From e189b743bd253488ddbf1b6b5700da24ff6fe895 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 00:34:25 +0200 Subject: [PATCH] mesh-vault: its handlers, tools and provisioner run in the node's runtime (hq ADR 0198) The mesh-vault container goes with its Dockerfile, build bases, bus credential and state directory; its env was already host paths, so it becomes the bundle's words unchanged. --- modules/mesh-vault/Dockerfile | 22 ------------ modules/mesh-vault/module.json | 61 ++++++++++------------------------ 2 files changed, 18 insertions(+), 65 deletions(-) delete mode 100644 modules/mesh-vault/Dockerfile diff --git a/modules/mesh-vault/Dockerfile b/modules/mesh-vault/Dockerfile deleted file mode 100644 index ffe09b0..0000000 --- a/modules/mesh-vault/Dockerfile +++ /dev/null @@ -1,22 +0,0 @@ -# mesh-vault's runtime: the tool runtime, carrying this module's compiled provisioner, tools and event -# consumer. The same shape as postgres's, minus the client the database needs: mesh-vault reaches no -# server, because what it provides is a value the mesh already delivered to its node. -# -# **Built from this module's own directory and nothing else.** The sdk is in the base image, so -# nothing is copied out of a neighbouring checkout (novox/hq ADR 0069). Two bases, named rather than -# pinned — the image this is COMPILED in and the image it RUNS in — answered by the mesh from -# `build.on` in module.json (novox/hq issue 044). -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/vault -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/vault/dist /app/modules/vault/dist -# The entrypoints a tool host loads from this module: its event consumer, its tools and its -# provisioner — one image, one process, one broker account (novox/hq ADR 0052). -ENV MESH_TOOL_MODULES=/app/modules/vault/dist/index.js,/app/modules/vault/dist/tools/index.js,/app/modules/vault/dist/provisioner/index.js diff --git a/modules/mesh-vault/module.json b/modules/mesh-vault/module.json index 29e17a3..31c3092 100644 --- a/modules/mesh-vault/module.json +++ b/modules/mesh-vault/module.json @@ -27,16 +27,7 @@ "secret": "${dir:grants}" }, "keeps": "/var/lib/mesh-vault/root", - "own-secrets": { - "broker": "${dir:mesh-state}/broker" - }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -57,45 +48,29 @@ "id": "root", "type": "directory", "mode": "0700" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-vault", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:grants}:${dir:grants}:ro", - "${dir:ledger}:${dir:ledger}", - "${dir:root}:${dir:root}:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "${dir:grants}/mesh.json", - "MESH_VAULT_LEDGER": "${dir:ledger}", - "MESH_VAULT_ROOT": "${dir:root}" - }, - "artifact": "runtime" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "loads": [ + "index.js", + "tools/index.js", + "provisioner/index.js" + ], + "env": { + "MESH_RECEIVES": "${dir:grants}/mesh.json", + "MESH_VAULT_LEDGER": "${dir:ledger}", + "MESH_VAULT_ROOT": "${dir:root}" + } } ] },