Rename seat claims to the mesh-*/node-* convention; retire verdaccio (ADR 0121)
Claims renamed to match the controller's seat set: node-dns-resolver (dnsmasq), node-intrusion-prevention (fail2ban), node-packet-filter (nftables), node-resolver-config (resolv-conf, resolved-split-dns), node-uplink (networkmanager, systemd-networkd, dhcpcd), mesh-build-machine (builder, +mesh scope), mesh-catalog (mesh-catalog). showcase now declares its own seat and claims it. verdaccio removed — the mesh keeps distribution as its registry and gitea already serves npm, so a second npm registry is redundant.
This commit is contained in:
+182
-59
@@ -2,72 +2,195 @@
|
||||
"module": "showcase",
|
||||
"version": "1",
|
||||
"slug": "show",
|
||||
|
||||
"capabilities": ["container-runtime"],
|
||||
|
||||
"provides": [{ "name": "greeting", "scope": "mesh" }],
|
||||
"serves": { "greeting": { "path": "/greeting" } },
|
||||
"requires": ["postgres-database"],
|
||||
"binds": { "postgres-database": "/var/lib/showcase/database.json" },
|
||||
"secrets": { "postgres-database": "/var/lib/showcase/database.secret" },
|
||||
"own-secrets": { "broker": "/var/lib/mesh/showcase/broker" },
|
||||
|
||||
"claims": [{ "name": "the-showcase", "scope": "node" }],
|
||||
|
||||
"emits": ["module.showcase.acknowledged"],
|
||||
"consumes": ["module.showcase.greeted"],
|
||||
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"provides": [
|
||||
{
|
||||
"name": "greeting",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"greeting": {
|
||||
"path": "/greeting"
|
||||
}
|
||||
},
|
||||
"requires": [
|
||||
"postgres-database"
|
||||
],
|
||||
"binds": {
|
||||
"postgres-database": "/var/lib/showcase/database.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "/var/lib/showcase/database.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/showcase/broker"
|
||||
},
|
||||
"claims": [
|
||||
{
|
||||
"name": "the-showcase",
|
||||
"scope": "node"
|
||||
}
|
||||
],
|
||||
"emits": [
|
||||
"module.showcase.acknowledged"
|
||||
],
|
||||
"consumes": [
|
||||
"module.showcase.greeted"
|
||||
],
|
||||
"listens": [
|
||||
{ "port": 8080, "protocol": "tcp", "from": "mesh",
|
||||
"why": "the port the daemon itself listens on. The mesh assigns the machine-side number and tells consumers that one (ADR 0038)" }
|
||||
{
|
||||
"port": 8080,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the port the daemon itself listens on. The mesh assigns the machine-side number and tells consumers that one (ADR 0038)"
|
||||
}
|
||||
],
|
||||
|
||||
"build": {
|
||||
"artifacts": [
|
||||
{ "name": "code", "kind": "bundle", "language": "typescript",
|
||||
"entrypoints": ["index.js", "tools/index.js", "provisioner/index.js",
|
||||
"daemon/index.js", "step/index.js", "report/index.js"] },
|
||||
{ "name": "files", "kind": "archive", "from": "files" },
|
||||
{ "name": "helper", "kind": "upstream",
|
||||
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b" }
|
||||
{
|
||||
"name": "code",
|
||||
"kind": "bundle",
|
||||
"language": "typescript",
|
||||
"entrypoints": [
|
||||
"index.js",
|
||||
"tools/index.js",
|
||||
"provisioner/index.js",
|
||||
"daemon/index.js",
|
||||
"step/index.js",
|
||||
"report/index.js"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "files",
|
||||
"kind": "archive",
|
||||
"from": "files"
|
||||
},
|
||||
{
|
||||
"name": "helper",
|
||||
"kind": "upstream",
|
||||
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b"
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
"resources": [
|
||||
{ "id": "account", "type": "user", "name": "showcase", "shell": "/usr/bin/nologin",
|
||||
"home": "/var/lib/showcase" },
|
||||
|
||||
{ "id": "logs", "type": "access", "path": "/var/log", "mode": "0755" },
|
||||
|
||||
{ "id": "mesh-state", "type": "directory", "path": "/var/lib/mesh/showcase", "mode": "0700" },
|
||||
