records: its consumer and tools run in the node's runtime (hq ADR 0198)

The records container goes with its Dockerfile, build bases and bus credential. The checkout, the config file and the origin file are read where the mesh writes them, and git comes from the machine's git package instead of the image's apt layer.
This commit is contained in:
jochen
2026-10-04 00:52:31 +02:00
parent 043ae17fbf
commit 8877f893e5
2 changed files with 19 additions and 65 deletions
+19 -39
View File
@@ -11,9 +11,6 @@
"binds": {
"git": "${dir:mesh-state}/git.json"
},
"own-secrets": {
"broker": "${dir:mesh-state}/broker"
},
"consumes": [
"gitea.pull.merged"
],
@@ -53,47 +50,30 @@
"content": "${bound:git:scheme}://${bound:git:at}:${bound:git:port}\n"
},
{
"id": "runtime",
"type": "container",
"name": "records",
"network": "host",
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
"${dir:mesh-state}/origin:/run/config/origin:ro",
"${dir:checkout}:${dir:checkout}"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECORDS_CONFIG_FILE": "/run/config/config.json",
"MESH_RECORDS_ORIGIN_FILE": "/run/config/origin",
"MESH_RECORDS_DIR": "${dir:checkout}"
},
"artifact": "runtime",
"restart-on": [
"config",
"origin"
]
"id": "git",
"type": "package",
"package": "git"
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js"
],
"loads": [
"index.js",
"tools/index.js"
],
"env": {
"MESH_RECORDS_CONFIG_FILE": "${dir:mesh-state}/config.json",
"MESH_RECORDS_ORIGIN_FILE": "${dir:mesh-state}/origin",
"MESH_RECORDS_DIR": "${dir:checkout}"
}
}
]
}