Convert gitlab into a tools-only mesh catalog module
Port the HAL gitlab module (whose tools lived in @hal/sdk) into a self-contained mesh-catalog module modelled on cloudflare-dns: the GitLab API client and all its tools live in the module (ADR 0039), served through mesh-sdk's registerModuleTools harness. Tools-only, outbound-only external-SaaS shape: a runtime-only container on network:host, no service, no listener, no provisioner. The token is an own-secret; GITLAB_URL is a public setting in a merge:json config file. The client is built lazily and never throws at registration, so the runtime comes up and serves all 23 tools even with no valid token (the Servarr lesson) — it only fails when a tool is actually invoked unconfigured. Ported 23 tools: projects (list, get), merge requests (list, get, create, approve, add note), pipelines (list, get, retry, cancel, list jobs, job log), and project + group CI/CD variables (list, get, create, update, delete each). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
{
|
||||
"module": "gitlab",
|
||||
"version": "1",
|
||||
"own-secrets": {
|
||||
"token": "/var/lib/gitlab/token",
|
||||
"broker": "/var/lib/mesh/gitlab/broker"
|
||||
},
|
||||
"resources": [
|
||||
{
|
||||
"id": "mesh-state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh/gitlab",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/gitlab",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/gitlab/config.json",
|
||||
"merge": "json",
|
||||
"content": "{}",
|
||||
"mode": "0600"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "mesh-runtime-gitlab",
|
||||
"image": "mesh-runtime-gitlab@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/gitlab/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/gitlab/token:/run/secrets/token:ro",
|
||||
"/var/lib/mesh/gitlab/broker:/run/secrets/broker:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_GITLAB_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_GITLAB_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker"
|
||||
}
|
||||
}
|
||||
],
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user