{ "id": "state", "type": "directory", "path": "/var/lib/showcase", "mode": "0755" },
|
||||
|
||||
{ "id": "settings", "type": "file", "path": "/var/lib/showcase/showcase.env", "mode": "0600",
|
||||
"content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n" },
|
||||
|
||||
{ "id": "packed", "type": "archive", "path": "/opt/showcase", "artifact": "files" },
|
||||
|
||||
{ "id": "net", "type": "network", "name": "showcase" },
|
||||
|
||||
{ "id": "tooling", "type": "package", "package": "jq" },
|
||||
|
||||
{ "id": "migrate", "type": "process", "name": "showcase-migrate", "artifact": "code",
|
||||
"run": ["node", "step/index.js"], "run-once": true,
|
||||
"env-file": ["/var/lib/showcase/showcase.env"] },
|
||||
|
||||
{ "id": "server", "type": "process", "name": "showcase", "artifact": "code",
|
||||
"run": ["node", "daemon/index.js"], "user": "showcase",
|
||||
"env-file": ["/var/lib/showcase/showcase.env"],
|
||||
"restart-on": ["settings"] },
|
||||
|
||||
{ "id": "reporting", "type": "process", "name": "showcase-report", "artifact": "code",
|
||||
"run": ["node", "report/index.js"], "schedule": "0 3 * * *",
|
||||
"env-file": ["/var/lib/showcase/showcase.env"] },
|
||||
|
||||
{ "id": "tools", "type": "container", "name": "mesh-showcase", "artifact": "helper",
|
||||
{
|
||||
"id": "account",
|
||||
"type": "user",
|
||||
"name": "showcase",
|
||||
"shell": "/usr/bin/nologin",
|
||||
"home": "/var/lib/showcase"
|
||||
},
|
||||
{
|
||||
"id": "logs",
|
||||
"type": "access",
|
||||
"path": "/var/log",
|
||||
"mode": "0755"
|
||||
},
|
||||
{
|
||||
"id": "mesh-state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh/showcase",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/showcase",
|
||||
"mode": "0755"
|
||||
},
|
||||
{
|
||||
"id": "settings",
|
||||
"type": "file",
|
||||
"path": "/var/lib/showcase/showcase.env",
|
||||
"mode": "0600",
|
||||
"content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n"
|
||||
},
|
||||
{
|
||||
"id": "packed",
|
||||
"type": "archive",
|
||||
"path": "/opt/showcase",
|
||||
"artifact": "files"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
"type": "network",
|
||||
"name": "showcase"
|
||||
},
|
||||
{
|
||||
"id": "tooling",
|
||||
"type": "package",
|
||||
"package": "jq"
|
||||
},
|
||||
{
|
||||
"id": "migrate",
|
||||
"type": "process",
|
||||
"name": "showcase-migrate",
|
||||
"artifact": "code",
|
||||
"run": [
|
||||
"node",
|
||||
"step/index.js"
|
||||
],
|
||||
"run-once": true,
|
||||
"env-file": [
|
||||
"/var/lib/showcase/showcase.env"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "process",
|
||||
"name": "showcase",
|
||||
"artifact": "code",
|
||||
"run": [
|
||||
"node",
|
||||
"daemon/index.js"
|
||||
],
|
||||
"user": "showcase",
|
||||
"env-file": [
|
||||
"/var/lib/showcase/showcase.env"
|
||||
],
|
||||
"restart-on": [
|
||||
"settings"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "reporting",
|
||||
"type": "process",
|
||||
"name": "showcase-report",
|
||||
"artifact": "code",
|
||||
"run": [
|
||||
"node",
|
||||
"report/index.js"
|
||||
],
|
||||
"schedule": "0 3 * * *",
|
||||
"env-file": [
|
||||
"/var/lib/showcase/showcase.env"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "tools",
|
||||
"type": "container",
|
||||
"name": "mesh-showcase",
|
||||
"artifact": "helper",
|
||||
"network": "showcase",
|
||||
"volumes": ["/var/lib/mesh/showcase/broker:/run/secrets/broker:ro"],
|
||||
"env": { "MESH_BROKER_FILE": "/run/secrets/broker" },
|
||||
"args": ["sleep", "infinity"] }
|
||||
"volumes": [
|
||||
"/var/lib/mesh/showcase/broker:/run/secrets/broker:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker"
|
||||
},
|
||||
"args": [
|
||||
"sleep",
|
||||
"infinity"
|
||||
]
|
||||
}
|
||||
],
|
||||
"seats": [
|
||||
{
|
||||
"name": "the-showcase",
|
||||
"scope": "node"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user