audit-logger: the container names its image directly (a container has no artifact)

A container resource takes a digest-pinned image, not a build artifact — the
host refuses 'artifact' on a container. Verified: the mesh assigns it and the
host runs it in the lab.
This commit is contained in:
2026-09-04 02:13:01 +02:00
parent 8f0994fcdc
commit c2c26a29a9
+1 -10
View File
@@ -5,15 +5,6 @@
"own-secrets": {
"broker": "/var/lib/audit-logger/broker"
},
"build": {
"artifacts": [
{
"name": "runtime",
"kind": "upstream",
"from": "registry.invalid/mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000"
}
]
},
"resources": [
{
"id": "state",
@@ -31,7 +22,7 @@
"id": "run",
"type": "container",
"name": "mesh-audit-logger",
"artifact": "runtime",
"image": "mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",