nextcloud: its handlers and tools run in the node's runtime (hq ADR 0198)
The mesh-nextcloud container goes with its Dockerfile, build bases and bus credential. occ still runs through docker exec, now with the host's own docker CLI and socket.
This commit is contained in:
@@ -1,40 +0,0 @@
|
|||||||
# nextcloud's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
ARG DOCKER_CLI
|
|
||||||
|
|
||||||
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
|
|
||||||
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
|
|
||||||
FROM ${DOCKER_CLI} AS dockercli
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/nextcloud
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
|
|
||||||
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
|
|
||||||
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client
|
|
||||||
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
|
|
||||||
# systemd unit, no package manager tree pulled in for it).
|
|
||||||
COPY --from=dockercli /usr/local/bin/docker /usr/local/bin/docker
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/nextcloud/dist/index.js,/app/modules/nextcloud/dist/tools/index.js
|
|
||||||
@@ -30,8 +30,7 @@
|
|||||||
"share.created"
|
"share.created"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:state}/admin.secret",
|
"admin": "${dir:state}/admin.secret"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
@@ -94,53 +93,28 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-nextcloud",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
|
||||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
||||||
"/var/run/docker.sock:/var/run/docker.sock"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}",
|
|
||||||
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json",
|
|
||||||
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "DOCKER_CLI",
|
|
||||||
"image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}",
|
||||||
|
"MESH_NEXTCLOUD_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
||||||
|
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
|
||||||
|
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user