Defer model-usage and anthropic-manager from the buildable set (issue 060)

Both carry third-party runtime deps (pg; tweetnacl + sealedbox) that
their Dockerfile installs with npm — which 404s in a mesh build, whose
npm points at the mesh's own registry, not public npm. The workstation
build script got away with it by installing on a host with public npm.
Delivering a module's third-party deps into a mesh build is an open
question (how: publish to the mesh registry, or proxy); until it is
answered these two stay on the placeholder path they were already on.
The other 37 modules build from their own directory with no external
fetch.
This commit is contained in:
2026-09-18 02:48:09 +02:00
parent e362fb951c
commit b8d390cbae
4 changed files with 6 additions and 102 deletions
-26
View File
@@ -1,26 +0,0 @@
# anthropic-manager's runtime: the tool runtime, carrying this module's compiled code.
#
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
# the base images, published like any other artifact — which is what makes this buildable by the
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
# happens to have the siblings.
#
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
ARG BUILD_BASE
ARG RUNTIME_BASE
FROM ${BUILD_BASE} AS build
WORKDIR /app/modules/anthropic-manager
COPY . .
# This module's own third-party dependencies, installed beside its compiled code so Node
# resolves them from the module and falls back to the shared tree for everything common.
RUN npm install --omit=dev --no-save --no-package-lock --ignore-scripts "tweetnacl@^1.0.3" "tweetnacl-sealedbox-js@^1.2.0"
RUN node /app/node_modules/typescript/bin/tsc client.ts adopt/index.ts refresh/index.ts \
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE}
COPY --from=build /app/modules/anthropic-manager/dist /app/modules/anthropic-manager/dist
COPY --from=build /app/modules/anthropic-manager/node_modules /app/modules/anthropic-manager/node_modules
# No serve-time entrypoints: every container of this module names its command (`run` on a
# schedule), so nothing here serves — deliberately no MESH_TOOL_MODULES.
+3 -24
View File
@@ -37,6 +37,7 @@
"id": "refresh",
"type": "container",
"name": "mesh-anthropic-manager-refresh",
"image": "mesh-runtime-anthropic-manager@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "host",
"schedule": "*/5 * * * *",
"args": [
@@ -56,29 +57,7 @@
"MESH_ANTHROPIC_GRANT_OUT": "/run/state/out/grant.json",
"MESH_ANTHROPIC_USAGE_OUT": "/run/state/out/usage.json",
"MESH_TOOLS_MAIN": "/app/dist/main.js"
},
"artifact": "runtime"
}
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
}
]
}
-28
View File
@@ -1,28 +0,0 @@
# model-usage's runtime: the tool runtime, carrying this module's compiled code.
#
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
# the base images, published like any other artifact — which is what makes this buildable by the
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
# happens to have the siblings.
#
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
ARG BUILD_BASE
ARG RUNTIME_BASE
FROM ${BUILD_BASE} AS build
WORKDIR /app/modules/model-usage
COPY . .
# This module's own third-party dependencies, installed beside its compiled code so Node
# resolves them from the module and falls back to the shared tree for everything common.
RUN npm install --omit=dev --no-save --no-package-lock --ignore-scripts "pg@^8"
RUN node /app/node_modules/typescript/bin/tsc index.ts tools/index.ts pg.d.ts \
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE}
COPY --from=build /app/modules/model-usage/dist /app/modules/model-usage/dist
COPY --from=build /app/modules/model-usage/node_modules /app/modules/model-usage/node_modules
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
# the convention novox/hq issues 060/061 settled.
ENV MESH_TOOL_MODULES=/app/modules/model-usage/dist/index.js,/app/modules/model-usage/dist/tools/index.js
+3 -24
View File
@@ -49,6 +49,7 @@
"id": "runtime",
"type": "container",
"name": "mesh-model-usage",
"image": "mesh-runtime-model-usage@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "host",
"volumes": [
"/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro",
@@ -59,29 +60,7 @@
},
"env-file": [
"/var/lib/model-usage/db.env"
],
"artifact": "runtime"
]
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
}
]
}