records: its consumer and tools run in the node's runtime (hq ADR 0198)

The records container goes with its Dockerfile, build bases and bus credential. The checkout, the config file and the origin file are read where the mesh writes them, and git comes from the machine's git package instead of the image's apt layer.
This commit is contained in:
jochen
2026-10-04 00:34:57 +02:00
parent e189b743bd
commit 6696445e61
2 changed files with 19 additions and 65 deletions
+19 -39
View File
@@ -11,9 +11,6 @@
"binds": {
"git": "${dir:mesh-state}/git.json"
},
"own-secrets": {
"broker": "${dir:mesh-state}/broker"
},
"consumes": [
"gitea.pull.merged"
],
@@ -53,47 +50,30 @@
"content": "${bound:git:scheme}://${bound:git:at}:${bound:git:port}\n"
},
{
"id": "runtime",
"type": "container",
"name": "records",
"network": "host",
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
"${dir:mesh-state}/origin:/run/config/origin:ro",
"${dir:checkout}:${dir:checkout}"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECORDS_CONFIG_FILE": "/run/config/config.json",
"MESH_RECORDS_ORIGIN_FILE": "/run/config/origin",
"MESH_RECORDS_DIR": "${dir:checkout}"
},
"artifact": "runtime",
"restart-on": [
"config",
"origin"
]
"id": "git",
"type": "package",
"package": "git"
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js"
],
"loads": [
"index.js",
"tools/index.js"
],
"env": {
"MESH_RECORDS_CONFIG_FILE": "${dir:mesh-state}/config.json",
"MESH_RECORDS_ORIGIN_FILE": "${dir:mesh-state}/origin",
"MESH_RECORDS_DIR": "${dir:checkout}"
}
}
]
}