A definition names no host path for its own data

Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
2026-09-30 21:10:18 +02:00
parent 12bbcafacf
commit eed5e8958a
28 changed files with 210 additions and 223 deletions
+6 -7
View File
@@ -9,10 +9,10 @@
"model-access"
],
"binds": {
"model-access": "/var/lib/anthropic-consumer/model.json"
"model-access": "${dir:state}/model.json"
},
"secrets": {
"model-access": "/var/lib/anthropic-consumer/access-token"
"model-access": "${dir:state}/access-token"
},
"own-secrets": {
"broker": "/var/lib/mesh/anthropic-consumer/broker"
@@ -30,8 +30,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/anthropic-consumer",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "claude-home",
@@ -42,7 +42,6 @@
{
"id": "out",
"type": "directory",
"path": "/var/lib/anthropic-consumer/out",
"mode": "0700"
},
{
@@ -56,7 +55,7 @@
"/app/modules/anthropic-consumer/dist/apply/index.js"
],
"volumes": [
"/var/lib/anthropic-consumer:/run/state"
"${dir:state}:/run/state"
],
"env": {
"MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/access-token",
@@ -78,7 +77,7 @@
],
"volumes": [
"/var/lib/mesh/anthropic-consumer/broker:/run/secrets/broker:ro",
"/var/lib/anthropic-consumer:/run/state"
"${dir:state}:/run/state"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+5 -6
View File
@@ -6,7 +6,7 @@
"**"
],
"own-secrets": {
"broker": "/var/lib/audit-logger/broker"
"broker": "${dir:state}/broker"
},
"build": {
"on": [
@@ -33,13 +33,12 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/audit-logger",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "trail",
"type": "directory",
"path": "/var/lib/audit-logger/trail",
"mode": "0700"
},
{
@@ -48,8 +47,8 @@
"name": "mesh-audit-logger",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
"/var/lib/audit-logger/trail:/trail"
"${dir:state}/broker:/run/secrets/broker:ro",
"${dir:trail}:/trail"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+2 -3
View File
@@ -33,7 +33,6 @@
{
"id": "workspace",
"type": "directory",
"path": "/var/lib/builder/workspace",
"mode": "0700"
},
{
@@ -41,7 +40,7 @@
"type": "file",
"path": "/var/lib/mesh/builder/builder.env",
"mode": "0600",
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=${dir:workspace}\n"
},
{
"id": "server",
@@ -53,7 +52,7 @@
],
"volumes": [
"/var/lib/mesh/builder:/run/mesh:ro",
"/var/lib/builder/workspace:/var/lib/builder/workspace",
"${dir:workspace}:${dir:workspace}",
"/var/run/docker.sock:/var/run/docker.sock"
],
"restart-on": [
+9 -10
View File
@@ -12,13 +12,13 @@
"public-dns": {}
},
"grants": {
"public-dns": "/var/lib/cloudflare-dns/grants"
"public-dns": "${dir:grants}"
},
"receives": {
"public-dns": "/var/lib/cloudflare-dns/grants/mesh.json"
"public-dns": "${dir:grants}/mesh.json"
},
"own-secrets": {
"token": "/var/lib/cloudflare-dns/token",
"token": "${dir:state}/token",
"broker": "/var/lib/mesh/cloudflare-dns/broker"
},
"emits": [
@@ -35,19 +35,18 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/cloudflare-dns",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/cloudflare-dns/grants",
"mode": "0700"
},
{
"id": "config",
"type": "file",
"path": "/var/lib/cloudflare-dns/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"content": "{}",
"mode": "0600"
@@ -58,9 +57,9 @@
"name": "mesh-cloudflare-dns",
"network": "host",
"volumes": [
"/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro",
"/var/lib/cloudflare-dns/grants:/grants",
"/var/lib/cloudflare-dns/token:/run/secrets/token:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:grants}:/grants",
"${dir:state}/token:/run/secrets/token:ro",
"/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro"
],
"env": {
+6 -6
View File
@@ -3,7 +3,7 @@
"version": "1",
"slug": "confl",
"own-secrets": {
"token": "/var/lib/confluence/token",
"token": "${dir:state}/token",
