diff --git a/modules/audit-logger/Dockerfile b/modules/audit-logger/Dockerfile new file mode 100644 index 0000000..f95c9ed --- /dev/null +++ b/modules/audit-logger/Dockerfile @@ -0,0 +1,33 @@ +# audit-logger's runtime: the shared runtime image, carrying this module's compiled code. +# +# **Built from this module's own directory and nothing else.** The toolkit is in the base image, so +# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a +# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have +# the siblings laid out beside it. + +# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in. +# They are different images on purpose — the first carries a compiler and the second must not, or +# every running container would carry one it never invokes. The mesh answers both with the copies it +# holds, because a fingerprint written here would name one particular copy and no other mesh has it +# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults, so a build +# nobody told stops here and says which module to build first. +ARG BUILD_BASE +ARG RUNTIME_BASE + +FROM ${BUILD_BASE} AS build +# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own +# node_modules — the module is compiled against exactly the toolkit it will run against. +WORKDIR /app/modules/audit-logger +COPY . . +# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are +# symlinks to a launcher that requires its library relatively — resolved away when the base image +# was assembled. +RUN node /app/node_modules/typescript/bin/tsc audit.ts index.ts \ + --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist + +FROM ${RUNTIME_BASE} +COPY --from=build /app/modules/audit-logger/dist /app/modules/audit-logger/dist +# **Served, not run.** This subscribes on import, and the serve mode binds the broker before it +# imports anything — `run` exists for a step that works offline and exits, and would leave this +# with nothing to subscribe to. +ENV MESH_TOOL_MODULES=/app/modules/audit-logger/dist/index.js diff --git a/modules/audit-logger/module.json b/modules/audit-logger/module.json index 509cbee..1b8bfa8 100644 --- a/modules/audit-logger/module.json +++ b/modules/audit-logger/module.json @@ -2,10 +2,33 @@ "module": "audit-logger", "version": "1", "slug": "audit", - "consumes": ["#"], + "consumes": [ + "#" + ], "own-secrets": { "broker": "/var/lib/audit-logger/broker" }, + "build": { + "on": [ + { + "arg": "BUILD_BASE", + "module": "mesh-tools", + "artifact": "build" + }, + { + "arg": "RUNTIME_BASE", + "module": "mesh-tools", + "artifact": "runtime" + } + ], + "artifacts": [ + { + "name": "runtime", + "kind": "image", + "from": "Dockerfile" + } + ] + }, "resources": [ { "id": "state", @@ -23,7 +46,6 @@ "id": "run", "type": "container", "name": "mesh-audit-logger", - "image": "mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000", "network": "host", "volumes": [ "/var/lib/audit-logger/broker:/run/secrets/broker:ro", @@ -32,7 +54,8 @@ "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "AUDIT_LOG": "/trail/audit.log" - } + }, + "artifact": "runtime" } ] }