nats: the module, and an image that reloads in place
Step 1.1 and 1.2 of novox/hq ADR 0116. The server is a built artifact rather than the upstream image directly, because it needs an entrypoint of its own: the host can only recreate a container, and recreating the bus for every permission change drops every connection and every in-flight ack. nats-server reloads on SIGHUP by itself, so the config is mounted as a directory (not digest-tracked, hq issue 103) and the entrypoint watches the one file. Verified against the real server, not assumed: a user added to the config connects, a revoked one is refused, both within one poll interval, with the container's PID and restart count unchanged and "Reloaded: accounts" in its log. Two corrections found by checking rather than reading: - the seat delivers nothing now (hq ADR 0117), and the controller's parser refused the manifest until it did — "nats claims mesh-broker, whose holder answers for amqp, and nats does not provide amqp" - pinned to the multi-arch index digest; the first pin was the amd64 manifest, which builds here and fails on any other architecture
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
{
|
||||
"module": "nats",
|
||||
"version": "1",
|
||||
"provides": [],
|
||||
"claims": [
|
||||
{
|
||||
"name": "mesh-broker",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"emits": [],
|
||||
"consumes": [],
|
||||
"listens": [
|
||||
{
|
||||
"port": 4222,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the mesh bus \u2014 every link the mesh has, over TLS, reached across the overlay"
|
||||
}
|
||||
],
|
||||
"guards": [
|
||||
8222
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "jetstream-data",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh-broker-nats",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "conf-dir",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/nats-module/conf",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "mesh-broker-nats",
|
||||
"ports": [
|
||||
"4222:4222",
|
||||
"127.0.0.1:8222:8222"
|
||||
],
|
||||
"volumes": [
|
||||
"/var/lib/mesh-broker-nats:/data",
|
||||
"/var/lib/nats-module/conf:/etc/nats:ro",
|
||||
"/var/lib/mesh-broker-nats-tls:/tls:ro"
|
||||
],
|
||||
"artifact": "server"
|
||||
}
|
||||
],
|
||||
"accesses": [
|
||||
{
|
||||
"path": "/var/lib/mesh-broker-nats-tls",
|
||||
"mode": "read"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "server",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user