"broker": "/var/lib/mesh/confluence/broker"
},
"resources": [
@@ -16,13 +16,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/confluence",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "file",
"path": "/var/lib/confluence/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"content": "{}",
"mode": "0600"
@@ -33,8 +33,8 @@
"name": "mesh-runtime-confluence",
"network": "host",
"volumes": [
"/var/lib/confluence/config.json:/run/config/config.json:ro",
"/var/lib/confluence/token:/run/secrets/token:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:state}/token:/run/secrets/token:ro",
"/var/lib/mesh/confluence/broker:/run/secrets/broker:ro"
],
"env": {
+7 -7
View File
@@ -15,11 +15,11 @@
}
},
"binds": {
"route": "/var/lib/de-spiegel/route.json"
"route": "${dir:state}/route.json"
},
"own-secrets": {
"smtp-user": "/var/lib/de-spiegel/smtp-user.secret",
"smtp-pass": "/var/lib/de-spiegel/smtp-pass.secret"
"smtp-user": "${dir:state}/smtp-user.secret",
"smtp-pass": "${dir:state}/smtp-pass.secret"
},
"listens": [
{
@@ -34,13 +34,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/de-spiegel",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/de-spiegel/server.env",
"path": "${dir:state}/server.env",
"mode": "0600",
"content": "SMTP_AUTH_USER=${secret:smtp-user}\nSMTP_AUTH_PASS=${secret:smtp-pass}\n"
},
@@ -56,7 +56,7 @@
"image": "registry-api.novox.be/novox/de-spiegel@sha256:e144b72ce9c145870470d765343549f2c60211728cd118b9ff0e4029f36342ba",
"network": "de-spiegel",
"env-file": [
"/var/lib/de-spiegel/server.env"
"${dir:state}/server.env"
],
"ports": [
"35621"
+6 -6
View File
@@ -2,7 +2,7 @@
"module": "gitlab",
"version": "1",
"own-secrets": {
"token": "/var/lib/gitlab/token",
"token": "${dir:state}/token",
"broker": "/var/lib/mesh/gitlab/broker"
},
"resources": [
@@ -15,13 +15,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/gitlab",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "file",
"path": "/var/lib/gitlab/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"content": "{}",
"mode": "0600"
@@ -32,8 +32,8 @@
"name": "mesh-runtime-gitlab",
"network": "host",
"volumes": [
"/var/lib/gitlab/config.json:/run/config/config.json:ro",
"/var/lib/gitlab/token:/run/secrets/token:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:state}/token:/run/secrets/token:ro",
"/var/lib/mesh/gitlab/broker:/run/secrets/broker:ro"
],
"env": {
+5 -5
View File
@@ -15,7 +15,7 @@
}
},
"binds": {
"route": "/var/lib/hello-web/route.json"
"route": "${dir:state}/route.json"
},
"listens": [
{
@@ -30,13 +30,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/hello-web",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "page",
"type": "file",
"path": "/var/lib/hello-web/index.html",
"path": "${dir:state}/index.html",
"mode": "0644",
"content": "hello from hello-web, routed by the mesh\n"
},
@@ -54,7 +54,7 @@
"8080"
],
"volumes": [
"/var/lib/hello-web/index.html:/www/index.html:ro"
"${dir:state}/index.html:/www/index.html:ro"
],
"args": [
"sh",
+9 -9
View File
@@ -26,13 +26,13 @@
}
},
"binds": {
"mongodb-database": "/var/lib/invoicing/database.json",
"s3-bucket": "/var/lib/invoicing/store.json",
"route": "/var/lib/invoicing/route.json"
"mongodb-database": "${dir:state}/database.json",
"s3-bucket": "${dir:state}/store.json",
"route": "${dir:state}/route.json"
},
"secrets": {
"mongodb-database": "/var/lib/invoicing/database.secret",
"s3-bucket": "/var/lib/invoicing/store.secret"
"mongodb-database": "${dir:state}/database.secret",
"s3-bucket": "${dir:state}/store.secret"
},
"listens": [
{
@@ -60,13 +60,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/invoicing",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "api-env",
"type": "file",
"path": "/var/lib/invoicing/api.env",
"path": "${dir:state}/api.env",
"mode": "0600",
