Merge pull request 'Rename seat claims to mesh-*/node-*; retire verdaccio (ADR 0121)' (#112) from feat/system-seats-named-by-scope into main
This commit was merged in pull request #112.
This commit is contained in:
@@ -6,8 +6,8 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-build-machine",
|
"name": "mesh-build-machine",
|
||||||
"scope": "node"
|
"scope": "mesh"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-uplink",
|
"name": "node-uplink",
|
||||||
"scope": "node"
|
"scope": "node"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -6,7 +6,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-intrusion-prevention",
|
"name": "node-intrusion-prevention",
|
||||||
"scope": "node"
|
"scope": "node"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-catalogue",
|
"name": "mesh-catalog",
|
||||||
"scope": "mesh"
|
"scope": "mesh"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-uplink",
|
"name": "node-uplink",
|
||||||
"scope": "node"
|
"scope": "node"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -6,7 +6,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-packet-filter",
|
"name": "node-packet-filter",
|
||||||
"scope": "node"
|
"scope": "node"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
@@ -30,7 +30,7 @@
|
|||||||
"id": "stock-unit-stop",
|
"id": "stock-unit-stop",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
||||||
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) \u2014 a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
||||||
"mode": "0644"
|
"mode": "0644"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -2,12 +2,22 @@
|
|||||||
"module": "resolv-conf",
|
"module": "resolv-conf",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
"slug": "resolv",
|
"slug": "resolv",
|
||||||
|
"requires": [
|
||||||
"requires": ["wildcard-resolution"],
|
"wildcard-resolution"
|
||||||
"claims": [{"name": "the-resolver-configuration", "scope": "node"}],
|
],
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "node-resolver-config",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{"id": "resolv", "type": "file", "path": "/etc/resolv.conf", "mode": "0644",
|
{
|
||||||
"content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead — this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's resolver, and only it — the one line the predecessor wrote on every\n# machine it set up. It answers the mesh's names itself and forwards everything\n# else to upstreams named in its own configuration, never read from this file.\n# This file used to carry a second nameserver as a placeholder for \"whatever\n# this machine used before\"; that was never a fallback for names the mesh does\n# not know — a resolver's second line is asked only when the first does not\n# answer at all — and now that the first answers everything it would be a line\n# nothing ever reached.\nnameserver 127.0.0.1\noptions edns0\n"}
|
"id": "resolv",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/resolv.conf",
|
||||||
|
"mode": "0644",
|
||||||
|
"content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead \u2014 this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's resolver, and only it \u2014 the one line the predecessor wrote on every\n# machine it set up. It answers the mesh's names itself and forwards everything\n# else to upstreams named in its own configuration, never read from this file.\n# This file used to carry a second nameserver as a placeholder for \"whatever\n# this machine used before\"; that was never a fallback for names the mesh does\n# not know \u2014 a resolver's second line is asked only when the first does not\n# answer at all \u2014 and now that the first answers everything it would be a line\n# nothing ever reached.\nnameserver 127.0.0.1\noptions edns0\n"
|
||||||
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,18 +2,38 @@
|
|||||||
"module": "resolved-split-dns",
|
"module": "resolved-split-dns",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
"slug": "splitdns",
