From 7563569c8a118c5efee876adc3f7ab257f9dcab6 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 23:33:50 +0200 Subject: [PATCH] postgres: its handlers, tools and provisioner run in the node's runtime (hq ADR 0198) The mesh-postgres container goes with its Dockerfile, build bases and bus credential: its three entrypoints are loads of one bundle, given their words as host paths, and psql comes from postgresql-libs instead of the image's apt layer. The seat word is dropped, since a bundle's words cannot carry one and the client treats it as optional. --- modules/postgres/Dockerfile | 41 ----------------------- modules/postgres/module.json | 63 +++++++++++++----------------------- 2 files changed, 22 insertions(+), 82 deletions(-) delete mode 100644 modules/postgres/Dockerfile diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile deleted file mode 100644 index 818ada5..0000000 --- a/modules/postgres/Dockerfile +++ /dev/null @@ -1,41 +0,0 @@ -# postgres's runtime: the tool runtime, carrying this module's compiled provisioner, tools and -# event consumer. -# -# **Built from this module's own directory and nothing else.** The sdk is in the base image, so -# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a -# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have -# the siblings. -# -# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in. -# They are different images on purpose — the first carries a compiler and the second must not, or -# every running container would carry one it never invokes. The mesh answers both with the copies it -# holds, because a fingerprint written here would name one particular copy and no other mesh has it -# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults, so a build -# nobody told stops here and says which module to build first. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own -# node_modules — the module is compiled against exactly the sdk it will run against. -WORKDIR /app/modules/postgres -COPY . . -# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are -# symlinks to a launcher that requires its library relatively — resolved away when the base image -# was assembled. -RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -# **This module talks to its database through psql, so psql has to be here.** The client is how -# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only -# what every module needs. -RUN apt-get update \ - && apt-get install -y --no-install-recommends postgresql-client \ - && rm -rf /var/lib/apt/lists/* -COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist -# What a tool host should load from this module: its event consumer and its tools, which are -# separate entrypoints because they are loaded by different things. The provisioner is the third, -# and is not listed here — the declaration names it in the container's `args`, because it is what -# this module's own container runs. One image, because they are one module and share a client. -ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js,/app/modules/postgres/dist/tools/index.js,/app/modules/postgres/dist/provisioner/index.js diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 98da700..f25d84d 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -53,16 +53,9 @@ }, "own-secrets": { "superuser": "${dir:state}/superuser.secret", - "broker": "${dir:mesh-state}/broker", "reader": "${dir:state}/reader.secret" }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -99,45 +92,33 @@ ] }, { - "id": "runtime", - "type": "container", - "name": "mesh-postgres", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:grants}:${dir:grants}:ro", - "${dir:state}/superuser.secret:/run/secrets/superuser:ro", - "${dir:state}/reader.secret:/run/secrets/reader:ro" - ], - "env": { - "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable", - "MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}", - "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "${dir:grants}/mesh.json", - "MESH_POSTGRES_READER_PASSWORD_FILE": "/run/secrets/reader" - }, - "artifact": "runtime" + "id": "client", + "type": "package", + "package": "postgresql-libs" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "loads": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "env": { + "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable", + "MESH_PROVISION_PASSWORD_FILE": "${dir:state}/superuser.secret", + "MESH_RECEIVES": "${dir:grants}/mesh.json", + "MESH_POSTGRES_READER_PASSWORD_FILE": "${dir:state}/reader.secret" + } } ] }