minio: full nox module — client, tools, provisioner and events (ADR 0044/0045/0046)

Object store, an s3-bucket provider. Client ported with no npm deps: S3 data
plane over fetch + SigV4 (node:crypto), scoped access keys via the mc CLI (the
admin API needs an Argon2 payload node built-ins can't make — the honest port
hal also used). Tools: list buckets/objects, bucket info, presigned url. The
provisioner makes a bucket + scoped key per grant and emits
module.minio.bucket.created/removed (the secret stays off the bus). Typechecks;
manifest parses.

(Trimmed the generated self-consuming ledger: a provider need not subscribe to
its own emits.)
This commit is contained in:
2026-09-04 02:35:51 +02:00
parent fb42fb956b
commit f689b7dfa6
6 changed files with 537 additions and 5 deletions
+10 -5
View File
@@ -10,6 +10,10 @@
"capabilities": [
"container-runtime"
],
"emits": [
"module.minio.bucket.created",
"module.minio.bucket.removed"
],
"listens": [
{
"port": 9000,
@@ -31,7 +35,8 @@
"s3-bucket": "/var/lib/minio/grants"
},
"own-secrets": {
"root": "/var/lib/minio/root.secret"
"root": "/var/lib/minio/root.secret",
"broker": "/var/lib/minio/broker"
},
"resources": [
{
@@ -94,9 +99,9 @@
"network": "minio",
"env": {
"GRANTS": "/var/lib/minio/grants",
"MESH_OBJECTSTORE_URL": "http://minio:9000",
"MESH_OBJECTSTORE_ROOT_USER": "meshroot",
"MESH_OBJECTSTORE_ROOT_PASSWORD_FILE": "/run/secrets/root"
"MESH_MINIO_ENDPOINT": "http://minio:9000",
"MESH_MINIO_ROOT_USER": "meshroot",
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root"
},
"volumes": [
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
@@ -104,4 +109,4 @@
]
}
]
}
}