|
"slug": "splitdns",
|
||||||
|
"requires": [
|
||||||
"requires": ["wildcard-resolution"],
|
"wildcard-resolution"
|
||||||
"claims": [{"name": "the-resolver-configuration", "scope": "node"}],
|
],
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "node-resolver-config",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{"id": "drop-in", "type": "directory", "path": "/etc/systemd/resolved.conf.d", "mode": "0755"},
|
{
|
||||||
|
"id": "drop-in",
|
||||||
{"id": "route", "type": "file",
|
"type": "directory",
|
||||||
"path": "/etc/systemd/resolved.conf.d/mesh.conf", "mode": "0644",
|
"path": "/etc/systemd/resolved.conf.d",
|
||||||
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims. The mesh's resolver can forward the rest too;\n# this module is for a machine that wants systemd-resolved to stay in charge of\n# that, and only lends it the mesh's suffix.\n#\n# 127.0.0.1 is where the mesh's resolver answers on every machine — a fixed\n# address, so this file needs to know nothing about this particular machine.\n# systemd-resolved holds .53 and .54 itself, which is why the resolver is on\n# neither, and why the two coexist here.\n[Resolve]\nDNS=127.0.0.1\nDomains=~internal\n"},
|
"mode": "0755"
|
||||||
|
},
|
||||||
{"id": "resolved", "type": "service", "unit": "systemd-resolved.service",
|
{
|
||||||
"state": "running", "boot": "enabled", "restart-on": ["route"]}
|
"id": "route",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/resolved.conf.d/mesh.conf",
|
||||||
|
"mode": "0644",
|
||||||
|
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims. The mesh's resolver can forward the rest too;\n# this module is for a machine that wants systemd-resolved to stay in charge of\n# that, and only lends it the mesh's suffix.\n#\n# 127.0.0.1 is where the mesh's resolver answers on every machine \u2014 a fixed\n# address, so this file needs to know nothing about this particular machine.\n# systemd-resolved holds .53 and .54 itself, which is why the resolver is on\n# neither, and why the two coexist here.\n[Resolve]\nDNS=127.0.0.1\nDomains=~internal\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "resolved",
|
||||||
|
"type": "service",
|
||||||
|
"unit": "systemd-resolved.service",
|
||||||
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
|
"restart-on": [
|
||||||
|
"route"
|
||||||
|
]
|
||||||
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
+182
-59
@@ -2,72 +2,195 @@
|
|||||||
"module": "showcase",
|
"module": "showcase",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
"slug": "show",
|
"slug": "show",
|
||||||
|
"capabilities": [
|
||||||
"capabilities": ["container-runtime"],
|
"container-runtime"
|
||||||
|
],
|
||||||
"provides": [{ "name": "greeting", "scope": "mesh" }],
|
"provides": [
|
||||||
"serves": { "greeting": { "path": "/greeting" } },
|
{
|
||||||
"requires": ["postgres-database"],
|
"name": "greeting",
|
||||||
"binds": { "postgres-database": "/var/lib/showcase/database.json" },
|
"scope": "mesh"
|
||||||
"secrets": { "postgres-database": "/var/lib/showcase/database.secret" },
|
}
|
||||||
"own-secrets": { "broker": "/var/lib/mesh/showcase/broker" },
|
],
|
||||||
|
"serves": {
|
||||||
"claims": [{ "name": "the-showcase", "scope": "node" }],
|
"greeting": {
|
||||||
|
"path": "/greeting"
|
||||||
"emits": ["module.showcase.acknowledged"],
|
}
|
||||||
"consumes": ["module.showcase.greeted"],
|
},
|
||||||
|
"requires": [
|
||||||
|
"postgres-database"
|
||||||
|
],
|
||||||
|
"binds": {
|
||||||
|
"postgres-database": "/var/lib/showcase/database.json"
|
||||||
|
},
|
||||||
|
"secrets": {
|
||||||
|
"postgres-database": "/var/lib/showcase/database.secret"
|
||||||
|
},
|
||||||
|
"own-secrets": {
|
||||||
|
"broker": "/var/lib/mesh/showcase/broker"
|
||||||
|
},
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "the-showcase",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"emits": [
|
||||||
|
"module.showcase.acknowledged"
|
||||||
|
],
|
||||||
|
"consumes": [