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=${bound:mongodb-database:as}\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_BUCKET=mesh-novox-invoice\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n"
},
@@ -103,7 +103,7 @@
"GID": "2201"
},
"env-file": [
"/var/lib/invoicing/api.env"
"${dir:state}/api.env"
],
"ports": [
"9000"
+6 -6
View File
@@ -2,7 +2,7 @@
"module": "jira",
"version": "1",
"own-secrets": {
"token": "/var/lib/jira/token",
"token": "${dir:state}/token",
"broker": "/var/lib/mesh/jira/broker"
},
"resources": [
@@ -15,13 +15,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/jira",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "file",
"path": "/var/lib/jira/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"content": "{}",
"mode": "0600"
@@ -32,8 +32,8 @@
"name": "mesh-runtime-jira",
"network": "host",
"volumes": [
"/var/lib/jira/config.json:/run/config/config.json:ro",
"/var/lib/jira/token:/run/secrets/token:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:state}/token:/run/secrets/token:ro",
"/var/lib/mesh/jira/broker:/run/secrets/broker:ro"
],
"env": {
+17 -18
View File
@@ -21,11 +21,11 @@
}
},
"binds": {
"postgres-database": "/var/lib/keycloak/database.json",
"route": "/var/lib/keycloak/route.json"
"postgres-database": "${dir:state}/database.json",
"route": "${dir:state}/route.json"
},
"secrets": {
"postgres-database": "/var/lib/keycloak/database.secret"
"postgres-database": "${dir:state}/database.secret"
},
"capabilities": [
"container-runtime"
@@ -55,13 +55,13 @@
}
},
"receives": {
"oidc-client": "/var/lib/keycloak/grants/mesh.json"
"oidc-client": "${dir:grants}/mesh.json"
},
"grants": {
"oidc-client": "/var/lib/keycloak/grants"
"oidc-client": "${dir:grants}"
},
"own-secrets": {
"admin": "/var/lib/keycloak/admin.secret",
"admin": "${dir:state}/admin.secret",
"broker": "/var/lib/mesh/keycloak/broker"
},
"resources": [
@@ -74,26 +74,25 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/keycloak",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/keycloak/grants",
"mode": "0700"
},
{
"id": "admin-env",
"type": "file",
"path": "/var/lib/keycloak/admin.env",
"path": "${dir:state}/admin.env",
"mode": "0600",
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"
},
{
"id": "database-env",
"type": "file",
"path": "/var/lib/keycloak/database.env",
"path": "${dir:state}/database.env",
"mode": "0600",
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"
},
@@ -105,7 +104,7 @@
{
"id": "hostname",
"type": "file",
"path": "/var/lib/keycloak/hostname.env",
"path": "${dir:state}/hostname.env",
"mode": "0644",
"content": "KC_HOSTNAME=https://${bound:route:name}\n"
},
@@ -125,9 +124,9 @@
"KC_PROXY_HEADERS": "xforwarded"
},
"env-file": [
"/var/lib/keycloak/admin.env",
"/var/lib/keycloak/database.env",
"/var/lib/keycloak/hostname.env"
"${dir:state}/admin.env",
"${dir:state}/database.env",
"${dir:state}/hostname.env"
],
"ports": [
"8080"
@@ -153,15 +152,15 @@
"volumes": [
"/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro",
"/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro",
"/var/lib/keycloak/admin.secret:/run/secrets/admin:ro",
"/var/lib/keycloak/grants:/var/lib/keycloak/grants:ro"
"${dir:state}/admin.secret:/run/secrets/admin:ro",
"${dir:grants}:${dir:grants}:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json",
"MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin",
"MESH_RECEIVES": "/var/lib/keycloak/grants/mesh.json"
"MESH_RECEIVES": "${dir:grants}/mesh.json"
},
"restart-on": [
"runtime-config"
+4 -5
View File
@@ -6,25 +6,24 @@
"model-access"
],
"binds": {
"model-access": "/var/lib/local-model-consumer/model.json"
"model-access": "${dir:state}/model.json"
},
"resources": [
{
"id": "state",
"type": "directory",
"path": "/var/lib/local-model-consumer",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "directory",
