Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
28b756f1c9 | ||
|
|
d543defae6 | ||
|
|
f14c763463 | ||
|
|
ab44ff02e1 | ||
|
|
c4c44efb1b | ||
|
|
5cc6258326 | ||
|
|
21f5301268 |
+24
-55
@@ -2,15 +2,12 @@
|
||||
// module's tools and anything else baserow-specific import it; nothing outside baserow does.
|
||||
//
|
||||
// Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/.
|
||||
// The standard image creates no admin from env, so the account is one a person made in Baserow: its
|
||||
// password is the module's `admin` secret, accepted from the operator, and its email and the public
|
||||
// host Baserow answers to reach the runtime config file the mesh mounts (the email from the
|
||||
// assignment's settings). Until both are there fromEnv throws and the module exposes no tools — the
|
||||
// same dormant-until-configured shape gitea uses for its token.
|
||||
// Those credentials are the mesh's own: a person signs up in Baserow (the standard image creates no
|
||||
// admin from env), and the credential is placed in the runtime config file the mesh mounts. Until
|
||||
// that happens fromEnv throws and the module simply exposes no tools — the same dormant-until-
|
||||
// configured shape gitea uses for its token.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
import { request as httpRequest } from "node:http";
|
||||
import { request as httpsRequest } from "node:https";
|
||||
|
||||
export interface BaserowApplication {
|
||||
id: number;
|
||||
@@ -71,63 +68,35 @@ export class BaserowClient {
|
||||
return h;
|
||||
}
|
||||
|
||||
/**
|
||||
* One HTTP exchange. Not `fetch`: Node's fetch drops a caller's Host header and sends the URL's
|
||||
* own, and Baserow answers only the host of its BASEROW_PUBLIC_URL — any other Host is looked up
|
||||
* as a published builder site and gets 404, `/api/_health/` included. A co-located caller reaching
|
||||
* it by container name must present the public host, so the request is made with node:http, which
|
||||
* sends the Host it is given.
|
||||
*/
|
||||
private send(path: string, method: string, headers: Record<string, string>, body?: string): Promise<{ status: number; text: string }> {
|
||||
const url = new URL(`${this.baseUrl}${path}`);
|
||||
const request = url.protocol === "https:" ? httpsRequest : httpRequest;
|
||||
// A length, never chunked: Baserow's server reads a chunked body as empty.
|
||||
const sent = body === undefined ? headers : { ...headers, "Content-Length": String(Buffer.byteLength(body)) };
|
||||
return new Promise((resolve, reject) => {
|
||||
const req = request(url, { method, headers: sent }, (res) => {
|
||||
let text = "";
|
||||
res.setEncoding("utf8");
|
||||
res.on("data", (chunk: string) => (text += chunk));
|
||||
res.on("end", () => resolve({ status: res.statusCode ?? 0, text }));
|
||||
res.on("error", reject);
|
||||
});
|
||||
req.on("error", reject);
|
||||
if (body !== undefined) req.write(body);
|
||||
req.end();
|
||||
});
|
||||
}
|
||||
|
||||
/** Exchange email + password for a JWT, caching it until Baserow refuses it. Handles both the
|
||||
/** Exchange email + password for a JWT, caching it for the client's lifetime. Handles both the
|
||||
* older `{ token }` and the newer `{ access_token }` response shapes. */
|
||||
async authenticate(): Promise<string> {
|
||||
if (this.token) return this.token;
|
||||
const res = await this.send(
|
||||
"/api/user/token-auth/",
|
||||
"POST",
|
||||
this.headers(),
|
||||
JSON.stringify({ email: this.email, password: this.password }),
|
||||
);
|
||||
if (res.status < 200 || res.status >= 300) throw new Error(`baserow auth failed: ${res.status} ${res.text}`);
|
||||
const data = JSON.parse(res.text) as { token?: string; access_token?: string };
|
||||
const res = await fetch(`${this.baseUrl}/api/user/token-auth/`, {
|
||||
method: "POST",
|
||||
headers: this.headers(),
|
||||
body: JSON.stringify({ email: this.email, password: this.password }),
|
||||
});
|
||||
if (!res.ok) throw new Error(`baserow auth failed: ${res.status} ${await res.text()}`);
|
||||
const data = (await res.json()) as { token?: string; access_token?: string };
|
||||
const token = data.access_token ?? data.token;
|
||||
if (!token) throw new Error("baserow auth returned no token");
|
||||
this.token = token;
|
||||
return token;
|
||||
}
|
||||
|
||||
/** An authenticated GET. A refused token is dropped and the call made once more with a fresh one:
|
||||
* Baserow's access tokens expire after minutes, and the runtime lives for weeks. */
|
||||
private async authed<T>(path: string): Promise<T> {
|
||||
for (let attempt = 0; ; attempt++) {
|
||||
const token = await this.authenticate();
|
||||
const res = await this.send(path, "GET", this.headers({ Authorization: `JWT ${token}` }));
|
||||
if (res.status === 401 && attempt === 0) {
|
||||
this.token = null;
|
||||
continue;
|
||||
}
|
||||
if (res.status < 200 || res.status >= 300) throw new Error(`baserow ${path}: ${res.status} ${res.text}`);
|
||||
return (res.text ? JSON.parse(res.text) : null) as T;
|
||||
}
|
||||
private async authed<T>(path: string, options: RequestInit = {}): Promise<T> {
|
||||
const token = await this.authenticate();
|
||||
const res = await fetch(`${this.baseUrl}${path}`, {
|
||||
...options,
|
||||
headers: this.headers({
|
||||
Authorization: `JWT ${token}`,
|
||||
...(options.headers as Record<string, string> | undefined),
|
||||
}),
|
||||
});
|
||||
if (!res.ok) throw new Error(`baserow ${path}: ${res.status} ${await res.text()}`);
|
||||
const text = await res.text();
|
||||
return (text ? JSON.parse(text) : null) as T;
|
||||
}
|
||||
|
||||
/** The applications (databases) the account can see, across all its workspaces. */
|
||||
|
||||
+16
-15
@@ -18,14 +18,14 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"postgres-database": "${dir:state}/database.json",
|
||||
"route": "${dir:state}/route.json"
|
||||
"postgres-database": "/var/lib/baserow/database.json",
|
||||
"route": "/var/lib/baserow/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "${dir:state}/database.secret"
|
||||
"postgres-database": "/var/lib/baserow/database.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"secret-key": "/var/lib/baserow/secret-key.secret",
|
||||
"broker": "/var/lib/mesh/baserow/broker"
|
||||
},
|
||||
"listens": [
|
||||
@@ -34,7 +34,7 @@
|
||||
"port": 80,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's"
|
||||
"why": "the Baserow web UI and REST API; a public name is a route grant later"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -47,21 +47,22 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/baserow",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/baserow/data",
|
||||
"mode": "0755",
|
||||
"owner": "9999:9999"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"path": "/var/lib/baserow/server.env",
|
||||
"mode": "0600",
|
||||
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n"
|
||||
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
@@ -72,25 +73,25 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "baserow",
|
||||
"image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080",
|
||||
"image": "baserow/baserow@sha256:834424a10413798567f76428f255dc259445b7f8dcec56598c05b4073bb2a124",
|
||||
"network": "baserow",
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
"/var/lib/baserow/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/baserow/data",
|
||||
"${dir:state}/database.secret:/run/secrets/database:ro"
|
||||
]
|
||||
"/services/baserow/data:/baserow/data"
|
||||
],
|
||||
"secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/baserow/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
|
||||
@@ -94,7 +94,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_BAZARR_URL": "http://127.0.0.1:6767",
|
||||
"MESH_BAZARR_URL": "http://127.0.0.1:${port:6767}",
|
||||
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
|
||||
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
||||
|
||||
@@ -76,7 +76,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_BOOKSHELF_URL": "http://127.0.0.1:8787",
|
||||
"MESH_BOOKSHELF_URL": "http://127.0.0.1:${port:8787}",
|
||||
"MESH_BOOKSHELF_CONFIG_DIR": "/var/lib/bookshelf/config"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
|
||||
@@ -69,8 +69,7 @@
|
||||
"kind": "image",
|
||||
"from": "Dockerfile",
|
||||
"context": {
|
||||
"seat": "git",
|
||||
"repository": "novox/mesh-controller",
|
||||
"repository": "https://git.novox.be/novox/mesh-controller.git",
|
||||
"ref": "main"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -27,7 +27,7 @@
|
||||
"port": 35621,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the de-spiegel site and its /contact endpoint over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the de-spiegel site and its /contact endpoint over http; the public name de-spiegel.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -61,10 +61,7 @@
|
||||
"ports": [
|
||||
"35621"
|
||||
],
|
||||
"secrets-in-environment": "the application's own code reads SMTP_AUTH_USER/PASS from the environment (de-spiegel server/index.js); converting is that repository's change",
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
"secrets-in-environment": "the application's own code reads SMTP_AUTH_USER/PASS from the environment (de-spiegel server/index.js); converting is that repository's change"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -95,13 +95,6 @@ export class GiteaClient {
|
||||
if (res.status === 401) {
|
||||
token = await this.tokens.renew(token);
|
||||
res = await this.send(path, options, token);
|
||||
} else if (res.status === 403) {
|
||||
// A kept token minted before a scope was added lacks it. The forge says so; the source
|
||||
// re-mints with the whole list and the call is retried once. Any other 403 stays a 403.
|
||||
const text = await res.text();
|
||||
if (!MintedToken.lacksScope(res.status, text)) throw new Error(`Gitea API ${path}: 403 ${text}`);
|
||||
token = await this.tokens.renew(token);
|
||||
res = await this.send(path, options, token);
|
||||
}
|
||||
if (!res.ok) throw new Error(`Gitea API ${path}: ${res.status} ${await res.text()}`);
|
||||
if (res.status === 204) return null as T;
|
||||
|
||||
@@ -29,7 +29,6 @@ interface Forge {
|
||||
mints: number;
|
||||
lastScopes: string[] | null;
|
||||
tokens: Map<string, string>;
|
||||
scopesOf: Map<string, string[]>;
|
||||
admins: Map<string, string>;
|
||||
close(): Promise<void>;
|
||||
}
|
||||
@@ -86,20 +85,6 @@ function fakeForge(): Promise<Forge> {
|
||||
}
|
||||
return json(res, 405, { message: "method not allowed" });
|
||||
}
|
||||
if (url.pathname === "/api/v1/repos/search") {
|
||||
// The client lists through the search endpoint since 2026-09-28 (the forge's whole view);
|
||||
// it sits under `repository`, which write:repository covers.
|
||||
const h = req.headers.authorization ?? "";
|
||||
const value = h.startsWith("token ") ? h.slice(6) : "";
|
||||
if (![...forge.tokens.values()].includes(value)) return json(res, 401, { message: "token is required" });
|
||||
if (!covers(forge.scopesOf.get(value) ?? [], "read:repository")) {
|
||||
return json(res, 403, { message: `token does not have at least one of required scope(s), required=[read:repository]` });
|
||||
}
|
||||
return json(res, 200, {
|
||||
ok: true,
|
||||
data: [{ full_name: "novox/hq", name: "hq", owner: { login: "novox" }, private: true, html_url: "http://fake/novox/hq" }],
|
||||
});
|
||||
}
|
||||
if (url.pathname === "/api/v1/user/repos") {
|
||||
const h = req.headers.authorization ?? "";
|
||||
const value = h.startsWith("token ") ? h.slice(6) : "";
|
||||
@@ -116,21 +101,6 @@ function fakeForge(): Promise<Forge> {
|
||||
{ full_name: "novox/hq", name: "hq", owner: { login: "novox" }, private: true, html_url: "http://fake/novox/hq" },
|
||||
]);
|
||||
}
|
||||
const adminUser = url.pathname.match(/^\/api\/v1\/admin\/users\/([^/]+)$/);
|
||||
if (adminUser && req.method === "PATCH") {
|
||||
const h = req.headers.authorization ?? "";
|
||||
const value = h.startsWith("token ") ? h.slice(6) : "";
|
||||
if (![...forge.tokens.values()].includes(value)) return json(res, 401, { message: "token is required" });
|
||||
if (!covers(forge.scopesOf.get(value) ?? [], "write:admin")) {
|
||||
return json(res, 403, {
|
||||
message: `token does not have at least one of required scope(s), required=[write:admin]`,
|
||||
});
|
||||
}
|
||||
const login = decodeURIComponent(adminUser[1]);
|
||||
if (login === "untouchable") return json(res, 403, { message: "user untouchable may not be edited" });
|
||||
const patch = await body(req);
|
||||
return json(res, 200, { login, is_admin: patch?.admin === true });
|
||||
}
|
||||
return json(res, 404, { message: "no such route in the fake" });
|
||||
});
|
||||
return new Promise((resolve) => {
|
||||
@@ -141,7 +111,6 @@ function fakeForge(): Promise<Forge> {
|
||||
get mints() { return forge.mints; },
|
||||
get lastScopes() { return forge.lastScopes; },
|
||||
tokens: forge.tokens,
|
||||
scopesOf: forge.scopesOf,
|
||||
admins: forge.admins,
|
||||
close: () => new Promise((r) => server.close(() => r())),
|
||||
});
|
||||
@@ -183,14 +152,14 @@ function minted(env: NodeJS.ProcessEnv, logs: string[]): GiteaClient {
|
||||
const forge = await fakeForge();
|
||||
after(() => forge.close());
|
||||
|
||||
test("first start: mints with the admin account, keeps the token at 0600, asks for the tools' scopes only", async () => {
|
||||
test("first start: mints with the admin account, keeps the token at 0600, asks for two scopes only", async () => {
|
||||
const { env, file, logs } = await delivered(forge);
|
||||
|
||||
const repos = await minted(env, logs).listRepos();
|
||||
|
||||
assert.equal(repos[0]?.full_name, "novox/hq");
|
||||
assert.equal(forge.mints, 1);
|
||||
assert.deepEqual(forge.lastScopes, ["write:repository", "write:issue", "read:user", "write:admin"]);
|
||||
assert.deepEqual(forge.lastScopes, ["write:repository", "write:issue", "read:user"]);
|
||||
assert.deepEqual(forge.lastScopes, [...TOKEN_SCOPES]);
|
||||
const token = forge.tokens.get("mesh-tools")!;
|
||||
assert.equal(await readFile(file, "utf8"), token + "\n");
|
||||
@@ -228,34 +197,6 @@ test("the forge rejects the kept token (its data was restored): minted afresh, o
|
||||
assert.ok(logs.some((l) => l.startsWith("the forge rejected the kept token")), logs.join("\n"));
|
||||
});
|
||||
|
||||
test("a kept token from before write:admin: the forge refuses the admin route for the scope, the token is re-minted with the whole list, and the call goes through", async () => {
|
||||
const { env, file, logs } = await delivered(forge);
|
||||
const client = minted(env, logs);
|
||||
await client.listRepos();
|
||||
const before = forge.mints;
|
||||
const old = forge.tokens.get("mesh-tools")!;
|
||||
forge.scopesOf.set(old, ["write:repository", "write:issue", "read:user"]); // minted by the previous build
|
||||
|
||||
const user = await client.api<{ login: string; is_admin: boolean }>("/admin/users/mesh_novox_builder", {
|
||||
method: "PATCH",
|
||||
body: JSON.stringify({ admin: true }),
|
||||
});
|
||||
|
||||
assert.equal(user.is_admin, true);
|
||||
assert.equal(forge.mints, before + 1);
|
||||
assert.deepEqual(forge.lastScopes, [...TOKEN_SCOPES]);
|
||||
assert.notEqual(forge.tokens.get("mesh-tools"), old);
|
||||
assert.equal(await readFile(file, "utf8"), forge.tokens.get("mesh-tools") + "\n");
|
||||
assert.ok(logs.some((l) => l.startsWith("the forge rejected the kept token")), logs.join("\n"));
|
||||
// A 403 that is not about scopes is the forge's answer, not a reason to mint.
|
||||
const again = forge.mints;
|
||||
await assert.rejects(
|
||||
client.api("/admin/users/untouchable", { method: "PATCH", body: JSON.stringify({ admin: true }) }),
|
||||
/403 .*untouchable/,
|
||||
);
|
||||
assert.equal(forge.mints, again);
|
||||
});
|
||||
|
||||
test("the kept file is gone but the forge still holds a token by that name: replaced, not refused", async () => {
|
||||
const { env, file, logs } = await delivered(forge);
|
||||
await minted(env, logs).listRepos();
|
||||
|
||||
+3
-14
@@ -34,21 +34,15 @@ export const TOKEN_NAME = "mesh-tools";
|
||||
* It sits under the `user` category despite listing repositories, not `repository`
|
||||
* — confirmed against the running forge (1.27.3), which answered
|
||||
* `required=[read:user]` to a token carrying only the other two.
|
||||
* write:admin — /admin/users: the forge's own users are the mesh's to settle, such as making
|
||||
* the builder's login a site admin so every repository the mesh may build is
|
||||
* clonable (novox/hq 229). Nothing under /orgs or write:user.
|
||||
*
|
||||
* A token kept from before a scope was added lacks it: the forge answers such a call with
|
||||
* `403 token does not have at least one of required scope(s)`, and the client treats that like a
|
||||
* 401 — the source re-mints by name, with the whole list, and the call is retried once.
|
||||
* Nothing under /admin, /orgs or write:user — the escape-hatch tool reaches only what these three cover.
|
||||
*/
|
||||
export const TOKEN_SCOPES: readonly string[] = ["write:repository", "write:issue", "read:user", "write:admin"];
|
||||
export const TOKEN_SCOPES: readonly string[] = ["write:repository", "write:issue", "read:user"];
|
||||
|
||||
/** Where a client's token comes from, and what to do when the forge says it is wrong. */
|
||||
export interface TokenSource {
|
||||
/** The token to authenticate with now; minted, read or configured. */
|
||||
current(): Promise<string>;
|
||||
/** The forge answered 401 to `rejected`, or 403 for a scope it lacks. A fresh token, or a plain error when there is nothing to renew with. */
|
||||
/** The forge answered 401 to `rejected`. A fresh token, or a plain error when there is nothing to renew with. */
|
||||
renew(rejected: string): Promise<string>;
|
||||
}
|
||||
|
||||
@@ -176,11 +170,6 @@ export class MintedToken implements TokenSource {
|
||||
return this.mint("the forge rejected the kept token — minting a fresh one");
|
||||
}
|
||||
|
||||
/** What the forge's scoped tokens say when a kept token predates a scope the tools now need. */
|
||||
static lacksScope(status: number, body: string): boolean {
|
||||
return status === 403 && /required scope/i.test(body);
|
||||
}
|
||||
|
||||
/** One mint at a time: concurrent first calls share it, rather than each minting its own. */
|
||||
private mint(why: string): Promise<string> {
|
||||
if (this.inflight === null) {
|
||||
|
||||
+16
-74
@@ -5,7 +5,7 @@
|
||||
"alert.firing"
|
||||
],
|
||||
"own-secrets": {
|
||||
"admin": "/var/lib/mesh/grafana/admin",
|
||||
"admin": "/var/lib/grafana-module/admin.secret",
|
||||
"broker": "/var/lib/mesh/grafana/broker"
|
||||
},
|
||||
"capabilities": [
|
||||
@@ -30,87 +30,45 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/grafana-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/grafana/data",
|
||||
"mode": "0700",
|
||||
"owner": "472:472"
|
||||
},
|
||||
{
|
||||
"id": "admin-secret",
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/admin.secret",
|
||||
"mode": "0400",
|
||||
"owner": "472:472",
|
||||
"content": "${secret:admin}"
|
||||
},
|
||||
{
|
||||
"id": "oidc-secret",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/oidc-client.secret",
|
||||
"mode": "0400",
|
||||
"owner": "472:472",
|
||||
"content": "${secret:oidc-client}"
|
||||
},
|
||||
{
|
||||
"id": "oidc-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/oidc.env",
|
||||
"mode": "0644",
|
||||
"content": "GF_SERVER_ROOT_URL=https://${bound:route:name}\nGF_AUTH_GENERIC_OAUTH_ENABLED=true\nGF_AUTH_GENERIC_OAUTH_NAME=Keycloak\nGF_AUTH_GENERIC_OAUTH_CLIENT_ID=${bound:oidc-client:as}\nGF_AUTH_GENERIC_OAUTH_CLIENT_SECRET__FILE=/run/secrets/oidc-client\nGF_AUTH_GENERIC_OAUTH_SCOPES=openid email profile roles\nGF_AUTH_GENERIC_OAUTH_AUTH_URL=${bound:oidc-client:issuer}${bound:oidc-client:authorization-path}\nGF_AUTH_GENERIC_OAUTH_TOKEN_URL=${bound:oidc-client:issuer}${bound:oidc-client:token-path}\nGF_AUTH_GENERIC_OAUTH_API_URL=${bound:oidc-client:issuer}${bound:oidc-client:userinfo-path}\nGF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=contains(roles[*], 'admin') && 'Admin' || contains(realm_access.roles[*], 'admin') && 'Admin' || 'Viewer'\nGF_AUTH_GENERIC_OAUTH_USE_PKCE=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true\n"
|
||||
},
|
||||
{
|
||||
"id": "influxdb-secret",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/influxdb-api.secret",
|
||||
"mode": "0400",
|
||||
"owner": "472:472",
|
||||
"content": "${secret:influxdb-api}"
|
||||
},
|
||||
{
|
||||
"id": "influxdb-datasource",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/datasource-influxdb.yaml",
|
||||
"mode": "0644",
|
||||
"content": "apiVersion: 1\n# Written by the mesh from grafana's influxdb-api binding; grafana reads it at start. Its own name and\n# uid, so a data source somebody made in the UI is never overwritten, and read-only in the UI because\n# the mesh resets it. The password is read from the file the mesh delivers, never written here.\ndatasources:\n - name: InfluxDB (mesh)\n uid: mesh-influxdb-api\n type: influxdb\n access: proxy\n url: ${bound:influxdb-api:scheme}://${bound:influxdb-api:at}:${bound:influxdb-api:port}\n user: ${bound:influxdb-api:as}\n isDefault: false\n editable: false\n jsonData:\n dbName: ${bound:influxdb-api:bucket}\n httpMode: POST\n secureJsonData:\n password: $__file{/run/secrets/influxdb-api}\n"
|
||||
"path": "/var/lib/grafana-module/server.env",
|
||||
"mode": "0600",
|
||||
"content": "GF_SECURITY_ADMIN_PASSWORD=${secret:admin}\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "grafana",
|
||||
"image": "grafana/grafana@sha256:ac461fb352abc50da10a51c7d02462e9c05488f11f53f14b3ad79a8145f638a0",
|
||||
"image": "grafana/grafana@sha256:f772d434e8fab0049deb2b1b30abd43342bcfca1537614aa8d36080232cf4283",
|
||||
"ports": [
|
||||
"3000"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/var/lib/grafana",
|
||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
||||
"${dir:state}/oidc-client.secret:/run/secrets/oidc-client:ro",
|
||||
"${dir:state}/influxdb-api.secret:/run/secrets/influxdb-api:ro",
|
||||
"${dir:state}/datasource-influxdb.yaml:/etc/grafana/provisioning/datasources/mesh-influxdb.yaml:ro"
|
||||
"/services/grafana/data:/var/lib/grafana"
|
||||
],
|
||||
"env": {
|
||||
"GF_SECURITY_ADMIN_PASSWORD__FILE": "/run/secrets/admin"
|
||||
},
|
||||
"env-file": [
|
||||
"${dir:state}/oidc.env"
|
||||
"/var/lib/grafana-module/server.env"
|
||||
],
|
||||
"restart-on": [
|
||||
"oidc-env",
|
||||
"oidc-secret",
|
||||
"influxdb-datasource",
|
||||
"influxdb-secret"
|
||||
]
|
||||
"secrets-in-environment": "grafana honours GF_SECURITY_ADMIN_PASSWORD__FILE; convertible, awaiting a bed that exercises the admin password (assigned-grafana serves tools only)"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/grafana/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"user\": \"admin\",\n \"password\": \"${secret:admin}\"\n}\n",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
@@ -124,7 +82,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_GRAFANA_URL": "http://127.0.0.1:${port:3000}",
|
||||
"MESH_GRAFANA_URL": "http://127.0.0.1:3000",
|
||||
"MESH_GRAFANA_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
@@ -134,32 +92,16 @@
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route",
|
||||
"oidc-client",
|
||||
"influxdb-api"
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "grafana",
|
||||
"endpoint": "web"
|
||||
},
|
||||
"oidc-client": {
|
||||
"label": "grafana",
|
||||
"endpoint": "web",
|
||||
"callback": "/login/generic_oauth"
|
||||
},
|
||||
"influxdb-api": {
|
||||
"access": "read"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json",
|
||||
"oidc-client": "${dir:state}/oidc.json",
|
||||
"influxdb-api": "${dir:state}/influxdb.json"
|
||||
},
|
||||
"secrets": {
|
||||
"oidc-client": "/var/lib/mesh/grafana/oidc-client",
|
||||
"influxdb-api": "/var/lib/mesh/grafana/influxdb-api"
|
||||
"route": "/var/lib/mesh/grafana/route.json"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
+22
-47
@@ -1,26 +1,6 @@
|
||||
{
|
||||
"module": "icecast",
|
||||
"version": "1",
|
||||
"requires": [
|
||||
"route",
|
||||
"secret"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "icecast",
|
||||
"endpoint": "stream"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"source": "${dir:state}/source.secret",
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"relay": "${dir:state}/relay.secret"
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -37,7 +17,7 @@
|
||||
"port": 8000,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "streams in from sources (HTTP PUT) and out to listeners, plus the status and admin pages; a public name is its route"
|
||||
"why": "streams in from sources and out to listeners"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -50,43 +30,28 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/icecast-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "logs",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"owner": "100:101"
|
||||
},
|
||||
{
|
||||
"id": "server-conf",
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/icecast.xml",
|
||||
"path": "/var/lib/icecast-module/server.env",
|
||||
"mode": "0600",
|
||||
"content": "<icecast>\n <!-- Written by the mesh (modules/icecast). Passwords arrive as secrets rendered into this file,\n never as environment: the image's entrypoint seds ICECAST_* variables into the file only\n when they are set, and none are. -->\n <location>Earth</location>\n <admin>icemaster@localhost</admin>\n <limits>\n <clients>100</clients>\n <sources>2</sources>\n <queue-size>524288</queue-size>\n <client-timeout>30</client-timeout>\n <header-timeout>15</header-timeout>\n <source-timeout>10</source-timeout>\n <burst-on-connect>1</burst-on-connect>\n <burst-size>65535</burst-size>\n </limits>\n <authentication>\n <source-password>${secret:source}</source-password>\n <relay-password>${secret:relay}</relay-password>\n <admin-user>admin</admin-user>\n <admin-password>${secret:admin}</admin-password>\n </authentication>\n <!-- The name icecast writes into playlists (.m3u/.xspf: http://<hostname>:<port>/<mount>) and\n would announce to YP (none configured). A machine's own name belongs to its assignment, and\n an assignment merges only into JSON; this XML cannot take it, so the neutral default stays. -->\n <hostname>localhost</hostname>\n <listen-socket>\n <port>8000</port>\n </listen-socket>\n <http-headers>\n <header name=\"Access-Control-Allow-Origin\" value=\"*\" />\n </http-headers>\n <fileserve>1</fileserve>\n <paths>\n <basedir>/usr/share/icecast</basedir>\n <logdir>/var/log/icecast</logdir>\n <webroot>/usr/share/icecast/web</webroot>\n <adminroot>/usr/share/icecast/admin</adminroot>\n <alias source=\"/\" destination=\"/status.xsl\"/>\n </paths>\n <logging>\n <accesslog>access.log</accesslog>\n <errorlog>error.log</errorlog>\n <loglevel>3</loglevel>\n <logsize>10000</logsize>\n </logging>\n <security>\n <chroot>0</chroot>\n <!-- Starts as root, reads this 0600 root-owned file, then drops to the image's icecast user\n (uid 100, group icecast 101) before serving. -->\n <changeowner>\n <user>icecast</user>\n <group>icecast</group>\n </changeowner>\n </security>\n</icecast>\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
"type": "network",
|
||||
"name": "icecast"
|
||||
"content": "ICECAST_SOURCE_PASSWORD=${secret:source}\nICECAST_ADMIN_PASSWORD=${secret:admin}\nICECAST_RELAY_PASSWORD=${secret:relay}\nICECAST_ADMIN_USERNAME=admin\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "icecast",
|
||||
"image": "infiniteproject/icecast@sha256:cd506cf3dfe31ce05fd37d7e672dbd1213e7255cc93d28ecf5a3b547af4e162c",
|
||||
"network": "icecast",
|
||||
"env-file": [
|
||||
"/var/lib/icecast-module/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"8000"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:state}/icecast.xml:/etc/icecast.xml:ro",
|
||||
"${dir:logs}:/var/log/icecast"
|
||||
],
|
||||
"restart-on": [
|
||||
"server-conf"
|
||||
]
|
||||
"secrets-in-environment": "the image seds ICECAST_*_PASSWORD into icecast.xml and has no _FILE; convertible by mounting a generated icecast.xml, not yet done"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
@@ -100,14 +65,14 @@
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "mesh-icecast",
|
||||
"network": "icecast",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/icecast/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/icecast/config.json:/run/config/config.json:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_ICECAST_URL": "http://icecast:8000",
|
||||
"MESH_ICECAST_URL": "http://127.0.0.1:8000",
|
||||
"MESH_ICECAST_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
@@ -136,5 +101,15 @@
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
},
|
||||
"requires": [
|
||||
"secret"
|
||||
],
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"source": "/var/lib/icecast-module/source.secret",
|
||||
"admin": "/var/lib/icecast-module/admin.secret",
|
||||
"relay": "/var/lib/icecast-module/relay.secret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/influxdb
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts grants.ts provisioner/index.ts tools/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
@@ -21,4 +21,4 @@ COPY --from=build /app/modules/influxdb/dist /app/modules/influxdb/dist
|
||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||
# the convention novox/hq issues 060/061 settled.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/influxdb/dist/tools/index.js,/app/modules/influxdb/dist/provisioner/index.js
|
||||
ENV MESH_TOOL_MODULES=/app/modules/influxdb/dist/tools/index.js
|
||||
|
||||
+3
-118
@@ -17,25 +17,6 @@ export interface InfluxBucket {
|
||||
retentionSeconds?: number;
|
||||
}
|
||||
|
||||
/** One permission of an authorization, as InfluxDB represents it: an action on a resource type,
|
||||
* in one org, optionally narrowed to one resource by id (no id = every resource of that type). */
|
||||
export interface InfluxPermission {
|
||||
action: "read" | "write";
|
||||
resource: { type: string; orgID?: string; id?: string; name?: string; org?: string };
|
||||
}
|
||||
|
||||
/** A v1-compatibility ("legacy") authorization: a username (InfluxDB calls it `token`) and a
|
||||
* password the caller chooses, scoped by permissions. The one credential InfluxDB 2.x lets a
|
||||
* caller set to a value it did not generate — which is what a mesh-minted password needs. */
|
||||
export interface LegacyAuthorization {
|
||||
id: string;
|
||||
token: string;
|
||||
orgID: string;
|
||||
status?: "active" | "inactive";
|
||||
description?: string;
|
||||
permissions: InfluxPermission[];
|
||||
}
|
||||
|
||||
/** The settings-merged config the mesh delivers (novox/hq ADR 0046): { url, apiKey, token, password, user, ... }. */
|
||||
function meshConfig(file?: string): Record<string, string> {
|
||||
if (!file) return {};
|
||||
@@ -43,20 +24,13 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** A secret delivered as a file, trimmed; undefined when there is none, so the caller can fall back. */
|
||||
function tokenFromFile(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim() || undefined; }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class InfluxDBClient {
|
||||
readonly baseUrl: string;
|
||||
|
||||
constructor(
|
||||
url: string,
|
||||
private readonly token: string,
|
||||
readonly org: string,
|
||||
private readonly org: string,
|
||||
) {
|
||||
this.baseUrl = url.replace(/\/$/, "");
|
||||
}
|
||||
@@ -69,10 +43,8 @@ export class InfluxDBClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): InfluxDBClient {
|
||||
const cfg = meshConfig(env.MESH_INFLUXDB_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_INFLUXDB_URL ?? `http://127.0.0.1:${env.INFLUXDB_PORT ?? "8086"}`;
|
||||
// The token reaches the process as a file (novox/hq ADR 0086); the environment variable stays
|
||||
// only for a workstation running the tools by hand.
|
||||
const token = cfg.token ?? tokenFromFile(env.MESH_INFLUXDB_TOKEN_FILE) ?? env.MESH_INFLUXDB_TOKEN;
|
||||
if (!token) throw new Error("no InfluxDB token — set MESH_INFLUXDB_TOKEN_FILE");
|
||||
const token = cfg.token ?? env.MESH_INFLUXDB_TOKEN;
|
||||
if (!token) throw new Error("no InfluxDB token — set MESH_INFLUXDB_TOKEN");
|
||||
const org = cfg.org ?? env.MESH_INFLUXDB_ORG ?? "mesh";
|
||||
return new InfluxDBClient(url, token, org);
|
||||
}
|
||||
@@ -89,93 +61,6 @@ export class InfluxDBClient {
|
||||
return res;
|
||||
}
|
||||
|
||||
/** Like request, but the answer is returned whatever its status, for the caller to read. */
|
||||
private async raw(path: string, init?: RequestInit): Promise<Response> {
|
||||
return fetch(`${this.baseUrl}${path}`, {
|
||||
...init,
|
||||
headers: { Authorization: `Token ${this.token}`, ...(init?.headers ?? {}) },
|
||||
});
|
||||
}
|
||||
|
||||
private async send(path: string, method: string, body?: unknown): Promise<Response> {
|
||||
return this.request(path, {
|
||||
method,
|
||||
headers: { "Content-Type": "application/json" },
|
||||
body: body === undefined ? undefined : JSON.stringify(body),
|
||||
});
|
||||
}
|
||||
|
||||
/** The id of the org of this name, or undefined when there is none. */
|
||||
async orgID(name: string): Promise<string | undefined> {
|
||||
const res = await this.raw(`/api/v2/orgs?org=${encodeURIComponent(name)}`);
|
||||
if (res.status === 404) return undefined;
|
||||
if (!res.ok) throw new Error(`InfluxDB API /api/v2/orgs: ${res.status} ${await res.text()}`);
|
||||
const body = (await res.json()) as { orgs?: { id: string; name: string }[] };
|
||||
return body.orgs?.find((o) => o.name === name)?.id;
|
||||
}
|
||||
|
||||
/** The bucket of exactly this name in the org, or undefined. */
|
||||
async findBucket(orgID: string, name: string): Promise<InfluxBucket | undefined> {
|
||||
const res = await this.raw(`/api/v2/buckets?orgID=${encodeURIComponent(orgID)}&name=${encodeURIComponent(name)}`);
|
||||
if (res.status === 404) return undefined;
|
||||
if (!res.ok) throw new Error(`InfluxDB API /api/v2/buckets: ${res.status} ${await res.text()}`);
|
||||
const body = (await res.json()) as { buckets?: { id: string; name: string; orgID?: string }[] };
|
||||
const b = body.buckets?.find((x) => x.name === name);
|
||||
return b ? { id: b.id, name: b.name, orgID: b.orgID } : undefined;
|
||||
}
|
||||
|
||||
/** Create a bucket that keeps its data for ever — retention is the operator's choice, never the mesh's. */
|
||||
async createBucket(orgID: string, name: string, description: string): Promise<InfluxBucket> {
|
||||
const b = (await (await this.send("/api/v2/buckets", "POST", {
|
||||
orgID, name, description, retentionRules: [],
|
||||
})).json()) as { id: string; name: string; orgID?: string };
|
||||
return { id: b.id, name: b.name, orgID: b.orgID };
|
||||
}
|
||||
|
||||
/** The v1 authorization whose username is exactly this, or undefined. */
|
||||
async findLegacy(username: string): Promise<LegacyAuthorization | undefined> {
|
||||
const path = `/private/legacy/authorizations?token=${encodeURIComponent(username)}`;
|
||||
const res = await this.raw(path);
|
||||
// InfluxDB answers a filter matching nothing with 404, not an empty list.
|
||||
if (res.status === 404) return undefined;
|
||||
if (!res.ok) throw new Error(`InfluxDB API ${path}: ${res.status} ${await res.text()}`);
|
||||
const body = (await res.json()) as { authorizations?: LegacyAuthorization[] };
|
||||
return body.authorizations?.find((a) => a.token === username);
|
||||
}
|
||||
|
||||
async createLegacy(a: Omit<LegacyAuthorization, "id">): Promise<LegacyAuthorization> {
|
||||
return (await (await this.send("/private/legacy/authorizations", "POST", a)).json()) as LegacyAuthorization;
|
||||
}
|
||||
|
||||
/** Set a v1 authorization's password. InfluxDB keeps only a hash of it, so it can be set, never read. */
|
||||
async setLegacyPassword(id: string, password: string): Promise<void> {
|
||||
await this.send(`/private/legacy/authorizations/${encodeURIComponent(id)}/password`, "POST", { password });
|
||||
}
|
||||
|
||||
async updateLegacy(id: string, patch: { status?: "active" | "inactive"; description?: string }): Promise<void> {
|
||||
await this.send(`/private/legacy/authorizations/${encodeURIComponent(id)}`, "PATCH", patch);
|
||||
}
|
||||
|
||||
async deleteLegacy(id: string): Promise<void> {
|
||||
await this.send(`/private/legacy/authorizations/${encodeURIComponent(id)}`, "DELETE");
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether this username and password sign in on the v1 API — the consumer's own view. Asked with
|
||||
* a statement that reads nothing (`SHOW DATABASES` lists only what the credential may read), sent
|
||||
* with Basic auth so the password is never in a URL. 401 is a wrong password or no such user;
|
||||
* anything else that is not a server error means InfluxDB knew who was asking.
|
||||
*/
|
||||
async legacySignsIn(username: string, password: string): Promise<boolean> {
|
||||
const res = await fetch(`${this.baseUrl}/query?q=${encodeURIComponent("SHOW DATABASES")}`, {
|
||||
headers: { Authorization: `Basic ${Buffer.from(`${username}:${password}`).toString("base64")}` },
|
||||
});
|
||||
await res.arrayBuffer();
|
||||
if (res.status === 401) return false;
|
||||
if (res.status >= 500) throw new Error(`InfluxDB v1 /query: ${res.status}`);
|
||||
return true;
|
||||
}
|
||||
|
||||
/** Server health — the one endpoint that needs no token, but we send it anyway. */
|
||||
async health(): Promise<InfluxHealth> {
|
||||
return (await (await this.request("/health")).json()) as InfluxHealth;
|
||||
|
||||
@@ -1,186 +0,0 @@
|
||||
// What the `influxdb-api` provision means in InfluxDB: one v1-compatibility authorization per
|
||||
// consumer, in the org this module serves, under the username and password the mesh gave both ends,
|
||||
// allowed exactly the access the consumer contributed. The provisioner (provisioner/index.ts) is the
|
||||
// sdk harness calling these; they are here, apart from it, so they can be exercised against a fake
|
||||
// InfluxDB without a broker or a contributions file.
|
||||
//
|
||||
// **Why a v1 authorization and not a v2 API token.** The mesh mints the consumer's password and
|
||||
// hands it to both ends (novox/hq ADR 0048); the provider sets it, and never hands one back. An
|
||||
// InfluxDB 2.x API token is generated by the server — `POST /api/v2/authorizations` ignores a token
|
||||
// the caller sends — so a token could only ever be the operator's to accept, one per pair, by hand.
|
||||
// A v1 authorization is a username and a password the caller chooses (8–72 characters; the mesh
|
||||
// mints 40), stored hashed, and it reads and writes through InfluxQL (`/query`) and line protocol
|
||||
// (`/write`), which every bucket answers under its own name as a database (InfluxDB maps each
|
||||
// bucket to a database of the same name by itself). That is what grafana's InfluxDB data source
|
||||
// speaks, and what Node-RED's influxdb nodes speak in their 1.x mode — so the mesh can make every
|
||||
// consumer's credential, rotate it and withdraw it, with no person in the loop.
|
||||
//
|
||||
// **What a consumer contributes.** `access`: "read" (the default), "write" or "read-write".
|
||||
// `buckets`: the buckets it may use, by name. A reader that names none may read every bucket of the
|
||||
// org — a dashboard is pointed at data, it does not own it. A writer must name its buckets: writing
|
||||
// everywhere, the org's system buckets included, is never what a consumer means. A named bucket
|
||||
// that does not exist is created, keeping its data for ever; the mesh never deletes a bucket.
|
||||
//
|
||||
// **Only what the mesh made is touched.** An authorization this module creates is named with the
|
||||
// mesh's identity prefix and its description starts with MARK. One with the same username that
|
||||
// lacks the mark is somebody else's: it is refused, never adopted, never updated, never deleted.
|
||||
// Every other authorization, token, user and bucket in the instance is left exactly as it was.
|
||||
|
||||
import type { InfluxDBClient, InfluxPermission, LegacyAuthorization } from "./client.js";
|
||||
|
||||
/** How a description marks an authorization as the mesh's own work. */
|
||||
export const MARK = "[mesh]";
|
||||
|
||||
/** The prefix the mesh gives every consumer identity (novox/hq ADR 0049). */
|
||||
const IDENTITY_PREFIX = "mesh_";
|
||||
|
||||
/** One consumer, as the harness hands it over. */
|
||||
export interface ApiGrant {
|
||||
readonly as: string;
|
||||
readonly password: string;
|
||||
readonly values: Readonly<Record<string, unknown>>;
|
||||
readonly consumer?: string;
|
||||
}
|
||||
|
||||
export type Access = "read" | "write" | "read-write";
|
||||
|
||||
/** What a contribution asks for, checked. Refused when it cannot be served as asked. */
|
||||
export function askedFor(values: Readonly<Record<string, unknown>>): { access: Access; buckets: string[] } {
|
||||
const access = values.access ?? "read";
|
||||
if (access !== "read" && access !== "write" && access !== "read-write") {
|
||||
throw new Error(`contributes an access of ${JSON.stringify(access)} — it is "read", "write" or "read-write"`);
|
||||
}
|
||||
const raw = values.buckets ?? [];
|
||||
if (!Array.isArray(raw) || raw.some((b) => typeof b !== "string" || b.trim() === "")) {
|
||||
throw new Error(`contributes buckets of ${JSON.stringify(raw)} — a list of bucket names`);
|
||||
}
|
||||
const buckets = [...new Set((raw as string[]).map((b) => b.trim()))].sort();
|
||||
if (access !== "read" && buckets.length === 0) {
|
||||
throw new Error(`asks to write and names no bucket (\`buckets\`) — a writer names what it writes to`);
|
||||
}
|
||||
if (buckets.some((b) => b.startsWith("_"))) {
|
||||
throw new Error(`names a system bucket (${buckets.filter((b) => b.startsWith("_")).join(", ")}) — those are InfluxDB's own`);
|
||||
}
|
||||
return { access: access as Access, buckets };
|
||||
}
|
||||
|
||||
/** The permissions a grant resolves to, given each named bucket's id. */
|
||||
export function permissionsFor(orgID: string, access: Access, bucketIDs: string[]): InfluxPermission[] {
|
||||
const actions: ("read" | "write")[] = access === "read-write" ? ["read", "write"] : [access];
|
||||
const out: InfluxPermission[] = [];
|
||||
for (const action of actions) {
|
||||
if (bucketIDs.length === 0) {
|
||||
out.push({ action, resource: { type: "buckets", orgID } });
|
||||
continue;
|
||||
}
|
||||
for (const id of bucketIDs) out.push({ action, resource: { type: "buckets", orgID, id } });
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** A permission as a comparable string: what InfluxDB answers carries names and links besides. */
|
||||
function key(p: InfluxPermission): string {
|
||||
return `${p.action}:${p.resource.type}:${p.resource.orgID ?? ""}:${p.resource.id ?? "*"}`;
|
||||
}
|
||||
|
||||
function samePermissions(a: readonly InfluxPermission[], b: readonly InfluxPermission[]): boolean {
|
||||
const x = a.map(key).sort();
|
||||
const y = b.map(key).sort();
|
||||
return x.length === y.length && x.every((v, i) => v === y[i]);
|
||||
}
|
||||
|
||||
export function marked(a: Pick<LegacyAuthorization, "token" | "description">): boolean {
|
||||
return a.token.startsWith(IDENTITY_PREFIX) && (a.description ?? "").startsWith(MARK);
|
||||
}
|
||||
|
||||
function describe(g: ApiGrant): string {
|
||||
return `${MARK} made by the mesh for ${g.consumer ? `a module on ${g.consumer}` : "a consumer"} — do not edit; it is reset`;
|
||||
}
|
||||
|
||||
export class ApiGrants {
|
||||
constructor(private readonly influx: InfluxDBClient, readonly org: string) {}
|
||||
|
||||
private async orgID(): Promise<string> {
|
||||
const id = await this.influx.orgID(this.org);
|
||||
if (!id) throw new Error(`InfluxDB has no org ${JSON.stringify(this.org)} — the org this module serves must exist`);
|
||||
return id;
|
||||
}
|
||||
|
||||
/** The ids of the named buckets, creating any that are missing when `create` says so. Undefined
|
||||
* when one is missing and may not be created (a read-only question). */
|
||||
private async bucketIDs(orgID: string, names: string[], create: ApiGrant | undefined): Promise<string[] | undefined> {
|
||||
const ids: string[] = [];
|
||||
for (const name of names) {
|
||||
let b = await this.influx.findBucket(orgID, name);
|
||||
if (!b) {
|
||||
if (!create) return undefined;
|
||||
b = await this.influx.createBucket(orgID, name, `${MARK} made by the mesh for ${create.as}; the mesh never deletes it`);
|
||||
}
|
||||
ids.push(b.id);
|
||||
}
|
||||
return ids.sort();
|
||||
}
|
||||
|
||||
/** Create the consumer's authorization, or bring the mesh's existing one back to what the grant
|
||||
* says. Idempotent: a second apply of the same grant changes nothing beyond re-asserting the
|
||||
* password, which InfluxDB can be told but never asked. */
|
||||
async ensure(g: ApiGrant): Promise<"created" | "updated" | "unchanged"> {
|
||||
if (!g.as.startsWith(IDENTITY_PREFIX)) {
|
||||
throw new Error(`${g.as} is not a mesh identity — the mesh names every consumer ${IDENTITY_PREFIX}<node>_<module>`);
|
||||
}
|
||||
const { access, buckets } = askedFor(g.values);
|
||||
const orgID = await this.orgID();
|
||||
const found = await this.influx.findLegacy(g.as);
|
||||
if (found && !marked(found)) {
|
||||
throw new Error(
|
||||
`InfluxDB already has a v1 authorization ${g.as} the mesh did not make — left alone; ` +
|
||||
`delete it if the mesh should own that name`);
|
||||
}
|
||||
const want = permissionsFor(orgID, access, (await this.bucketIDs(orgID, buckets, g))!);
|
||||
|
||||
if (found && found.orgID === orgID && samePermissions(found.permissions, want)) {
|
||||
// Only what differs is written. The password cannot be read back, so it is tried instead.
|
||||
let changed = false;
|
||||
if (found.status === "inactive") {
|
||||
await this.influx.updateLegacy(found.id, { status: "active" });
|
||||
changed = true;
|
||||
}
|
||||
if (!(await this.influx.legacySignsIn(g.as, g.password))) {
|
||||
await this.influx.setLegacyPassword(found.id, g.password);
|
||||
changed = true;
|
||||
}
|
||||
return changed ? "updated" : "unchanged";
|
||||
}
|
||||
// InfluxDB cannot change an authorization's permissions in place, so the mesh's own is made
|
||||
// again. Only ever one the mesh made: a foreign one was refused above.
|
||||
if (found) await this.influx.deleteLegacy(found.id);
|
||||
const made = await this.influx.createLegacy({
|
||||
token: g.as, orgID, status: "active", description: describe(g), permissions: want,
|
||||
});
|
||||
await this.influx.setLegacyPassword(made.id, g.password);
|
||||
return found ? "updated" : "created";
|
||||
}
|
||||
|
||||
/** Whether InfluxDB still holds this consumer's authorization exactly as the grant says: present,
|
||||
* the mesh's, active, allowed what was asked and nothing more, and signing in with the mesh's
|
||||
* password. Reads only — a missing bucket is "not held", never created here. */
|
||||
async holds(g: ApiGrant): Promise<boolean> {
|
||||
const { access, buckets } = askedFor(g.values);
|
||||
const orgID = await this.influx.orgID(this.org);
|
||||
if (!orgID) return false;
|
||||
const found = await this.influx.findLegacy(g.as);
|
||||
if (!found || !marked(found) || found.status === "inactive" || found.orgID !== orgID) return false;
|
||||
const ids = await this.bucketIDs(orgID, buckets, undefined);
|
||||
if (!ids || !samePermissions(found.permissions, permissionsFor(orgID, access, ids))) return false;
|
||||
return this.influx.legacySignsIn(g.as, g.password);
|
||||
}
|
||||
|
||||
/** Withdraw a consumer's authorization — only one the mesh made. Its buckets and their data stay. */
|
||||
async remove(as: string): Promise<"removed" | "absent" | "not ours"> {
|
||||
const found = await this.influx.findLegacy(as);
|
||||
if (!found) return "absent";
|
||||
if (!marked(found)) return "not ours";
|
||||
await this.influx.deleteLegacy(found.id);
|
||||
return "removed";
|
||||
}
|
||||
}
|
||||
@@ -1,19 +1,11 @@
|
||||
{
|
||||
"module": "influxdb",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "influxdb-api",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/influxdb/broker",
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"admin-token": "${dir:state}/admin-token.secret"
|
||||
"broker": "/var/lib/mesh/influxdb/broker"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -21,23 +13,9 @@
|
||||
"port": 8086,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "queries, writes and the web UI, over http; consumers granted influxdb-api sign in with the mesh's credential, and a name is a route grant"
|
||||
"why": "queries and writes, over http"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"influxdb-api": {
|
||||
"scheme": "http",
|
||||
"port": 8086,
|
||||
"org": "mesh",
|
||||
"bucket": "default"
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"influxdb-api": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"influxdb-api": "${dir:grants}"
|
||||
},
|
||||
"resources": [
|
||||
{
|
||||
"id": "mesh-state",
|
||||
@@ -48,50 +26,46 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/influxdb-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "/var/lib/influxdb-module/server.env",
|
||||
"mode": "0600",
|
||||
"content": "DOCKER_INFLUXDB_INIT_MODE=setup\nDOCKER_INFLUXDB_INIT_USERNAME=admin\nDOCKER_INFLUXDB_INIT_PASSWORD=${secret:admin}\nDOCKER_INFLUXDB_INIT_ADMIN_TOKEN=${secret:admin-token}\nDOCKER_INFLUXDB_INIT_ORG=mesh\nDOCKER_INFLUXDB_INIT_BUCKET=default\n"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/influxdb/data",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "directory",
|
||||
"path": "/services/influxdb/config",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"mode": "0600",
|
||||
"content": "DOCKER_INFLUXDB_INIT_MODE=setup\nDOCKER_INFLUXDB_INIT_USERNAME=admin\nDOCKER_INFLUXDB_INIT_PASSWORD_FILE=/run/secrets/admin\nDOCKER_INFLUXDB_INIT_ADMIN_TOKEN_FILE=/run/secrets/admin-token\nDOCKER_INFLUXDB_INIT_ORG=mesh\nDOCKER_INFLUXDB_INIT_BUCKET=default\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "influxdb",
|
||||
"image": "influxdb@sha256:f75e48af0598e8aec7986e991a848d19a119101a7d563a2e5db1dfaac9c45daa",
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
"/var/lib/influxdb-module/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"8086"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/var/lib/influxdb2",
|
||||
"${dir:config}:/etc/influxdb2",
|
||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
||||
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro"
|
||||
]
|
||||
"/services/influxdb/data:/var/lib/influxdb2",
|
||||
"/services/influxdb/config:/etc/influxdb2"
|
||||
],
|
||||
"secrets-in-environment": "the image honours DOCKER_INFLUXDB_INIT_PASSWORD_FILE and _ADMIN_TOKEN_FILE; convertible, awaiting a bed that proves it"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
@@ -109,15 +83,13 @@
|
||||
"volumes": [
|
||||
"/var/lib/mesh/influxdb/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/influxdb/config.json:/run/config/config.json:ro",
|
||||
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro",
|
||||
"${dir:grants}:${dir:grants}:ro"
|
||||
"/services/influxdb/config:/var/lib/influxdb/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_INFLUXDB_URL": "http://127.0.0.1:${port:8086}",
|
||||
"MESH_INFLUXDB_URL": "http://127.0.0.1:8086",
|
||||
"MESH_INFLUXDB_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_INFLUXDB_TOKEN_FILE": "/run/secrets/admin-token",
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||
"MESH_INFLUXDB_CONFIG_DIR": "/var/lib/influxdb/config"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
@@ -125,15 +97,6 @@
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "influxdb",
|
||||
"endpoint": "api"
|
||||
}
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
@@ -154,5 +117,14 @@
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
},
|
||||
"requires": [
|
||||
"secret"
|
||||
],
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"admin": "/var/lib/influxdb-module/admin.secret",
|
||||
"admin-token": "/var/lib/influxdb-module/admin-token.secret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,14 +1,9 @@
|
||||
{
|
||||
"name": "@novox/module-influxdb",
|
||||
"version": "0.1.0",
|
||||
"description": "influxdb — time-series database; provides the mesh influxdb-api interface. Its API client, provisioner and tools live here (novox/hq ADR 0039).",
|
||||
"description": "influxdb — time-series database. Its API client and tools live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts grants.ts provisioner/index.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"typecheck": "tsc -p tsconfig.json",
|
||||
"test": "npm run build && node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
},
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
// influxdb's provisioner — the adapter that makes influxdb a provider of the mesh `influxdb-api`
|
||||
// interface. The reconcile loop, the contributions file and reading the mesh's minted secret are the
|
||||
// sdk harness's; this writes only the per-service half: how InfluxDB creates, checks and removes a
|
||||
// consumer's credential (novox/hq ADR 0039/0040/0048). What that credential is, and why it is a v1
|
||||
// authorization, is in ../grants.ts.
|
||||
//
|
||||
// The `influxdb-api` interface: a consumer reaches `${bound:influxdb-api:scheme}://…:at:…:port`,
|
||||
// signs in as `${bound:influxdb-api:as}` with the password the mesh minted for the pair, and reads
|
||||
// or writes the org's buckets as databases of the same name — `${bound:influxdb-api:bucket}` being
|
||||
// the one this instance serves by default. The org and the default bucket are the assignment's
|
||||
// settings, which reach both what is served and this module's config.json, so the org a consumer is
|
||||
// told and the org its credential is made in cannot disagree.
|
||||
|
||||
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||
import { InfluxDBClient } from "../client.js";
|
||||
import { ApiGrants } from "../grants.js";
|
||||
|
||||
let grants: ApiGrants | undefined;
|
||||
try {
|
||||
const influx = InfluxDBClient.fromEnv();
|
||||
grants = new ApiGrants(influx, influx.org);
|
||||
} catch (err) {
|
||||
// No admin token: nothing can be provisioned, and the tools loaded beside this must still serve.
|
||||
console.error(`[provisioner:influxdb-api] not started: ${err instanceof Error ? err.message : err}`);
|
||||
}
|
||||
|
||||
if (grants) serve(grants);
|
||||
|
||||
function serve(grants: ApiGrants): void {
|
||||
runProvisioner("influxdb-api", {
|
||||
async create(p: Provision): Promise<void> {
|
||||
const done = await grants.ensure(p);
|
||||
if (done !== "unchanged") {
|
||||
console.log(`[provisioner:influxdb-api] ${done} v1 authorization ${p.as} in org ${grants.org}`);
|
||||
}
|
||||
},
|
||||
|
||||
async remove(p: { as: string }): Promise<void> {
|
||||
const done = await grants.remove(p.as);
|
||||
if (done === "not ours") {
|
||||
console.error(`[provisioner:influxdb-api] ${p.as}: an authorization of that name exists that the mesh did not make — left alone`);
|
||||
} else if (done === "removed") {
|
||||
console.log(`[provisioner:influxdb-api] removed v1 authorization ${p.as}; its buckets and their data stay`);
|
||||
}
|
||||
},
|
||||
|
||||
// Asked every minute by the harness: whether InfluxDB still holds this consumer's authorization
|
||||
// exactly as the mesh gave it, so one deleted, disabled or re-passworded behind the mesh's back is
|
||||
// made whole again (hq issue 120).
|
||||
async holds(p: Provision): Promise<boolean> {
|
||||
return grants.holds(p);
|
||||
},
|
||||
});
|
||||
}
|
||||
@@ -1,246 +0,0 @@
|
||||
// What holds influxdb to the `influxdb-api` provision (grants.ts): one v1 authorization per consumer,
|
||||
// under the username and password the mesh gave, allowed only what the consumer contributed; made
|
||||
// once and brought back on every apply; buckets created when missing and never deleted; and an
|
||||
// authorization the mesh did not make — same name or not — never adopted, changed or deleted.
|
||||
//
|
||||
// InfluxDB is a fake: the routes the module touches, answering with the status codes and shapes
|
||||
// InfluxDB 2.9 gives (a filter matching nothing is a 404, a password outside 8–72 characters a 400,
|
||||
// an inactive authorization or a wrong password a 401 on /query). Run against the compiled module
|
||||
// (npm test builds first), the way the runtime loads it.
|
||||
|
||||
import { test, after, beforeEach } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import { createServer, type IncomingMessage, type ServerResponse } from "node:http";
|
||||
|
||||
import { InfluxDBClient } from "../dist/client.js";
|
||||
import { ApiGrants, MARK, askedFor, marked } from "../dist/grants.js";
|
||||
|
||||
type Rec = Record<string, any>;
|
||||
|
||||
const ADMIN = "operator-token";
|
||||
const orgs = new Map<string, string>([["zurag", "org1"]]);
|
||||
let buckets: Rec[] = [];
|
||||
let auths: Rec[] = [];
|
||||
let calls: string[] = [];
|
||||
let seq = 0;
|
||||
|
||||
function body(req: IncomingMessage): Promise<any> {
|
||||
return new Promise((resolve) => {
|
||||
let raw = "";
|
||||
req.on("data", (c) => (raw += c));
|
||||
req.on("end", () => resolve(raw ? JSON.parse(raw) : undefined));
|
||||
});
|
||||
}
|
||||
|
||||
function send(res: ServerResponse, status: number, value?: unknown): void {
|
||||
res.writeHead(status, { "Content-Type": "application/json" });
|
||||
res.end(value === undefined ? "" : JSON.stringify(value));
|
||||
}
|
||||
|
||||
const server = createServer(async (req, res) => {
|
||||
const url = new URL(req.url!, "http://fake");
|
||||
const p = url.pathname;
|
||||
calls.push(`${req.method} ${p}`);
|
||||
if (p === "/query") {
|
||||
const basic = (req.headers.authorization ?? "").replace(/^Basic /, "");
|
||||
const [u, pw] = Buffer.from(basic, "base64").toString().split(":");
|
||||
const a = auths.find((x) => x.token === u);
|
||||
if (!a || a.status !== "active" || a.password === undefined || a.password !== pw) {
|
||||
return send(res, 401, { code: "unauthorized", message: "Unauthorized" });
|
||||
}
|
||||
return send(res, 200, { results: [{ statement_id: 0 }] });
|
||||
}
|
||||
if (req.headers.authorization !== `Token ${ADMIN}`) return send(res, 401, { code: "unauthorized" });
|
||||
if (p === "/api/v2/orgs") {
|
||||
const id = orgs.get(url.searchParams.get("org") ?? "");
|
||||
if (!id) return send(res, 404, { code: "not found", message: "organization name not found" });
|
||||
return send(res, 200, { orgs: [{ id, name: url.searchParams.get("org") }] });
|
||||
}
|
||||
if (p === "/api/v2/buckets" && req.method === "GET") {
|
||||
const found = buckets.filter((b) => b.orgID === url.searchParams.get("orgID") && b.name === url.searchParams.get("name"));
|
||||
if (found.length === 0) return send(res, 404, { code: "not found", message: "bucket not found" });
|
||||
return send(res, 200, { buckets: found });
|
||||
}
|
||||
if (p === "/api/v2/buckets" && req.method === "POST") {
|
||||
const b = { ...(await body(req)), id: `b${++seq}` };
|
||||
buckets.push(b);
|
||||
return send(res, 201, b);
|
||||
}
|
||||
if (p === "/private/legacy/authorizations" && req.method === "GET") {
|
||||
const found = auths.filter((a) => a.token === url.searchParams.get("token"));
|
||||
if (found.length === 0) return send(res, 404, { code: "not found", message: "authorization not found" });
|
||||
// Never answers with the password: InfluxDB keeps only its hash.