|
||||||
|
"module.showcase.greeted"
|
||||||
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{ "port": 8080, "protocol": "tcp", "from": "mesh",
|
{
|
||||||
"why": "the port the daemon itself listens on. The mesh assigns the machine-side number and tells consumers that one (ADR 0038)" }
|
"port": 8080,
|
||||||
|
"protocol": "tcp",
|
||||||
|
"from": "mesh",
|
||||||
|
"why": "the port the daemon itself listens on. The mesh assigns the machine-side number and tells consumers that one (ADR 0038)"
|
||||||
|
}
|
||||||
],
|
],
|
||||||
|
|
||||||
"build": {
|
"build": {
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{ "name": "code", "kind": "bundle", "language": "typescript",
|
{
|
||||||
"entrypoints": ["index.js", "tools/index.js", "provisioner/index.js",
|
"name": "code",
|
||||||
"daemon/index.js", "step/index.js", "report/index.js"] },
|
"kind": "bundle",
|
||||||
{ "name": "files", "kind": "archive", "from": "files" },
|
"language": "typescript",
|
||||||
{ "name": "helper", "kind": "upstream",
|
"entrypoints": [
|
||||||
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b" }
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js",
|
||||||
|
"daemon/index.js",
|
||||||
|
"step/index.js",
|
||||||
|
"report/index.js"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "files",
|
||||||
|
"kind": "archive",
|
||||||
|
"from": "files"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "helper",
|
||||||
|
"kind": "upstream",
|
||||||
|
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b"
|
||||||
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
|
||||||
"resources": [
|
"resources": [
|
||||||
{ "id": "account", "type": "user", "name": "showcase", "shell": "/usr/bin/nologin",
|
{
|
||||||
"home": "/var/lib/showcase" },
|
"id": "account",
|
||||||
|
"type": "user",
|
||||||
{ "id": "logs", "type": "access", "path": "/var/log", "mode": "0755" },
|
"name": "showcase",
|
||||||
|
"shell": "/usr/bin/nologin",
|
||||||
{ "id": "mesh-state", "type": "directory", "path": "/var/lib/mesh/showcase", "mode": "0700" },
|
"home": "/var/lib/showcase"
|
||||||
{ "id": "state", "type": "directory", "path": "/var/lib/showcase", "mode": "0755" },
|
},
|
||||||
|
{
|
||||||
{ "id": "settings", "type": "file", "path": "/var/lib/showcase/showcase.env", "mode": "0600",
|
"id": "logs",
|
||||||
"content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n" },
|
"type": "access",
|
||||||
|
"path": "/var/log",
|
||||||
{ "id": "packed", "type": "archive", "path": "/opt/showcase", "artifact": "files" },
|
"mode": "0755"
|
||||||
|
},
|
||||||
{ "id": "net", "type": "network", "name": "showcase" },
|
{
|
||||||
|
"id": "mesh-state",
|
||||||
{ "id": "tooling", "type": "package", "package": "jq" },
|
"type": "directory",
|
||||||
|
"path": "/var/lib/mesh/showcase",
|
||||||
{ "id": "migrate", "type": "process", "name": "showcase-migrate", "artifact": "code",
|
"mode": "0700"
|
||||||
"run": ["node", "step/index.js"], "run-once": true,
|
},
|
||||||
"env-file": ["/var/lib/showcase/showcase.env"] },
|
{
|
||||||
|
"id": "state",
|
||||||
{ "id": "server", "type": "process", "name": "showcase", "artifact": "code",
|
"type": "directory",
|
||||||
"run": ["node", "daemon/index.js"], "user": "showcase",
|
"path": "/var/lib/showcase",
|
||||||
"env-file": ["/var/lib/showcase/showcase.env"],
|
"mode": "0755"
|
||||||
"restart-on": ["settings"] },
|
},
|
||||||
|
{
|
||||||
{ "id": "reporting", "type": "process", "name": "showcase-report", "artifact": "code",
|
"id": "settings",
|
||||||
"run": ["node", "report/index.js"], "schedule": "0 3 * * *",
|
"type": "file",
|
||||||
"env-file": ["/var/lib/showcase/showcase.env"] },
|
"path": "/var/lib/showcase/showcase.env",
|
||||||
|
"mode": "0600",
|
||||||
{ "id": "tools", "type": "container", "name": "mesh-showcase", "artifact": "helper",
|
"content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "packed",
|
||||||
|
"type": "archive",
|
||||||
|
"path": "/opt/showcase",
|
||||||
