"content": "LETTA_PG_URI=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/letta\nLETTA_SERVER_PASSWORD=${secret:server-password}\nSECURE=true\nTZ=Europe/Brussels\n"
},
{
"id": "net",
"type": "network",
"name": "letta"
},
{
"id": "server",
"type": "container",
"name": "letta",
"image": "letta/letta@sha256:1d2e0692514287c5ed1a483e14e16ed945f8632d315539f5e66373bb7d7c471b",
"network": "letta",
"env-file": [
"/var/lib/letta/server.env"
],
"ports": [
"8283"
]
},
{
"id": "runtime-config",
"type": "file",
"path": "/var/lib/mesh/letta/config.json",
"mode": "0600",
"content": "{}\n",
"merge": "json"
},
{
"id": "runtime-env",
"type": "file",
"path": "/var/lib/letta/runtime.env",
"mode": "0600",
"content": "MESH_LETTA_PASSWORD=${secret:server-password}\n"
},
{
"id": "runtime",
"type": "container",
"name": "mesh-letta",
"image": "mesh-runtime-letta@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "letta",
"volumes": [
"/var/lib/mesh/letta/broker:/run/secrets/broker:ro",
"/var/lib/mesh/letta/config.json:/run/config/config.json:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_LETTA_URL": "http://letta:8283",
"MESH_LETTA_CONFIG_FILE": "/run/config/config.json"
},
"env-file": [
"/var/lib/letta/runtime.env"
],
"restart-on": [
"runtime-config"
]
}
]
}
+14
View File
@@ -0,0 +1,14 @@
{
"name": "@novox/module-letta",
"version": "0.1.0",
"description": "letta — AI agent framework. A consumer of a mesh Postgres database, with its own tools (novox/hq ADR 0039).",
"type": "module",
"private": true,
"dependencies": {
"@novox/mesh-sdk": "^0.1.0"
},
"devDependencies": {
"@types/node": "^22.0.0",
"typescript": "^5.6.0"
}
}
+51
View File
@@ -0,0 +1,51 @@
// letta's tools — letta's own code (novox/hq ADR 0039). They import letta's own client (../client)
// and plug into the mesh through the sdk's tool harness. Editing them rebuilds letta and nothing
// else. Absent a password they yield no tools rather than a failure.
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
import { LettaClient } from "../client.js";
export function getLettaTools(letta: LettaClient): ToolDefinition[] {
return [
{
name: "letta_list_agents",
description: "List the Letta agents on the server.",
input: {},
run: async () => ({ agents: await letta.listAgents() }),
},
{
name: "letta_get_messages",
description: "Fetch recent messages from a Letta agent's conversation.",
input: {
agent_id: { type: "string", description: "the agent id" },
limit: { type: "number", description: "max messages to return (default 20)" },
},
run: async (args) => {
const agentId = String(args.agent_id);
const limit = args.limit ? Number(args.limit) : 20;
return { messages: await letta.getMessages(agentId, limit) };
},
},
{
name: "letta_send_message",
description: "Send a user message to a Letta agent and return its reply.",
input: {
agent_id: { type: "string", description: "the agent id" },
text: { type: "string", description: "the message to send" },
},
run: async (args) => {
const agentId = String(args.agent_id);
const text = String(args.text);
return { reply: await letta.sendMessage(agentId, text) };
},
},
];
}
registerModuleTools("letta", (env) => {
try {
return getLettaTools(LettaClient.fromEnv(env));
} catch {
return [];
}
});
+12
View File
@@ -0,0 +1,12 @@
{
"compilerOptions": {
"target": "ES2022",
"module": "NodeNext",
"moduleResolution": "NodeNext",
"strict": true,
"esModuleInterop": true,
"skipLibCheck": true,
"noEmit": true
},
"include": ["client.ts", "tools/index.ts"]
}