diff --git a/modules/gitea/module.json b/modules/gitea/module.json index cd11944..90f6eb2 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -3,7 +3,8 @@ "version": "1", "requires": [ "postgres-database", - "route" + "route", + "secret" ], "contributes": { "postgres-database": { @@ -19,7 +20,11 @@ "route": "/var/lib/gitea/route.json" }, "secrets": { - "postgres-database": "/var/lib/gitea/database.secret" + "postgres-database": "/var/lib/gitea/database.secret", + "secret": { + "internal-token": "/var/lib/gitea/internal-token.secret", + "admin": "/var/lib/gitea/admin.secret" + } }, "capabilities": [ "container-runtime" @@ -57,8 +62,6 @@ "package-registry": "/var/lib/gitea/grants" }, "own-secrets": { - "internal-token": "/var/lib/gitea/internal-token.secret", - "admin": "/var/lib/gitea/admin.secret", "broker": "/var/lib/mesh/gitea/broker" }, "resources": [ diff --git a/modules/icecast/module.json b/modules/icecast/module.json index 82f1ba3..cdbef64 100644 --- a/modules/icecast/module.json +++ b/modules/icecast/module.json @@ -9,9 +9,6 @@ "module.icecast.stream.stopped" ], "own-secrets": { - "source": "/var/lib/icecast-module/source.secret", - "admin": "/var/lib/icecast-module/admin.secret", - "relay": "/var/lib/icecast-module/relay.secret", "broker": "/var/lib/mesh/icecast/broker" }, "listens": [ @@ -103,5 +100,15 @@ "from": "Dockerfile" } ] + }, + "requires": [ + "secret" + ], + "secrets": { + "secret": { + "source": "/var/lib/icecast-module/source.secret", + "admin": "/var/lib/icecast-module/admin.secret", + "relay": "/var/lib/icecast-module/relay.secret" + } } } diff --git a/modules/influxdb/module.json b/modules/influxdb/module.json index 6102067..54d4a93 100644 --- a/modules/influxdb/module.json +++ b/modules/influxdb/module.json @@ -5,8 +5,6 @@ "container-runtime" ], "own-secrets": { - "admin": "/var/lib/influxdb-module/admin.secret", - "admin-token": "/var/lib/influxdb-module/admin-token.secret", "broker": "/var/lib/mesh/influxdb/broker" }, "listens": [ @@ -118,5 +116,14 @@ "from": "Dockerfile" } ] + }, + "requires": [ + "secret" + ], + "secrets": { + "secret": { + "admin": "/var/lib/influxdb-module/admin.secret", + "admin-token": "/var/lib/influxdb-module/admin-token.secret" + } } } diff --git a/modules/mailu/module.json b/modules/mailu/module.json index ee67fbb..9a7239c 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -6,7 +6,8 @@ ], "requires": [ "postgres-database", - "route" + "route", + "secret" ], "contributes": { "postgres-database": { @@ -22,7 +23,12 @@ "route": "/var/lib/mailu/route.json" }, "secrets": { - "postgres-database": "/var/lib/mailu/database.secret" + "postgres-database": "/var/lib/mailu/database.secret", + "secret": { + "secret-key": "/var/lib/mailu/secret-key.secret", + "admin": "/var/lib/mailu/admin.secret", + "api-token": "/var/lib/mailu/api-token.secret" + } }, "emits": [ "module.mailu.user.created", @@ -67,9 +73,6 @@ } ], "own-secrets": { - "secret-key": "/var/lib/mailu/secret-key.secret", - "admin": "/var/lib/mailu/admin.secret", - "api-token": "/var/lib/mailu/api-token.secret", "broker": "/var/lib/mesh/mailu/broker" }, "resources": [ diff --git a/modules/route-proxy/Dockerfile b/modules/route-proxy/Dockerfile index a22fa35..45593a7 100644 --- a/modules/route-proxy/Dockerfile +++ b/modules/route-proxy/Dockerfile @@ -1,3 +1,5 @@ +ARG ALPINE_BASE=alpine:3.20 +ARG GO_BASE=golang:1.25 # The route-proxy module's runtime image: the reference reverse proxy compiled into a container. # # **The proxy source is not vendored here.** The canonical proxy — the contract written as something @@ -10,7 +12,7 @@ # # The mesh pins the digest of what this produces; the committed module.json carries the placeholder # digest every mesh-built image does, replaced at publish. -FROM golang:1.25 AS build +FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download @@ -19,7 +21,7 @@ RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-route-proxy ./examples/ # A small runtime with the public CA roots the ACME client needs to reach a real authority, and run # as root so it can bind :80 and :443 — the two privileged ports a public front door listens on. -FROM alpine:3.20 +FROM ${ALPINE_BASE} RUN apk add --no-cache ca-certificates COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"] diff --git a/modules/route-proxy/module.json b/modules/route-proxy/module.json index d0f73f5..7f944ee 100644 --- a/modules/route-proxy/module.json +++ b/modules/route-proxy/module.json @@ -98,5 +98,17 @@ "ACME_CA_BUNDLE": "/ca/root.crt" } } - ] + ], + "build": { + "on": [ + { + "arg": "GO_BASE", + "image": "golang@sha256:699337d620559a59b4a2bb298ad59611e535d2ee755a34cf2d2a98f37578dc80" + }, + { + "arg": "ALPINE_BASE", + "image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc" + } + ] + } } diff --git a/modules/umami/module.json b/modules/umami/module.json index 8e1a1f7..a6025d2 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -6,7 +6,8 @@ ], "requires": [ "postgres-database", - "route" + "route", + "secret" ], "contributes": { "postgres-database": { @@ -22,7 +23,11 @@ "route": "/var/lib/umami/route.json" }, "secrets": { - "postgres-database": "/var/lib/umami/database.secret" + "postgres-database": "/var/lib/umami/database.secret", + "secret": { + "app-secret": "/var/lib/umami/app.secret", + "admin": "/var/lib/umami/admin.secret" + } }, "provides": [ { @@ -40,8 +45,6 @@ "analytics": "/var/lib/umami/grants" }, "own-secrets": { - "app-secret": "/var/lib/umami/app.secret", - "admin": "/var/lib/umami/admin.secret", "broker": "/var/lib/mesh/umami/broker" }, "listens": [