From 8f0994fcdcc0994ae5aa70656f1a3f6419fffad2 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 4 Sep 2026 01:56:36 +0200 Subject: [PATCH] audit-logger: the assigned-module manifest (ADR 0048) Now a real assigned module, not just a handler: consumes '#', declares its broker own-secret, and runs the runtime image as a container that mounts the sealed credential and its trail. own-secrets:{broker} is the file the mesh seals it (module issue); the container reads MESH_BROKER_FILE from the mount and takes its node/module identity from the credential. Parses against the catalogue schema. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/audit-logger/module.json | 39 ++++++++++++++++++++++++++++---- 1 file changed, 35 insertions(+), 4 deletions(-) diff --git a/modules/audit-logger/module.json b/modules/audit-logger/module.json index 72bf5b9..4528f02 100644 --- a/modules/audit-logger/module.json +++ b/modules/audit-logger/module.json @@ -1,15 +1,46 @@ { "module": "audit-logger", "version": "1", - "consumes": [ - "#" - ], + "consumes": ["#"], + "own-secrets": { + "broker": "/var/lib/audit-logger/broker" + }, + "build": { + "artifacts": [ + { + "name": "runtime", + "kind": "upstream", + "from": "registry.invalid/mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000" + } + ] + }, "resources": [ { - "id": "log", + "id": "state", "type": "directory", "path": "/var/lib/audit-logger", "mode": "0700" + }, + { + "id": "trail", + "type": "directory", + "path": "/var/lib/audit-logger/trail", + "mode": "0700" + }, + { + "id": "run", + "type": "container", + "name": "mesh-audit-logger", + "artifact": "runtime", + "network": "host", + "volumes": [ + "/var/lib/audit-logger/broker:/run/secrets/broker:ro", + "/var/lib/audit-logger/trail:/trail" + ], + "env": { + "MESH_BROKER_FILE": "/run/secrets/broker", + "AUDIT_LOG": "/trail/audit.log" + } } ] }