|
"artifact": "files"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "net",
|
||||||
|
"type": "network",
|
||||||
|
"name": "showcase"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "tooling",
|
||||||
|
"type": "package",
|
||||||
|
"package": "jq"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "migrate",
|
||||||
|
"type": "process",
|
||||||
|
"name": "showcase-migrate",
|
||||||
|
"artifact": "code",
|
||||||
|
"run": [
|
||||||
|
"node",
|
||||||
|
"step/index.js"
|
||||||
|
],
|
||||||
|
"run-once": true,
|
||||||
|
"env-file": [
|
||||||
|
"/var/lib/showcase/showcase.env"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "server",
|
||||||
|
"type": "process",
|
||||||
|
"name": "showcase",
|
||||||
|
"artifact": "code",
|
||||||
|
"run": [
|
||||||
|
"node",
|
||||||
|
"daemon/index.js"
|
||||||
|
],
|
||||||
|
"user": "showcase",
|
||||||
|
"env-file": [
|
||||||
|
"/var/lib/showcase/showcase.env"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"settings"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "reporting",
|
||||||
|
"type": "process",
|
||||||
|
"name": "showcase-report",
|
||||||
|
"artifact": "code",
|
||||||
|
"run": [
|
||||||
|
"node",
|
||||||
|
"report/index.js"
|
||||||
|
],
|
||||||
|
"schedule": "0 3 * * *",
|
||||||
|
"env-file": [
|
||||||
|
"/var/lib/showcase/showcase.env"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "tools",
|
||||||
|
"type": "container",
|
||||||
|
"name": "mesh-showcase",
|
||||||
|
"artifact": "helper",
|
||||||
"network": "showcase",
|
"network": "showcase",
|
||||||
"volumes": ["/var/lib/mesh/showcase/broker:/run/secrets/broker:ro"],
|
"volumes": [
|
||||||
"env": { "MESH_BROKER_FILE": "/run/secrets/broker" },
|
"/var/lib/mesh/showcase/broker:/run/secrets/broker:ro"
|
||||||
"args": ["sleep", "infinity"] }
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_BROKER_FILE": "/run/secrets/broker"
|
||||||
|
},
|
||||||
|
"args": [
|
||||||
|
"sleep",
|
||||||
|
"infinity"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"seats": [
|
||||||
|
{
|
||||||
|
"name": "the-showcase",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-uplink",
|
"name": "node-uplink",
|
||||||
"scope": "node"
|
"scope": "node"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
# verdaccio's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/verdaccio
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/verdaccio/dist /app/modules/verdaccio/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/verdaccio/dist/index.js,/app/modules/verdaccio/dist/tools/index.js
|
|
||||||
@@ -1,91 +0,0 @@
|
|||||||
// The Verdaccio (npm registry) client — verdaccio's own code, living in the module (novox/hq
|
|
||||||
// ADR 0039). Both this module's tools and its events entrypoint import it, and nothing outside
|
|
||||||
// verdaccio does.
|
|
||||||
|
|
||||||
import { readFileSync } from "node:fs";
|
|
||||||
|
|
||||||
export interface VerdaccioPackage {
|
|
||||||
name: string;
|
|
||||||
version?: string;
|
|
||||||
description?: string;
|
|
||||||
time?: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface PackageInfo {
|
|
||||||
name: string;
|
|
||||||
latest?: string;
|
|
||||||
versions: string[];
|
|
||||||
description?: string;
|
|
||||||
modified?: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
/** The settings-merged config the mesh delivers (novox/hq ADR 0046): { url, apiKey, token, password, user, ... }. */
|
|
||||||
function meshConfig(file?: string): Record<string, string> {
|
|
||||||
if (!file) return {};
|
|
||||||
try { return JSON.parse(readFileSync(file, "utf8")) as Record<string, string>; }
|
|
||||||
catch { return {}; }
|
|
||||||
}
|
|
||||||
|
|
||||||
export class VerdaccioClient {
|
|
||||||
readonly baseUrl: string;
|
|
||||||
|
|
||||||
// A bearer token is optional: package listing and reading are public on most registries, so the
|
|
||||||
// token is sent only when configured, for a registry that gates reads behind auth.