"path": "/var/lib/local-model-consumer/config",
"mode": "0700"
},
{
"id": "openai-env",
"type": "file",
"path": "/var/lib/local-model-consumer/config/openai.env",
"path": "${dir:config}/openai.env",
"mode": "0600",
"content": "OPENAI_BASE_URL=http://${bound:model-access:at}:${bound:model-access:port}/v1\nOPENAI_MODEL=${bound:model-access:model}\nOPENAI_API_KEY=local\n"
}
+7 -7
View File
@@ -20,10 +20,10 @@
}
},
"binds": {
"postgres-database": "/var/lib/mesh-catalog/database.json"
"postgres-database": "${dir:state}/database.json"
},
"secrets": {
"postgres-database": "/var/lib/mesh-catalog/database.secret"
"postgres-database": "${dir:state}/database.secret"
},
"own-secrets": {
"broker": "/var/lib/mesh/mesh-catalog/broker"
@@ -49,13 +49,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/mesh-catalog",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "database-url",
"type": "file",
"path": "/var/lib/mesh-catalog/database.url",
"path": "${dir:state}/database.url",
"mode": "0600",
"content": "postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n"
},
@@ -66,8 +66,8 @@
"network": "host",
"volumes": [
"/var/lib/mesh/mesh-catalog/broker:/run/secrets/broker:ro",
"/var/lib/mesh-catalog:/run/state",
"/var/lib/mesh-catalog/database.url:/run/secrets/database-url:ro"
"${dir:state}:/run/state",
"${dir:state}/database.url:/run/secrets/database-url:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+10 -13
View File
@@ -21,10 +21,10 @@
"mesh-vault.secret.deprovisioned"
],
"receives": {
"secret": "/var/lib/mesh-vault/grants/mesh.json"
"secret": "${dir:grants}/mesh.json"
},
"grants": {
"secret": "/var/lib/mesh-vault/grants"
"secret": "${dir:grants}"
},
"keeps": "/var/lib/mesh-vault/root",
"own-secrets": {
@@ -40,25 +40,22 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/mesh-vault",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/mesh-vault/grants",
"mode": "0700"
},
{
"id": "ledger",
"type": "directory",
"path": "/var/lib/mesh-vault/ledger",
"mode": "0700"
},
{
"id": "root",
"type": "directory",
"path": "/var/lib/mesh-vault/root",
"mode": "0700"
},
{
@@ -68,15 +65,15 @@
"network": "host",
"volumes": [
"/var/lib/mesh/mesh-vault/broker:/run/secrets/broker:ro",
"/var/lib/mesh-vault/grants:/var/lib/mesh-vault/grants:ro",
"/var/lib/mesh-vault/ledger:/var/lib/mesh-vault/ledger",
"/var/lib/mesh-vault/root:/var/lib/mesh-vault/root:ro"
"${dir:grants}:${dir:grants}:ro",
"${dir:ledger}:${dir:ledger}",
"${dir:root}:${dir:root}:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/mesh-vault/grants/mesh.json",
"MESH_VAULT_LEDGER": "/var/lib/mesh-vault/ledger",
"MESH_VAULT_ROOT": "/var/lib/mesh-vault/root"
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_VAULT_LEDGER": "${dir:ledger}",
"MESH_VAULT_ROOT": "${dir:root}"
},
"artifact": "runtime"
}
+11 -12
View File
@@ -53,13 +53,13 @@
}
},
"receives": {
"s3-bucket": "/var/lib/minio/grants/mesh.json"
"s3-bucket": "${dir:grants}/mesh.json"
},
"grants": {
"s3-bucket": "/var/lib/minio/grants"
"s3-bucket": "${dir:grants}"
},
"own-secrets": {
"root": "/var/lib/minio/root.secret",
"root": "${dir:state}/root.secret",
"broker": "/var/lib/mesh/minio/broker"
},
"resources": [
@@ -72,19 +72,18 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/minio",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/minio/grants",
"mode": "0700"
},
{
"id": "root-env",
"type": "file",
"path": "/var/lib/minio/root.env",
"path": "${dir:state}/root.env",
"mode": "0600",
"content": "MINIO_ROOT_USER=meshroot\nMINIO_BROWSER_REDIRECT_URL=https://${bound:route:name-console}\n"
},
@@ -112,7 +111,7 @@
":9001"
],
"env-file": [
"/var/lib/minio/root.env"
"${dir:state}/root.env"
],
"ports": [
"9000",
@@ -120,7 +119,7 @@
],
"volumes": [
"/var/lib/minio-store:/data",
"/var/lib/minio/root.secret:/run/secrets/root:ro"
"${dir:state}/root.secret:/run/secrets/root:ro"
