Migrate audit-logger: it builds itself now

The first module moved onto the new build process. It named a placeholder digest
nothing could produce, so it only ever worked where somebody had pre-built its
image by hand. It names the two shared bases instead, and the mesh builds it.

Chosen first deliberately: it requires nothing, nothing requires it, and an
audit trail of every event on the mesh is the thing most worth having while
modules are being moved one at a time.
This commit is contained in:
2026-09-14 12:58:30 +02:00
parent 071afc1e2c
commit 680b91546c
2 changed files with 59 additions and 3 deletions
+26 -3
View File
@@ -2,10 +2,33 @@
"module": "audit-logger",
"version": "1",
"slug": "audit",
"consumes": ["#"],
"consumes": [
"#"
],
"own-secrets": {
"broker": "/var/lib/audit-logger/broker"
},
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
},
"resources": [
{
"id": "state",
@@ -23,7 +46,6 @@
"id": "run",
"type": "container",
"name": "mesh-audit-logger",
"image": "mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
@@ -32,7 +54,8 @@
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"AUDIT_LOG": "/trail/audit.log"
}
},
"artifact": "runtime"
}
]
}