records: its consumer and tools run in the node's runtime (hq ADR 0198)
The records container goes with its Dockerfile, build bases and bus credential. The checkout, the config file and the origin file are read where the mesh writes them, and git comes from the machine's git package instead of the image's apt layer.
This commit is contained in:
@@ -1,26 +0,0 @@
|
||||
# records' runtime: the tool runtime, carrying this module's compiled reader and its tools.
|
||||
#
|
||||
# **Built from this module's own directory and nothing else.** The sdk is in the base image, so
|
||||
# nothing is copied out of a neighbouring checkout (novox/hq ADR 0069).
|
||||
#
|
||||
# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in
|
||||
# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults.
|
||||
ARG BUILD_BASE
|
||||
ARG RUNTIME_BASE
|
||||
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/records
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc records.ts index.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
# **A module may need something the base image does not carry.** The reader keeps a checkout of the
|
||||
# repository it reads (novox/hq ADR 0153) — a git working copy, kept current, not a derived copy — and
|
||||
# the base image has no git. Certificates too, because the origin may be reached over TLS.
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends git ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
COPY --from=build /app/modules/records/dist /app/modules/records/dist
|
||||
# Both entrypoints, loaded in serve mode: the consumer that pulls on a merge, and the tools.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/records/dist/index.js,/app/modules/records/dist/tools/index.js
|
||||
+19
-39
@@ -11,9 +11,6 @@
|
||||
"binds": {
|
||||
"git": "${dir:mesh-state}/git.json"
|
||||
},
|
||||
"own-secrets": {
|
||||
"broker": "${dir:mesh-state}/broker"
|
||||
},
|
||||
"consumes": [
|
||||
"gitea.pull.merged"
|
||||
],
|
||||
@@ -53,47 +50,30 @@
|
||||
"content": "${bound:git:scheme}://${bound:git:at}:${bound:git:port}\n"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "records",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
||||
"${dir:mesh-state}/origin:/run/config/origin:ro",
|
||||
"${dir:checkout}:${dir:checkout}"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECORDS_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_RECORDS_ORIGIN_FILE": "/run/config/origin",
|
||||
"MESH_RECORDS_DIR": "${dir:checkout}"
|
||||
},
|
||||
"artifact": "runtime",
|
||||
"restart-on": [
|
||||
"config",
|
||||
"origin"
|
||||
]
|
||||
"id": "git",
|
||||
"type": "package",
|
||||
"package": "git"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
"arg": "BUILD_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "build"
|
||||
},
|
||||
{
|
||||
"arg": "RUNTIME_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "runtime",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
"name": "code",
|
||||
"kind": "bundle",
|
||||
"language": "typescript",
|
||||
"entrypoints": [
|
||||
"index.js",
|
||||
"tools/index.js"
|
||||
],
|
||||
"loads": [
|
||||
"index.js",
|
||||
"tools/index.js"
|
||||
],
|
||||
"env": {
|
||||
"MESH_RECORDS_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
||||
"MESH_RECORDS_ORIGIN_FILE": "${dir:mesh-state}/origin",
|
||||
"MESH_RECORDS_DIR": "${dir:checkout}"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user