],
"env": {
"MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
@@ -134,8 +133,8 @@
"network": "minio-net",
"volumes": [
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
"/var/lib/minio/root.secret:/run/secrets/root:ro"
"${dir:grants}:${dir:grants}:ro",
"${dir:state}/root.secret:/run/secrets/root:ro"
],
"env": {
"MESH_MINIO_ENDPOINT": "http://minio:9000",
@@ -143,7 +142,7 @@
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
"MESH_MINIO_REGION": "eu-west",
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
"MESH_RECEIVES": "${dir:grants}/mesh.json"
},
"artifact": "runtime"
}
+7 -7
View File
@@ -14,10 +14,10 @@
}
},
"binds": {
"postgres-database": "/var/lib/model-usage/database.json"
"postgres-database": "${dir:state}/database.json"
},
"secrets": {
"postgres-database": "/var/lib/model-usage/database.secret"
"postgres-database": "${dir:state}/database.secret"
},
"consumes": [
"*.usage.*"
@@ -35,13 +35,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/model-usage",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "database-url",
"type": "file",
"path": "/var/lib/model-usage/database.url",
"path": "${dir:state}/database.url",
"mode": "0600",
"content": "postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n"
},
@@ -53,8 +53,8 @@
"network": "host",
"volumes": [
"/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro",
"/var/lib/model-usage:/run/state",
"/var/lib/model-usage/database.url:/run/secrets/database-url:ro"
"${dir:state}:/run/state",
"${dir:state}/database.url:/run/secrets/database-url:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+8 -8
View File
@@ -18,14 +18,14 @@
}
},
"binds": {
"postgres-database": "/var/lib/n8n/database.json",
"route": "/var/lib/n8n/route.json"
"postgres-database": "${dir:state}/database.json",
"route": "${dir:state}/route.json"
},
"secrets": {
"postgres-database": "/var/lib/n8n/database.secret"
"postgres-database": "${dir:state}/database.secret"
},
"own-secrets": {
"basic-auth": "/var/lib/n8n/basic-auth.secret"
"basic-auth": "${dir:state}/basic-auth.secret"
},
"listens": [
{
@@ -40,8 +40,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/n8n",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "data",
@@ -53,7 +53,7 @@
{
"id": "server-env",
"type": "file",
"path": "/var/lib/n8n/server.env",
"path": "${dir:state}/server.env",
"mode": "0600",
"content": "N8N_HOST=${bound:route:name}\nN8N_PORT=5678\nN8N_PROTOCOL=https\nWEBHOOK_URL=https://${bound:route:name}/\nN8N_BASIC_AUTH_ACTIVE=true\nN8N_BASIC_AUTH_USER=admin\nN8N_BASIC_AUTH_PASSWORD=${secret:basic-auth}\nNODE_FUNCTION_ALLOW_BUILTIN=*\nNODE_FUNCTION_ALLOW_EXTERNAL=*\nDB_TYPE=postgresdb\nDB_POSTGRESDB_HOST=${bound:postgres-database:at}\nDB_POSTGRESDB_PORT=${bound:postgres-database:port}\nDB_POSTGRESDB_DATABASE=${bound:postgres-database:as}\nDB_POSTGRESDB_USER=${bound:postgres-database:as}\nDB_POSTGRESDB_PASSWORD=${secret:postgres-database}\n"
},
@@ -69,7 +69,7 @@
"image": "n8nio/n8n@sha256:4846eb2f4b874ab04cde7fc1e249d2ddaec66e9aea64439beb2972cfea88e3c0",
"network": "n8n",
"env-file": [
"/var/lib/n8n/server.env"
"${dir:state}/server.env"
],
"ports": [
"5678"
+5 -6
View File
@@ -9,22 +9,21 @@
"model-access"
],
"binds": {
"model-access": "/var/lib/openai-consumer/model.json"
"model-access": "${dir:state}/model.json"
},
"secrets": {
"model-access": "/var/lib/openai-consumer/api-key"
"model-access": "${dir:state}/api-key"
},
"resources": [
{
"id": "state",
"type": "directory",
"path": "/var/lib/openai-consumer",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "directory",
"path": "/var/lib/openai-consumer/config",
"mode": "0700"
},
{
@@ -38,7 +37,7 @@
"/app/modules/openai-consumer/dist/apply/index.js"
],
"volumes": [
"/var/lib/openai-consumer:/run/state"
"${dir:state}:/run/state"
],
"env": {
"MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/api-key",
+3 -3
View File
@@ -15,7 +15,7 @@
}
},
"binds": {
"route": "/var/lib/photos-eef/route.json"
"route": "${dir:state}/route.json"
},
"listens": [
{
@@ -30,8 +30,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/photos-eef",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "net",
+3 -3
View File
@@ -15,7 +15,7 @@
}
},
"binds": {
"route": "/var/lib/photos-filip/route.json"
"route": "${dir:state}/route.json"
},
"listens": [
{
@@ -30,8 +30,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/photos-filip",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "net",
+9 -9
View File
@@ -22,13 +22,13 @@
}
},
"binds": {
"s3-bucket": "/var/lib/photos/store.json",
"mongodb-database": "/var/lib/photos/database.json",
"route": "/var/lib/photos/route.json"
"s3-bucket": "${dir:state}/store.json",
"mongodb-database": "${dir:state}/database.json",
"route": "${dir:state}/route.json"
},
"secrets": {
"s3-bucket": "/var/lib/photos/store.secret",
"mongodb-database": "/var/lib/photos/database.secret"
"s3-bucket": "${dir:state}/store.secret",
"mongodb-database": "${dir:state}/database.secret"
},
"listens": [
{
@@ -50,13 +50,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/photos",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/photos/server.env",
"path": "${dir:state}/server.env",
"mode": "0600",
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=admin\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_BUCKET=mesh-novox-photos\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\nMINIO_USE_SSL=false\n"
},
@@ -72,7 +72,7 @@
"image": "registry-api.novox.be/novox/photos-server@sha256:3f165acbbd1fd731b12fe798c95879c081a44b00e2c569ef7f47165f6a527201",
"network": "photos",
"env-file": [
"/var/lib/photos/server.env"
"${dir:state}/server.env"
],
"ports": [
"9000"
+9 -10
View File
@@ -42,13 +42,13 @@
}
},
"receives": {
"postgres-database": "/var/lib/postgres/grants/mesh.json"
"postgres-database": "${dir:grants}/mesh.json"
},
"grants": {
"postgres-database": "/var/lib/postgres/grants"
"postgres-database": "${dir:grants}"
},
"own-secrets": {
"superuser": "/var/lib/postgres/superuser.secret",
"superuser": "${dir:state}/superuser.secret",
"broker": "/var/lib/mesh/postgres/broker"
},
"resources": [
@@ -61,13 +61,12 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/postgres",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/postgres/grants",
"mode": "0700"
},
{
@@ -91,7 +90,7 @@
],
"volumes": [
"/var/lib/mesh-store:/var/lib/postgresql/data",
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
]
},
{
@@ -101,15 +100,15 @@
"network": "host",
"volumes": [
"/var/lib/mesh/postgres/broker:/run/secrets/broker:ro",
"/var/lib/postgres/grants:/var/lib/postgres/grants:ro",
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
"${dir:grants}:${dir:grants}:ro",
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
],
"env": {
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
"MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}",
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"
"MESH_RECEIVES": "${dir:grants}/mesh.json"
},
"artifact": "runtime"
}
+4 -4
View File
@@ -34,8 +34,8 @@
{
"id": "checkout",
"type": "directory",
"path": "/var/lib/records",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "config",
@@ -61,13 +61,13 @@
"/var/lib/mesh/records/broker:/run/secrets/broker:ro",
"/var/lib/mesh/records/config.json:/run/config/config.json:ro",
"/var/lib/mesh/records/origin:/run/config/origin:ro",
"/var/lib/records:/var/lib/records"
"${dir:checkout}:${dir:checkout}"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECORDS_CONFIG_FILE": "/run/config/config.json",
"MESH_RECORDS_ORIGIN_FILE": "/run/config/origin",
"MESH_RECORDS_DIR": "/var/lib/records"
"MESH_RECORDS_DIR": "${dir:checkout}"
},
"artifact": "runtime",
"restart-on": [