|
|
||||||
constructor(
|
|
||||||
url: string,
|
|
||||||
private readonly token?: string,
|
|
||||||
) {
|
|
||||||
this.baseUrl = url.replace(/\/+$/, "");
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Build from the module's resolved environment. The URL is MESH_VERDACCIO_URL (or the local
|
|
||||||
* port); an optional MESH_VERDACCIO_TOKEN authenticates. Throws when no URL is configured.
|
|
||||||
*/
|
|
||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): VerdaccioClient {
|
|
||||||
const cfg = meshConfig(env.MESH_VERDACCIO_CONFIG_FILE);
|
|
||||||
const url = cfg.url ?? (env.MESH_VERDACCIO_URL ?? `http://127.0.0.1:${env.VERDACCIO_PORT ?? "4873"}`);
|
|
||||||
if (!url) throw new Error("no verdaccio URL — set MESH_VERDACCIO_URL");
|
|
||||||
return new VerdaccioClient(url, cfg.token ?? env.MESH_VERDACCIO_TOKEN);
|
|
||||||
}
|
|
||||||
|
|
||||||
private async getJson<T>(path: string): Promise<T> {
|
|
||||||
const res = await fetch(`${this.baseUrl}${path}`, {
|
|
||||||
headers: {
|
|
||||||
Accept: "application/json",
|
|
||||||
...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (!res.ok) throw new Error(`Verdaccio ${path}: ${res.status} ${await res.text()}`);
|
|
||||||
return res.json() as Promise<T>;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Every package the registry hosts, from Verdaccio's own web API — the same list its UI shows.
|
|
||||||
* Each entry carries the latest version and the time it was last published.
|
|
||||||
*/
|
|
||||||
async listPackages(): Promise<VerdaccioPackage[]> {
|
|
||||||
const raw = await this.getJson<any[]>("/-/verdaccio/data/packages");
|
|
||||||
return (raw ?? []).map((p) => ({
|
|
||||||
name: p.name,
|
|
||||||
version: p.version ?? p["dist-tags"]?.latest,
|
|
||||||
description: p.description,
|
|
||||||
time: p.time?.modified ?? p.time,
|
|
||||||
}));
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* The full detail of one package — its dist-tags, every published version, and timestamps —
|
|
||||||
* from the standard npm packument endpoint (`GET /<name>`).
|
|
||||||
*/
|
|
||||||
async getPackageInfo(name: string): Promise<PackageInfo> {
|
|
||||||
const doc = await this.getJson<any>(`/${encodeURIComponent(name).replace(/%2F/g, "/")}`);
|
|
||||||
return {
|
|
||||||
name: doc.name ?? name,
|
|
||||||
latest: doc["dist-tags"]?.latest,
|
|
||||||
versions: Object.keys(doc.versions ?? {}),
|
|
||||||
description: doc.description,
|
|
||||||
modified: doc.time?.modified,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
// verdaccio's events. The tool runtime imports this once the broker is bound.
|
|
||||||
//
|
|
||||||
// Emits (novox/hq ADR 0041/0042):
|
|
||||||
// module.verdaccio.package.published — a new package version was published to the registry
|
|
||||||
//
|
|
||||||
// A genuinely useful signal: a package was just published, so anything on the mesh that pins,
|
|
||||||
// mirrors or announces dependency releases can react without polling the registry. Verdaccio has
|
|
||||||
// no publish webhook, so the module discovers it by diffing the package list's latest versions.
|
|
||||||
//
|
|
||||||
// The polling is deliberately unhurried: a publish a minute late is still the event, whereas
|
|
||||||
// hammering the registry for immediacy nobody asked for is not.
|
|
||||||
|
|
||||||
import { emit } from "@novox/mesh-sdk/events";
|
|
||||||
import { VerdaccioClient } from "./client.js";
|
|
||||||
|
|
||||||
const verdaccio = VerdaccioClient.fromEnv();
|
|
||||||
|
|
||||||
// The latest version we have seen per package name. Primed silently on the first look so a registry
|
|
||||||
// that was already populated when this started does not announce its whole catalog as freshly
|
|
||||||
// published.
|
|
||||||
const latest = new Map<string, string>();
|
|
||||||
let primed = false;
|
|
||||||
|
|
||||||
async function pollPackages(): Promise<void> {
|
|
||||||
const packages = await verdaccio.listPackages();
|
|
||||||
for (const pkg of packages) {
|
|
||||||
if (!pkg.version) continue;
|
|
||||||
const known = latest.get(pkg.name);
|
|
||||||
if (known !== pkg.version) {
|
|
||||||
// A name we have not seen, or a name whose latest version moved — both are a publish.
|
|
||||||
if (primed) await emit("module.verdaccio.package.published", { name: pkg.name, version: pkg.version });
|
|
||||||
latest.set(pkg.name, pkg.version);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
primed = true;
|
|
||||||
}
|
|
||||||
|
|
||||||
const tick = (fn: () => Promise<void>, everyMs: number): void => {
|
|
||||||
const run = (): void => void fn().catch((err) => console.error(`[verdaccio] ${err}`));
|
|
||||||
setInterval(run, everyMs);
|
|
||||||
run();
|
|
||||||
};
|
|
||||||
tick(pollPackages, 60_000);
|
|
||||||
|
|
||||||
console.log("[verdaccio] watching the registry for newly published packages");
|
|
||||||
@@ -1,130 +0,0 @@
|
|||||||
{
|
|
||||||
"module": "verdaccio",
|
|
||||||
"version": "1",
|
|
||||||
"slug": "verdacc",
|
|
||||||
"capabilities": [
|
|
||||||
"container-runtime"
|
|
||||||
],
|
|
||||||
"emits": [
|
|
||||||
"module.verdaccio.package.published"
|
|
||||||
],
|
|
||||||
"own-secrets": {
|
|
||||||
"broker": "/var/lib/mesh/verdaccio/broker"
|
|
||||||
},
|
|
||||||
"listens": [
|
|
||||||
{
|
|
||||||
"port": 4873,
|
|
||||||
"protocol": "tcp",
|
|
||||||
"from": "mesh",
|
|
||||||
"why": "the package registry, for installs and publishes"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"resources": [
|
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"path": "/var/lib/mesh/verdaccio",
|
|
||||||
"mode": "0700"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "conf",
|
|
||||||
"type": "directory",
|
|
||||||
"path": "/services/verdaccio/conf",
|
|
||||||
"mode": "0755",
|
|
||||||
"owner": "10001:10001"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "storage",
|
|
||||||
"type": "directory",
|
|
||||||
"path": "/services/verdaccio/storage",
|
|
||||||
"mode": "0700",
|
|
||||||
"owner": "10001:10001"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "config",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/services/verdaccio/conf/config.yaml",
|
|
||||||
"mode": "0644",
|
|
||||||
"content": "storage: /verdaccio/storage\nauth:\n htpasswd:\n file: /verdaccio/conf/htpasswd\n max_users: 10\nuplinks:\n npmjs:\n url: https://registry.npmjs.org/\npackages:\n \"**\":\n access: $all\n publish: $authenticated\n proxy: npmjs\nserver:\n keepAliveTimeout: 60\n maxBodySize: 10mb\nmiddlewares:\n audit:\n enabled: true\nlog:\n type: stdout\n format: pretty\n level: http\n"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "server",
|
|
||||||
"type": "container",
|
|
||||||
"name": "verdaccio",
|
|
||||||
"image": "verdaccio/verdaccio@sha256:7b067a47ae51fb9dff3dcdce60ec0a2cbd7650c208cb4b9f6d37cb1b09b39d43",
|
|
||||||
"ports": [
|
|
||||||
"4873"
|
|
||||||
],
|
|
||||||
"volumes": [
|
|
||||||
"/services/verdaccio/storage:/verdaccio/storage",
|
|
||||||
"/services/verdaccio/conf:/verdaccio/conf"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime-config",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/mesh/verdaccio/config.json",
|
|
||||||
"mode": "0600",
|
|
||||||
"content": "{}\n",
|
|
||||||
"merge": "json"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-verdaccio",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"/var/lib/mesh/verdaccio/broker:/run/secrets/broker:ro",
|
|
||||||
"/var/lib/mesh/verdaccio/config.json:/run/config/config.json:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_VERDACCIO_URL": "http://127.0.0.1:4873",
|
|
||||||
"MESH_VERDACCIO_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"requires": [
|
|
||||||
"route"
|
|
||||||
],
|
|
||||||
"contributes": {
|
|
||||||
"route": {
|
|
||||||
"label": "npm",
|
|
||||||
"port": 4873
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"binds": {
|
|
||||||
"route": "/var/lib/mesh/verdaccio/route.json"
|
|
||||||
},
|
|
||||||
"provides": [
|
|
||||||
{
|
|
||||||
"name": "npm-package-registry",
|
|
||||||
"scope": "mesh"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"build": {
|
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
|
||||||
{
|
|
||||||
"name": "runtime",
|
|
||||||
"kind": "image",
|
|
||||||
"from": "Dockerfile"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
{
|
|
||||||
"name": "@novox/module-verdaccio",
|
|
||||||
"version": "0.1.0",
|
|
||||||
"description": "verdaccio — private npm registry. Its API client, tools and events live here (novox/hq ADR 0039).",
|
|
||||||
"type": "module",
|
|
||||||
"private": true,
|
|
||||||
"dependencies": {
|
|
||||||
"@novox/mesh-sdk": "^0.1.0"
|
|
||||||
},
|
|
||||||
"devDependencies": {
|
|
||||||
"@types/node": "^22.0.0",
|
|
||||||
"typescript": "^5.6.0"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
// verdaccio's tools — its own code (novox/hq ADR 0039), importing verdaccio's own client. They
|
|
||||||
// return structured data; the mesh serves them through the sdk's tool harness.
|
|
||||||
|
|
||||||
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
|
||||||
import { VerdaccioClient } from "../client.js";
|
|
||||||
|
|
||||||
export function getVerdaccioTools(verdaccio: VerdaccioClient): ToolDefinition[] {
|
|
||||||
return [
|
|
||||||
{
|
|
||||||
name: "verdaccio_list_packages",
|
|
||||||
description: "List every package hosted on the private npm registry, with each one's latest version.",
|
|
||||||
input: {},
|
|
||||||
run: async () => {
|
|
||||||
const packages = await verdaccio.listPackages();
|
|
||||||
return { count: packages.length, packages };
|
|
||||||
},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "verdaccio_package_info",
|
|
||||||
description: "Details of one package on the registry: its latest tag, all published versions, and description.",
|
|
||||||
input: { name: { type: "string", description: "the package name, e.g. '@novox/mesh-sdk'" } },
|
|
||||||
run: async (args) => verdaccio.getPackageInfo(String(args.name)),
|
|
||||||
},
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
// The tools exist only when a registry URL is configured; otherwise verdaccio contributes none
|
|
||||||
// rather than failing the whole runtime.
|
|
||||||
registerModuleTools("verdaccio", (env) => {
|
|
||||||
try {
|
|
||||||
return getVerdaccioTools(VerdaccioClient.fromEnv(env));
|
|
||||||
} catch {
|
|
||||||
return [];
|
|
||||||
}
|
|
||||||
});
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
{
|
|
||||||
"compilerOptions": {
|
|
||||||
"target": "ES2022",
|
|
||||||
"module": "NodeNext",
|
|
||||||
"moduleResolution": "NodeNext",
|
|
||||||
"strict": true,
|
|
||||||
"esModuleInterop": true,
|
|
||||||
"skipLibCheck": true,
|
|
||||||
"noEmit": true
|
|
||||||
},
|
|
||||||
"include": ["client.ts", "index.ts", "tools/index.ts"]
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user