From 6696445e61a1ec14c571bc8a4cbe8171038664ad Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 00:34:57 +0200 Subject: [PATCH] records: its consumer and tools run in the node's runtime (hq ADR 0198) The records container goes with its Dockerfile, build bases and bus credential. The checkout, the config file and the origin file are read where the mesh writes them, and git comes from the machine's git package instead of the image's apt layer. --- modules/records/Dockerfile | 26 ----------------- modules/records/module.json | 58 ++++++++++++------------------------- 2 files changed, 19 insertions(+), 65 deletions(-) delete mode 100644 modules/records/Dockerfile diff --git a/modules/records/Dockerfile b/modules/records/Dockerfile deleted file mode 100644 index 83a10c6..0000000 --- a/modules/records/Dockerfile +++ /dev/null @@ -1,26 +0,0 @@ -# records' runtime: the tool runtime, carrying this module's compiled reader and its tools. -# -# **Built from this module's own directory and nothing else.** The sdk is in the base image, so -# nothing is copied out of a neighbouring checkout (novox/hq ADR 0069). -# -# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in -# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/records -COPY . . -RUN node /app/node_modules/typescript/bin/tsc records.ts index.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -# **A module may need something the base image does not carry.** The reader keeps a checkout of the -# repository it reads (novox/hq ADR 0153) — a git working copy, kept current, not a derived copy — and -# the base image has no git. Certificates too, because the origin may be reached over TLS. -RUN apt-get update \ - && apt-get install -y --no-install-recommends git ca-certificates \ - && rm -rf /var/lib/apt/lists/* -COPY --from=build /app/modules/records/dist /app/modules/records/dist -# Both entrypoints, loaded in serve mode: the consumer that pulls on a merge, and the tools. -ENV MESH_TOOL_MODULES=/app/modules/records/dist/index.js,/app/modules/records/dist/tools/index.js diff --git a/modules/records/module.json b/modules/records/module.json index bf45d2f..f1f3c4e 100644 --- a/modules/records/module.json +++ b/modules/records/module.json @@ -11,9 +11,6 @@ "binds": { "git": "${dir:mesh-state}/git.json" }, - "own-secrets": { - "broker": "${dir:mesh-state}/broker" - }, "consumes": [ "gitea.pull.merged" ], @@ -53,47 +50,30 @@ "content": "${bound:git:scheme}://${bound:git:at}:${bound:git:port}\n" }, { - "id": "runtime", - "type": "container", - "name": "records", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro", - "${dir:mesh-state}/origin:/run/config/origin:ro", - "${dir:checkout}:${dir:checkout}" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECORDS_CONFIG_FILE": "/run/config/config.json", - "MESH_RECORDS_ORIGIN_FILE": "/run/config/origin", - "MESH_RECORDS_DIR": "${dir:checkout}" - }, - "artifact": "runtime", - "restart-on": [ - "config", - "origin" - ] + "id": "git", + "type": "package", + "package": "git" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "index.js", + "tools/index.js" + ], + "loads": [ + "index.js", + "tools/index.js" + ], + "env": { + "MESH_RECORDS_CONFIG_FILE": "${dir:mesh-state}/config.json", + "MESH_RECORDS_ORIGIN_FILE": "${dir:mesh-state}/origin", + "MESH_RECORDS_DIR": "${dir:checkout}" + } } ] }