audit-logger: its handler runs in the node's runtime (hq ADR 0198)
The mesh-audit-logger container goes with its Dockerfile, build bases and bus credential: its one entrypoint is a load of one bundle, which subscribes to every event through the runtime and writes the trail at the host path the container used to mount.
This commit is contained in:
@@ -1,33 +0,0 @@
|
|||||||
# audit-logger's runtime: the shared runtime image, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The toolkit is in the base image, so
|
|
||||||
# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a
|
|
||||||
# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have
|
|
||||||
# the siblings laid out beside it.
|
|
||||||
|
|
||||||
# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in.
|
|
||||||
# They are different images on purpose — the first carries a compiler and the second must not, or
|
|
||||||
# every running container would carry one it never invokes. The mesh answers both with the copies it
|
|
||||||
# holds, because a fingerprint written here would name one particular copy and no other mesh has it
|
|
||||||
# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults, so a build
|
|
||||||
# nobody told stops here and says which module to build first.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the toolkit it will run against.
|
|
||||||
WORKDIR /app/modules/audit-logger
|
|
||||||
COPY . .
|
|
||||||
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
|
||||||
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
|
||||||
# was assembled.
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc audit.ts index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/audit-logger/dist /app/modules/audit-logger/dist
|
|
||||||
# **Served, not run.** This subscribes on import, and the serve mode binds the broker before it
|
|
||||||
# imports anything — `run` exists for a step that works offline and exits, and would leave this
|
|
||||||
# with nothing to subscribe to.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/audit-logger/dist/index.js
|
|
||||||
@@ -5,27 +5,21 @@
|
|||||||
"consumes": [
|
"consumes": [
|
||||||
"**"
|
"**"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
|
||||||
"broker": "${dir:state}/broker"
|
|
||||||
},
|
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"AUDIT_LOG": "${dir:trail}/audit.log"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -40,21 +34,6 @@
|
|||||||
"id": "trail",
|
"id": "trail",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "run",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-audit-logger",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:trail}:/trail"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"AUDIT_LOG": "/trail/audit.log"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
|
|||||||
Reference in New Issue
Block a user