builder: consume package-registry as a real mesh grant, not a hand-faked one
The 'package-binding' resource was a hardcoded JSON fragment standing in
for a real grant — {"provision": "package-registry", "from": "gitea",
"at": "127.0.0.1", ...} written as if it were mesh-resolved, when nothing
resolved it. Declares requires: package-registry properly instead, with
binds/secrets pointing at the same file paths the resource used to
manually author, so the mesh mints the grant and writes it there.
npm-password renamed to package-registry.secret: it's gitea's generic
user+password, not npm-specific — the same credential works for basic
auth against cargo/PyPI/Go package endpoints too, once gitea's manifest
grows them (novox/hq ADR 0109).
Known gap, not fixed here (novox/hq issue 117): this makes builder
correct for the steady state but breaks a genesis bootstrap — gitea's own
image is built by builder, so builder cannot yet hold this grant the
first time either has to exist. Filed rather than silently accepted.
This commit is contained in:
+12
-22
@@ -11,14 +11,20 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
"artifact-store"
|
"artifact-store",
|
||||||
|
"package-registry"
|
||||||
],
|
],
|
||||||
|
"binds": {
|
||||||
|
"package-registry": "/var/lib/mesh/builder/package-registry.json"
|
||||||
|
},
|
||||||
|
"secrets": {
|
||||||
|
"package-registry": "/var/lib/mesh/builder/package-registry.secret"
|
||||||
|
},
|
||||||
"emits": [
|
"emits": [
|
||||||
"module.builder.built"
|
"module.builder.built"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/builder/broker",
|
"broker": "/var/lib/mesh/builder/broker"
|
||||||
"npm-password": "/var/lib/mesh/builder/npm-password"
|
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
@@ -38,27 +44,13 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/builder/builder.env",
|
"path": "/var/lib/mesh/builder/builder.env",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
|
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "package-binding",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/mesh/builder/package-registry.json",
|
|
||||||
"mode": "0600",
|
|
||||||
"merge": "json",
|
|
||||||
"protected": [
|
|
||||||
"provision",
|
|
||||||
"from",
|
|
||||||
"at",
|
|
||||||
"as"
|
|
||||||
],
|
|
||||||
"content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-builder",
|
"name": "mesh-builder",
|
||||||
"image": "mesh-builder@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
"image": "mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704",
|
||||||
"env-file": [
|
"env-file": [
|
||||||
"/var/lib/mesh/builder/builder.env"
|
"/var/lib/mesh/builder/builder.env"
|
||||||
],
|
],
|
||||||
@@ -68,9 +60,7 @@
|
|||||||
"/var/run/docker.sock:/var/run/docker.sock"
|
"/var/run/docker.sock:/var/run/docker.sock"
|
||||||
],
|
],
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
"builder-env",
|
"builder-env"
|
||||||
"package-binding",
|
|
||||||
"needs-npm-password"
|
|
||||||
],
|
],
|
||||||
"network": "host"
|
"network": "host"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user