diff --git a/modules/gitea/Dockerfile b/modules/gitea/Dockerfile index b0ac565..0c0eabf 100644 --- a/modules/gitea/Dockerfile +++ b/modules/gitea/Dockerfile @@ -34,4 +34,4 @@ COPY --from=build /app/modules/gitea/dist /app/modules/gitea/dist # separate entrypoints because they are loaded by different things. The provisioner is the third, # and is not listed here — the declaration names it in the container's `args`, because it is what # this module's own container runs. One image, because they are one module and share a client. -ENV MESH_TOOL_MODULES=/app/modules/gitea/dist/index.js,/app/modules/gitea/dist/tools/index.js +ENV MESH_TOOL_MODULES=/app/modules/gitea/dist/index.js,/app/modules/gitea/dist/tools/index.js,/app/modules/gitea/dist/provisioner/index.js diff --git a/modules/gitea/module.json b/modules/gitea/module.json index 54a9b46..31e7ade 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -167,10 +167,6 @@ "MESH_RECEIVES": "/var/lib/gitea/grants/mesh.json" }, "artifact": "runtime", - "args": [ - "run", - "/app/modules/gitea/dist/provisioner/index.js" - ], "restart-on": [ "runtime-config" ] diff --git a/modules/keycloak/Dockerfile b/modules/keycloak/Dockerfile new file mode 100644 index 0000000..c30eeba --- /dev/null +++ b/modules/keycloak/Dockerfile @@ -0,0 +1,30 @@ +# keycloak's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/keycloak +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/keycloak/dist /app/modules/keycloak/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/keycloak/dist/index.js,/app/modules/keycloak/dist/tools/index.js diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index fb11901..b14a087 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -110,7 +110,6 @@ "id": "runtime", "type": "container", "name": "mesh-keycloak", - "image": "mesh-runtime-keycloak@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "host", "volumes": [ "/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro", @@ -123,7 +122,29 @@ }, "restart-on": [ "runtime-config" - ] + ], + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/lavinmq/Dockerfile b/modules/lavinmq/Dockerfile index 2c022d9..dfbd207 100644 --- a/modules/lavinmq/Dockerfile +++ b/modules/lavinmq/Dockerfile @@ -38,4 +38,4 @@ COPY --from=build /app/modules/lavinmq/dist /app/modules/lavinmq/dist # provisioner are not listed here — the declaration names each in its container's `args`, because # they are what this module's own containers run. One image, because they are one module and share # a client. -ENV MESH_TOOL_MODULES=/app/modules/lavinmq/dist/index.js,/app/modules/lavinmq/dist/tools/index.js +ENV MESH_TOOL_MODULES=/app/modules/lavinmq/dist/index.js,/app/modules/lavinmq/dist/tools/index.js,/app/modules/lavinmq/dist/provisioner/index.js diff --git a/modules/lavinmq/module.json b/modules/lavinmq/module.json index 2a4b36e..a2afd95 100644 --- a/modules/lavinmq/module.json +++ b/modules/lavinmq/module.json @@ -107,11 +107,7 @@ "MESH_PROVISION_LAVINMQ": "http://127.0.0.1:15672", "MESH_PROVISION_ADMIN_USER": "guest", "MESH_LAVINMQ_ADMIN_PASSWORD": "guest" - }, - "args": [ - "run", - "/app/modules/lavinmq/dist/provisioner/index.js" - ] + } } ], "build": { diff --git a/modules/mailu/Dockerfile b/modules/mailu/Dockerfile new file mode 100644 index 0000000..b4c8a17 --- /dev/null +++ b/modules/mailu/Dockerfile @@ -0,0 +1,30 @@ +# mailu's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/mailu +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/mailu/dist /app/modules/mailu/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/mailu/dist/index.js,/app/modules/mailu/dist/tools/index.js diff --git a/modules/mailu/module.json b/modules/mailu/module.json index c7fea17..79a9c60 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -382,7 +382,6 @@ "id": "runtime", "type": "container", "name": "mesh-mailu", - "image": "mesh-runtime-mailu@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "mailu", "volumes": [ "/var/lib/mesh/mailu/broker:/run/secrets/broker:ro", @@ -399,7 +398,29 @@ }, "restart-on": [ "runtime-config" - ] + ], + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/minio/Dockerfile b/modules/minio/Dockerfile new file mode 100644 index 0000000..016bb77 --- /dev/null +++ b/modules/minio/Dockerfile @@ -0,0 +1,32 @@ +# minio's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/minio +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +# minio's client drives `mc` — copied from the official image, as the workstation build did. +COPY --from=minio/mc:latest /usr/bin/mc /usr/bin/mc +COPY --from=build /app/modules/minio/dist /app/modules/minio/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js diff --git a/modules/minio/module.json b/modules/minio/module.json index 185ff6a..457d7a0 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -102,7 +102,6 @@ "id": "runtime", "type": "container", "name": "mesh-minio", - "image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "minio", "volumes": [ "/var/lib/mesh/minio/broker:/run/secrets/broker:ro", @@ -115,7 +114,29 @@ "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/minio/grants/mesh.json" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/mongodb/Dockerfile b/modules/mongodb/Dockerfile new file mode 100644 index 0000000..05f3aef --- /dev/null +++ b/modules/mongodb/Dockerfile @@ -0,0 +1,37 @@ +# mongodb's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/mongodb +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +# mongodb's client shells out to `mongosh`, installed from MongoDB's own apt repo so its shared +# libraries come with it — copying the bare binary out of the mongo image leaves it unable to load. +RUN apt-get update && apt-get install -y --no-install-recommends gnupg curl ca-certificates \ + && curl -fsSL https://pgp.mongodb.com/server-7.0.asc | gpg --dearmor -o /usr/share/keyrings/mongodb.gpg \ + && echo "deb [signed-by=/usr/share/keyrings/mongodb.gpg] https://repo.mongodb.org/apt/debian bookworm/mongodb-org/7.0 main" > /etc/apt/sources.list.d/mongodb.list \ + && apt-get update && apt-get install -y --no-install-recommends mongodb-mongosh \ + && rm -rf /var/lib/apt/lists/* +COPY --from=build /app/modules/mongodb/dist /app/modules/mongodb/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/mongodb/dist/index.js,/app/modules/mongodb/dist/tools/index.js,/app/modules/mongodb/dist/provisioner/index.js diff --git a/modules/mongodb/module.json b/modules/mongodb/module.json index 6f7479e..bcd49f4 100644 --- a/modules/mongodb/module.json +++ b/modules/mongodb/module.json @@ -101,7 +101,6 @@ "id": "runtime", "type": "container", "name": "mesh-mongodb", - "image": "mesh-runtime-mongodb@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "mongodb", "volumes": [ "/var/lib/mesh/mongodb/broker:/run/secrets/broker:ro", @@ -113,7 +112,29 @@ "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/root", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/mongodb/grants/mesh.json" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/mssql/Dockerfile b/modules/mssql/Dockerfile new file mode 100644 index 0000000..20e878e --- /dev/null +++ b/modules/mssql/Dockerfile @@ -0,0 +1,30 @@ +# mssql's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/mssql +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/mssql/dist /app/modules/mssql/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/mssql/dist/index.js,/app/modules/mssql/dist/tools/index.js,/app/modules/mssql/dist/provisioner/index.js diff --git a/modules/mssql/module.json b/modules/mssql/module.json index 87d4708..cb516bc 100644 --- a/modules/mssql/module.json +++ b/modules/mssql/module.json @@ -97,7 +97,6 @@ "id": "runtime", "type": "container", "name": "mesh-mssql", - "image": "mesh-runtime-mssql@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "mssql", "volumes": [ "/var/lib/mesh/mssql/broker:/run/secrets/broker:ro", @@ -109,7 +108,29 @@ "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/sa", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/mssql/grants/mesh.json" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/nextcloud/Dockerfile b/modules/nextcloud/Dockerfile new file mode 100644 index 0000000..5a6e5a8 --- /dev/null +++ b/modules/nextcloud/Dockerfile @@ -0,0 +1,30 @@ +# nextcloud's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/nextcloud +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/nextcloud/dist/index.js,/app/modules/nextcloud/dist/tools/index.js diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index 8feaf75..ec67ae6 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -101,7 +101,6 @@ "id": "runtime", "type": "container", "name": "mesh-nextcloud", - "image": "mesh-runtime-nextcloud@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "host", "volumes": [ "/var/lib/mesh/nextcloud/broker:/run/secrets/broker:ro", @@ -115,7 +114,29 @@ }, "restart-on": [ "runtime-config" - ] + ], + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/portainer/Dockerfile b/modules/portainer/Dockerfile new file mode 100644 index 0000000..17820ac --- /dev/null +++ b/modules/portainer/Dockerfile @@ -0,0 +1,30 @@ +# portainer's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/portainer +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/portainer/dist /app/modules/portainer/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/portainer/dist/tools/index.js diff --git a/modules/portainer/module.json b/modules/portainer/module.json index f088bce..cb36c93 100644 --- a/modules/portainer/module.json +++ b/modules/portainer/module.json @@ -51,7 +51,6 @@ "id": "runtime", "type": "container", "name": "mesh-portainer", - "image": "mesh-runtime-portainer@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "host", "volumes": [ "/var/lib/mesh/portainer/broker:/run/secrets/broker:ro", @@ -64,10 +63,32 @@ }, "restart-on": [ "runtime-config" - ] + ], + "artifact": "runtime" } ], "own-secrets": { "broker": "/var/lib/mesh/portainer/broker" + }, + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] } } diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile index c8a2e36..818ada5 100644 --- a/modules/postgres/Dockerfile +++ b/modules/postgres/Dockerfile @@ -38,4 +38,4 @@ COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist # separate entrypoints because they are loaded by different things. The provisioner is the third, # and is not listed here — the declaration names it in the container's `args`, because it is what # this module's own container runs. One image, because they are one module and share a client. -ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js,/app/modules/postgres/dist/tools/index.js +ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js,/app/modules/postgres/dist/tools/index.js,/app/modules/postgres/dist/provisioner/index.js diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 6d27b72..4841894 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -98,11 +98,7 @@ "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json" }, - "artifact": "runtime", - "args": [ - "run", - "/app/modules/postgres/dist/provisioner/index.js" - ] + "artifact": "runtime" } ], "build": { diff --git a/modules/redis/Dockerfile b/modules/redis/Dockerfile new file mode 100644 index 0000000..2338a69 --- /dev/null +++ b/modules/redis/Dockerfile @@ -0,0 +1,30 @@ +# redis's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/redis +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/redis/dist /app/modules/redis/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/redis/dist/index.js,/app/modules/redis/dist/tools/index.js,/app/modules/redis/dist/provisioner/index.js diff --git a/modules/redis/module.json b/modules/redis/module.json index f50859d..22d2960 100644 --- a/modules/redis/module.json +++ b/modules/redis/module.json @@ -101,7 +101,6 @@ "id": "runtime", "type": "container", "name": "mesh-redis", - "image": "mesh-runtime-redis@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "redis", "volumes": [ "/var/lib/mesh/redis/broker:/run/secrets/broker:ro", @@ -113,7 +112,29 @@ "MESH_RECEIVES": "/var/lib/redis-module/grants/mesh.json", "MESH_PROVISION_REDIS": "redis:6379", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default" - } + }, + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/umami/Dockerfile b/modules/umami/Dockerfile new file mode 100644 index 0000000..2cf6a83 --- /dev/null +++ b/modules/umami/Dockerfile @@ -0,0 +1,30 @@ +# umami's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/umami +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/umami/dist /app/modules/umami/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/umami/dist/tools/index.js,/app/modules/umami/dist/provisioner/index.js diff --git a/modules/umami/module.json b/modules/umami/module.json index 761baa0..b7991e3 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -107,7 +107,6 @@ "id": "runtime", "type": "container", "name": "mesh-umami", - "image": "mesh-runtime-umami@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "umami", "volumes": [ "/var/lib/mesh/umami/broker:/run/secrets/broker:ro", @@ -121,7 +120,29 @@ }, "env-file": [ "/var/lib/umami/provisioner.env" - ] + ], + "artifact": "runtime" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } } diff --git a/modules/verdaccio/Dockerfile b/modules/verdaccio/Dockerfile new file mode 100644 index 0000000..ee4fec8 --- /dev/null +++ b/modules/verdaccio/Dockerfile @@ -0,0 +1,30 @@ +# verdaccio's runtime: the tool runtime, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in +# the base images, published like any other artifact — which is what makes this buildable by the +# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that +# happens to have the siblings. +# +# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the +# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the sdk it will run against. The compiler +# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image +# resolved away. +WORKDIR /app/modules/verdaccio +COPY . . +RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/verdaccio/dist /app/modules/verdaccio/dist +# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a +# provider's provisioner runs its reconcile loop in the same process, with the broker connected — +# the convention novox/hq issues 060/061 settled. A container that instead ran only its +# provisioner (`run`) served no tools and emitted no events; a container that named no command +# ran no provisioner at all. +ENV MESH_TOOL_MODULES=/app/modules/verdaccio/dist/index.js,/app/modules/verdaccio/dist/tools/index.js diff --git a/modules/verdaccio/module.json b/modules/verdaccio/module.json index 3c52bd8..8cd1a06 100644 --- a/modules/verdaccio/module.json +++ b/modules/verdaccio/module.json @@ -72,7 +72,6 @@ "id": "runtime", "type": "container", "name": "mesh-verdaccio", - "image": "mesh-runtime-verdaccio@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "host", "volumes": [ "/var/lib/mesh/verdaccio/broker:/run/secrets/broker:ro", @@ -85,7 +84,8 @@ }, "restart-on": [ "runtime-config" - ] + ], + "artifact": "runtime" } ], "requires": [ @@ -105,5 +105,26 @@ "name": "package-registry", "scope": "mesh" } - ] + ], + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + } }