audit-logger: the assigned-module manifest (ADR 0048)

Now a real assigned module, not just a handler: consumes '#', declares its
broker own-secret, and runs the runtime image as a container that mounts the
sealed credential and its trail. own-secrets:{broker} is the file the mesh
seals it (module issue); the container reads MESH_BROKER_FILE from the mount
and takes its node/module identity from the credential. Parses against the
catalogue schema.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-04 01:56:36 +02:00
parent 43625ec03f
commit 8f0994fcdc
+35 -4
View File
@@ -1,15 +1,46 @@
{ {
"module": "audit-logger", "module": "audit-logger",
"version": "1", "version": "1",
"consumes": [ "consumes": ["#"],
"#" "own-secrets": {
], "broker": "/var/lib/audit-logger/broker"
},
"build": {
"artifacts": [
{
"name": "runtime",
"kind": "upstream",
"from": "registry.invalid/mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000"
}
]
},
"resources": [ "resources": [
{ {
"id": "log", "id": "state",
"type": "directory", "type": "directory",
"path": "/var/lib/audit-logger", "path": "/var/lib/audit-logger",
"mode": "0700" "mode": "0700"
},
{
"id": "trail",
"type": "directory",
"path": "/var/lib/audit-logger/trail",
"mode": "0700"
},
{
"id": "run",
"type": "container",
"name": "mesh-audit-logger",
"artifact": "runtime",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
"/var/lib/audit-logger/trail:/trail"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"AUDIT_LOG": "/trail/audit.log"
}
} }
] ]
} }