From f79199777d39480bc2ef57ecaa1b36a16097c925 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 23:33:51 +0200 Subject: [PATCH] minio: its tools and provisioner run in the node's runtime (hq ADR 0198) The mesh-minio container goes with its Dockerfile, build bases, bus credential and state directory. The client reaches minio on the published port, runs the minio-client package's mcli instead of the image's mc, and keeps mc's config, which holds the root alias, in the module's own state directory rather than a shared /tmp. --- modules/minio/Dockerfile | 40 ----------------------- modules/minio/module.json | 69 ++++++++++++++------------------------- 2 files changed, 24 insertions(+), 85 deletions(-) delete mode 100644 modules/minio/Dockerfile diff --git a/modules/minio/Dockerfile b/modules/minio/Dockerfile deleted file mode 100644 index fc0e121..0000000 --- a/modules/minio/Dockerfile +++ /dev/null @@ -1,40 +0,0 @@ -# minio's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE -ARG MC_CLI - -# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder -# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM. -FROM ${MC_CLI} AS mccli - -FROM ${BUILD_BASE} AS build -# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own -# node_modules — the module is compiled against exactly the sdk it will run against. The compiler -# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image -# resolved away. -WORKDIR /app/modules/minio -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/minio/dist /app/modules/minio/dist -# The provisioner shells out to mc to actually create buckets and service accounts on the running -# minio server — mc itself was never in this runtime image, only in minio's own. Silently retried -# "spawn mc ENOENT" forever: a requirement was granted at the control-plane level without ever -# materializing the credential on minio. /usr/bin/mc there is a symlink to the real binary, mcli — -# both copied so the symlink resolves. -COPY --from=mccli /usr/bin/mcli /usr/bin/mcli -COPY --from=mccli /usr/bin/mc /usr/bin/mc -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js diff --git a/modules/minio/module.json b/modules/minio/module.json index eb304b4..1d1f045 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -59,16 +59,9 @@ "s3-bucket": "${dir:grants}" }, "own-secrets": { - "root": "${dir:state}/root.secret", - "broker": "${dir:mesh-state}/broker" + "root": "${dir:state}/root.secret" }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -127,48 +120,34 @@ } }, { - "id": "runtime", - "type": "container", - "name": "mesh-minio", - "network": "minio-net", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:grants}:${dir:grants}:ro", - "${dir:state}/root.secret:/run/secrets/root:ro" - ], - "env": { - "MESH_MINIO_ENDPOINT": "http://minio:9000", - "MESH_MINIO_ROOT_USER": "meshroot", - "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", - "MESH_MINIO_REGION": "eu-west", - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "${dir:grants}/mesh.json" - }, - "artifact": "runtime" + "id": "client", + "type": "package", + "package": "minio-client" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - }, - { - "arg": "MC_CLI", - "image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js", + "provisioner/index.js" + ], + "loads": [ + "tools/index.js", + "provisioner/index.js" + ], + "env": { + "MESH_MINIO_ENDPOINT": "http://127.0.0.1:${port:9000}", + "MESH_MINIO_ROOT_USER": "meshroot", + "MESH_MINIO_ROOT_PASSWORD_FILE": "${dir:state}/root.secret", + "MESH_MINIO_REGION": "eu-west", + "MESH_MINIO_MC_BIN": "mcli", + "MESH_MINIO_MC_CONFIG": "${dir:state}/mc", + "MESH_RECEIVES": "${dir:grants}/mesh.json" + } } ] }