+7 -7
View File
@@ -15,7 +15,7 @@
"route": {}
},
"receives": {
"route": "/var/lib/route-adapter/routes/mesh.json"
"route": "${dir:routes-dir}/mesh.json"
},
"accesses": [
{
@@ -27,8 +27,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/route-adapter",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "routes-dir",
@@ -39,7 +39,7 @@
{
"id": "config",
"type": "file",
"path": "/var/lib/route-adapter/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"mode": "0644",
"content": "{\n \"dynamic\": \"/services/traefik/dynamic\",\n \"entrypoint\": \"websecure\",\n \"certificate-resolver\": \"le\",\n \"machine\": \"host.docker.internal\"\n}\n"
@@ -51,12 +51,12 @@
"artifact": "runtime",
"run-once": true,
"volumes": [
"/var/lib/route-adapter/routes/mesh.json:/var/lib/route-adapter/routes/mesh.json:ro",
"/var/lib/route-adapter/config.json:/run/config/config.json:ro",
"${dir:routes-dir}/mesh.json:${dir:routes-dir}/mesh.json:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"/services/traefik/dynamic:/services/traefik/dynamic"
],
"env": {
"MESH_RECEIVES": "/var/lib/route-adapter/routes/mesh.json",
"MESH_RECEIVES": "${dir:routes-dir}/mesh.json",
"MESH_ROUTE_ADAPTER_CONFIG": "/run/config/config.json"
},
"args": [
+16 -16
View File
@@ -15,15 +15,15 @@
"route": {}
},
"receives": {
"route": "/var/lib/route-proxy/routes/mesh.json"
"route": "${dir:routes-dir}/mesh.json"
},
"requires": [
"acme-ca",
"internal-acme-ca"
],
"binds": {
"acme-ca": "/var/lib/route-proxy/acme-ca.json",
"internal-acme-ca": "/var/lib/route-proxy/internal-acme-ca.json"
"acme-ca": "${dir:state}/acme-ca.json",
"internal-acme-ca": "${dir:state}/internal-acme-ca.json"
},
"listens": [
{
@@ -45,8 +45,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/route-proxy",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "routes-dir",
@@ -69,14 +69,14 @@
{
"id": "acme-env",
"type": "file",
"path": "/var/lib/route-proxy/acme.env",
"path": "${dir:state}/acme.env",
"mode": "0600",
"content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n"
},
{
"id": "internal-acme-env",
"type": "file",
"path": "/var/lib/route-proxy/internal-acme.env",
"path": "${dir:state}/internal-acme.env",
"mode": "0600",
"content": "INTERNAL_ACME_DIRECTORY=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:path}\nINTERNAL_ACME_ROOTS=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}\nINTERNAL_ACME_ROOTS_PATH=${bound:internal-acme-ca:roots}\n"
},
@@ -88,10 +88,10 @@
"run-once": true,
"network": "host",
"env-file": [
"/var/lib/route-proxy/acme.env"
"${dir:state}/acme.env"
],
"volumes": [
"/var/lib/route-proxy/ca:/ca"
"${dir:ca-dir}:/ca"
],
"args": [
"sh",
@@ -110,10 +110,10 @@
"run-once": true,
"network": "host",
"env-file": [
"/var/lib/route-proxy/internal-acme.env"
"${dir:state}/internal-acme.env"
],
"volumes": [
"/var/lib/route-proxy/ca:/ca"
"${dir:ca-dir}:/ca"
],
"args": [
"sh",
@@ -131,13 +131,13 @@
"artifact": "server",
"network": "host",
"env-file": [
"/var/lib/route-proxy/acme.env",
"/var/lib/route-proxy/internal-acme.env"
"${dir:state}/acme.env",
"${dir:state}/internal-acme.env"
],
"volumes": [
"/var/lib/route-proxy/routes:/routes:ro",
"/var/lib/route-proxy/acme:/acme",
"/var/lib/route-proxy/ca:/ca:ro"
"${dir:routes-dir}:/routes:ro",
"${dir:acme-cache}:/acme",
"${dir:ca-dir}:/ca:ro"
],
"env": {
"ROUTES": "/routes/mesh.json",
+8 -8
View File
@@ -20,10 +20,10 @@
"postgres-database"
],
"binds": {
"postgres-database": "/var/lib/showcase/database.json"
"postgres-database": "${dir:state}/database.json"
},
"secrets": {
"postgres-database": "/var/lib/showcase/database.secret"
"postgres-database": "${dir:state}/database.secret"
},
"own-secrets": {
"broker": "/var/lib/mesh/showcase/broker"
@@ -100,13 +100,13 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/showcase",
"mode": "0755"
"mode": "0755",
"place": "."
