Defer minio from the buildable set too (issue 060)
minio's runtime copies the `mc` client from minio/mc:latest — a Docker Hub pull the mesh build environment cannot make (its docker reaches the mesh registry, not public Hub), the same isolation that blocks npm deps. apt-based installs (mongodb's mongosh, mosquitto) build fine because the build has real internet for apt; only npm and Docker Hub are redirected. Delivering an external binary or image layer into a mesh build is the same open question as the npm deps — deferred with them.
This commit is contained in:
@@ -1,32 +0,0 @@
|
|||||||
# minio's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/minio
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
# minio's client drives `mc` — copied from the official image, as the workstation build did.
|
|
||||||
COPY --from=minio/mc:latest /usr/bin/mc /usr/bin/mc
|
|
||||||
COPY --from=build /app/modules/minio/dist /app/modules/minio/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js
|
|
||||||
@@ -102,6 +102,7 @@
|
|||||||
"id": "runtime",
|
"id": "runtime",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "mesh-minio",
|
"name": "mesh-minio",
|
||||||
|
"image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||||
"network": "minio",
|
"network": "minio",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
|
||||||
@@ -114,29 +115,7 @@
|
|||||||
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
|
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
|
||||||
},
|
}
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
]
|
||||||
"build": {
|
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
|
||||||
{
|
|
||||||
"name": "runtime",
|
|
||||||
"kind": "image",
|
|
||||||
"from": "Dockerfile"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user