builder: consume package-registry as a real mesh grant, not a hand-faked one

The 'package-binding' resource was a hardcoded JSON fragment standing in
for a real grant — {"provision": "package-registry", "from": "gitea",
"at": "127.0.0.1", ...} written as if it were mesh-resolved, when nothing
resolved it. Declares requires: package-registry properly instead, with
binds/secrets pointing at the same file paths the resource used to
manually author, so the mesh mints the grant and writes it there.

npm-password renamed to package-registry.secret: it's gitea's generic
user+password, not npm-specific — the same credential works for basic
auth against cargo/PyPI/Go package endpoints too, once gitea's manifest
grows them (novox/hq ADR 0109).

Known gap, not fixed here (novox/hq issue 117): this makes builder
correct for the steady state but breaks a genesis bootstrap — gitea's own
image is built by builder, so builder cannot yet hold this grant the
first time either has to exist. Filed rather than silently accepted.
This commit is contained in:
2026-09-25 17:08:12 +02:00
parent 49c5903861
commit 755b0a5599
+12 -22
View File
@@ -11,14 +11,20 @@
}
],
"requires": [
"artifact-store"
"artifact-store",
"package-registry"
],
"binds": {
"package-registry": "/var/lib/mesh/builder/package-registry.json"
},
"secrets": {
"package-registry": "/var/lib/mesh/builder/package-registry.secret"
},
"emits": [
"module.builder.built"
],
"own-secrets": {
"broker": "/var/lib/mesh/builder/broker",
"npm-password": "/var/lib/mesh/builder/npm-password"
"broker": "/var/lib/mesh/builder/broker"
},
"resources": [
{
@@ -38,27 +44,13 @@
"type": "file",
"path": "/var/lib/mesh/builder/builder.env",
"mode": "0600",
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
},
{
"id": "package-binding",
"type": "file",
"path": "/var/lib/mesh/builder/package-registry.json",
"mode": "0600",
"merge": "json",
"protected": [
"provision",
"from",
"at",
"as"
],
"content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n"
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
},
{
"id": "server",
"type": "container",
"name": "mesh-builder",
"image": "mesh-builder@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"image": "mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704",
"env-file": [
"/var/lib/mesh/builder/builder.env"
],
@@ -68,9 +60,7 @@
"/var/run/docker.sock:/var/run/docker.sock"
],
"restart-on": [
"builder-env",
"package-binding",
"needs-npm-password"
"builder-env"
],
"network": "host"
}