},
{
"id": "settings",
"type": "file",
"path": "/var/lib/showcase/showcase.env",
"path": "${dir:state}/showcase.env",
"mode": "0600",
"content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n"
},
@@ -137,7 +137,7 @@
],
"run-once": true,
"env-file": [
"/var/lib/showcase/showcase.env"
"${dir:state}/showcase.env"
]
},
{
@@ -151,7 +151,7 @@
],
"user": "showcase",
"env-file": [
"/var/lib/showcase/showcase.env"
"${dir:state}/showcase.env"
],
"restart-on": [
"settings"
@@ -168,7 +168,7 @@
],
"schedule": "0 3 * * *",
"env-file": [
"/var/lib/showcase/showcase.env"
"${dir:state}/showcase.env"
]
},
{
+3 -3
View File
@@ -46,9 +46,9 @@
{
"id": "home",
"type": "directory",
"path": "/var/lib/step-ca",
"mode": "0700",
"owner": "1000:1000"
"owner": "1000:1000",
"place": "."
},
{
"id": "config",
@@ -80,7 +80,7 @@
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false"
},
"volumes": [
"/var/lib/step-ca:/home/step",
"${dir:home}:/home/step",
"/var/lib/mesh/step-ca:/run/mesh:ro"
],
"secrets-in-environment": "the entrypoint honours DOCKER_STEPCA_INIT_PASSWORD_FILE; convertible, awaiting a bed that proves it"
+18 -19
View File
@@ -19,14 +19,14 @@
}
},
"binds": {
"postgres-database": "/var/lib/umami/database.json",
"route": "/var/lib/umami/route.json"
"postgres-database": "${dir:state}/database.json",
"route": "${dir:state}/route.json"
},
"secrets": {
"postgres-database": "/var/lib/umami/database.secret",
"postgres-database": "${dir:state}/database.secret",
"secret": {
"app-secret": "/var/lib/umami/app.secret",
"admin": "/var/lib/umami/admin.secret"
"app-secret": "${dir:state}/app.secret",
"admin": "${dir:state}/admin.secret"
}
},
"provides": [
@@ -39,10 +39,10 @@
"analytics": {}
},
"receives": {
"analytics": "/var/lib/umami/grants/mesh.json"
"analytics": "${dir:grants}/mesh.json"
},
"grants": {
"analytics": "/var/lib/umami/grants"
"analytics": "${dir:grants}"
},
"own-secrets": {
"broker": "/var/lib/mesh/umami/broker"
@@ -53,7 +53,7 @@
"port": 3000,
"protocol": "tcp",
"from": "mesh",
"why": "one port serves two surfaces \u2014 the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path"
"why": "one port serves two surfaces — the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path"
}
],
"resources": [
@@ -66,28 +66,27 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/umami",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/umami/grants",
"mode": "0700"
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/umami/server.env",
"path": "${dir:state}/server.env",
"mode": "0600",
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
},
{
"id": "provisioner-env",
"type": "file",
"path": "/var/lib/umami/provisioner.env",
"path": "${dir:state}/provisioner.env",
"mode": "0600",
"content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=/var/lib/umami/grants\n"
"content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=${dir:grants}\n"
},
{
"id": "net",
@@ -101,7 +100,7 @@
"image": "ghcr.io/umami-software/umami@sha256:85909afc45bdcda1917394594a087421fdbb05610fded0fa9f6fb861abb2f367",
"network": "umami",
"env-file": [
"/var/lib/umami/server.env"
"${dir:state}/server.env"
],
"ports": [
"3000"
@@ -115,16 +114,16 @@
"network": "umami",
"volumes": [
"/var/lib/mesh/umami/broker:/run/secrets/broker:ro",
"/var/lib/umami/grants:/var/lib/umami/grants",
"/var/lib/umami/admin.secret:/run/secrets/admin:ro"
"${dir:grants}:${dir:grants}",
"${dir:state}/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
},
"env-file": [
"/var/lib/umami/provisioner.env"
"${dir:state}/provisioner.env"
],
"artifact": "runtime"
}