|
||||
return send(res, 200, { authorizations: found.map(({ password, ...a }) => ({ ...a, links: {} })) });
|
||||
}
|
||||
if (p === "/private/legacy/authorizations" && req.method === "POST") {
|
||||
const a = await body(req);
|
||||
if (auths.some((x) => x.token === a.token)) return send(res, 409, { code: "conflict", message: "token already exists" });
|
||||
const made = { ...a, id: `a${++seq}`, status: a.status ?? "active" };
|
||||
auths.push(made);
|
||||
return send(res, 201, made);
|
||||
}
|
||||
const m = /^\/private\/legacy\/authorizations\/([^/]+)(\/password)?$/.exec(p);
|
||||
const a = m && auths.find((x) => x.id === m[1]);
|
||||
if (!a) return send(res, 404, { code: "not found" });
|
||||
if (m![2] && req.method === "POST") {
|
||||
const { password } = await body(req);
|
||||
if (typeof password !== "string" || password.length < 8 || password.length > 72) {
|
||||
return send(res, 400, { code: "invalid", message: "passwords must be between 8 and 72 characters long" });
|
||||
}
|
||||
a.password = password;
|
||||
return send(res, 204);
|
||||
}
|
||||
if (req.method === "PATCH") {
|
||||
Object.assign(a, await body(req));
|
||||
return send(res, 200, a);
|
||||
}
|
||||
if (req.method === "DELETE") {
|
||||
auths = auths.filter((x) => x !== a);
|
||||
return send(res, 204);
|
||||
}
|
||||
send(res, 405);
|
||||
});
|
||||
await new Promise<void>((r) => server.listen(0, "127.0.0.1", r));
|
||||
after(() => server.close());
|
||||
const port = (server.address() as { port: number }).port;
|
||||
|
||||
const grants = new ApiGrants(new InfluxDBClient(`http://127.0.0.1:${port}`, ADMIN, "zurag"), "zurag");
|
||||
|
||||
const PW = "mesh-minted-password-of-forty-characters";
|
||||
|
||||
/** Grafana on ace, as the mesh hands it to the provisioner. */
|
||||
function grafana(password = PW, values: Record<string, unknown> = { access: "read" }) {
|
||||
return { as: "mesh_ace_grafana", password, consumer: "ace", values };
|
||||
}
|
||||
/** Node-RED on ace: writes one bucket. */
|
||||
function nodered(password = PW, values: Record<string, unknown> = { access: "write", buckets: ["zurag"] }) {
|
||||
return { as: "mesh_ace_nodered", password, consumer: "ace", values };
|
||||
}
|
||||
|
||||
function only(token: string): Rec {
|
||||
const found = auths.filter((a) => a.token === token);
|
||||
assert.equal(found.length, 1, `exactly one authorization ${token}, found ${found.length}`);
|
||||
return found[0];
|
||||
}
|
||||
|
||||
function perms(a: Rec): string[] {
|
||||
return a.permissions.map((p: Rec) => `${p.action}:${p.resource.type}:${p.resource.id ?? "*"}`).sort();
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
buckets = [{ id: "zb", orgID: "org1", name: "zurag" }];
|
||||
auths = [];
|
||||
calls = [];
|
||||
});
|
||||
|
||||
test("what a contribution may ask for, and what is refused", () => {
|
||||
assert.deepEqual(askedFor({}), { access: "read", buckets: [] });
|
||||
assert.deepEqual(askedFor({ access: "read-write", buckets: ["b", "a", "a"] }), { access: "read-write", buckets: ["a", "b"] });
|
||||
assert.throws(() => askedFor({ access: "admin" }), /access/);
|
||||
assert.throws(() => askedFor({ access: "write" }), /names no bucket/);
|
||||
assert.throws(() => askedFor({ buckets: "zurag" }), /list of bucket names/);
|
||||
assert.throws(() => askedFor({ access: "write", buckets: ["_monitoring"] }), /system bucket/);
|
||||
});
|
||||
|
||||
test("a reader is given one authorization, reading every bucket of the org, under the mesh's password", async () => {
|
||||
assert.equal(await grants.ensure(grafana()), "created");
|
||||
const a = only("mesh_ace_grafana");
|
||||
assert.equal(a.orgID, "org1");
|
||||
assert.equal(a.status, "active");
|
||||
assert.ok(a.description.startsWith(MARK));
|
||||
assert.deepEqual(perms(a), ["read:buckets:*"]);
|
||||
assert.equal(a.password, PW);
|
||||
assert.equal(await grants.holds(grafana()), true);
|
||||
});
|
||||
|
||||
test("a writer is allowed its own buckets only, and a missing one is made — never deleted", async () => {
|
||||
assert.equal(await grants.ensure(nodered(PW, { access: "write", buckets: ["zurag", "printer"] })), "created");
|
||||
const made = buckets.find((b) => b.name === "printer");
|
||||
assert.ok(made, "the missing bucket was created");
|
||||
assert.deepEqual(made!.retentionRules, [], "kept for ever: retention is the operator's choice");
|
||||
assert.deepEqual(perms(only("mesh_ace_nodered")), [`write:buckets:${made!.id}`, "write:buckets:zb"]);
|
||||
assert.equal(await grants.remove("mesh_ace_nodered"), "removed");
|
||||
assert.equal(buckets.length, 2, "withdrawing the consumer leaves every bucket and its data");
|
||||
});
|
||||
|
||||
test("applying the same grant again writes nothing", async () => {
|
||||
await grants.ensure(grafana());
|
||||
calls = [];
|
||||
assert.equal(await grants.ensure(grafana()), "unchanged");
|
||||
assert.ok(calls.every((c) => c.startsWith("GET")), `only reads: ${calls.join(", ")}`);
|
||||
only("mesh_ace_grafana");
|
||||
});
|
||||
|
||||
test("a rotated password is set in place; a changed access remakes only the mesh's own", async () => {
|
||||
await grants.ensure(nodered());
|
||||
const id = only("mesh_ace_nodered").id;
|
||||
assert.equal(await grants.holds(nodered("rotated-password-0123456789")), false);
|
||||
assert.equal(await grants.ensure(nodered("rotated-password-0123456789")), "updated");
|
||||
assert.equal(only("mesh_ace_nodered").id, id, "updated, not replaced");
|
||||
assert.equal(await grants.holds(nodered("rotated-password-0123456789")), true);
|
||||
|
||||
await grants.ensure(nodered(PW, { access: "read-write", buckets: ["zurag"] }));
|
||||
assert.deepEqual(perms(only("mesh_ace_nodered")), ["read:buckets:zb", "write:buckets:zb"]);
|
||||
assert.equal(await grants.holds(nodered(PW, { access: "read-write", buckets: ["zurag"] })), true);
|
||||
});
|
||||
|
||||
test("an authorization disabled, re-passworded or deleted behind the mesh's back is not held, and is made whole", async () => {
|
||||
await grants.ensure(grafana());
|
||||
only("mesh_ace_grafana").status = "inactive";
|
||||
assert.equal(await grants.holds(grafana()), false);
|
||||
assert.equal(await grants.ensure(grafana()), "updated");
|
||||
assert.equal(await grants.holds(grafana()), true);
|
||||
|
||||
only("mesh_ace_grafana").password = "somebody-else-set-this";
|
||||
assert.equal(await grants.holds(grafana()), false);
|
||||
await grants.ensure(grafana());
|
||||
assert.equal(await grants.holds(grafana()), true);
|
||||
|
||||
auths = [];
|
||||
assert.equal(await grants.holds(grafana()), false);
|
||||
assert.equal(await grants.ensure(grafana()), "created");
|
||||
});
|
||||
|
||||
test("holds only reads, and a bucket gone missing is not held rather than made", async () => {
|
||||
await grants.ensure(nodered());
|
||||
buckets = [];
|
||||
calls = [];
|
||||
assert.equal(await grants.holds(nodered()), false);
|
||||
assert.ok(calls.every((c) => c.startsWith("GET")), `only reads: ${calls.join(", ")}`);
|
||||
assert.equal(buckets.length, 0);
|
||||
});
|
||||
|
||||
test("an authorization of the same name the mesh did not make is refused, and left exactly as it was", async () => {
|
||||
auths = [{ id: "theirs", token: "mesh_ace_grafana", orgID: "org1", status: "active", description: "hand-made",
|
||||
permissions: [{ action: "write", resource: { type: "buckets", orgID: "org1" } }], password: "their-password" }];
|
||||
const before = JSON.stringify(auths);
|
||||
await assert.rejects(grants.ensure(grafana()), /did not make/);
|
||||
assert.equal(JSON.stringify(auths), before);
|
||||
assert.ok(calls.every((c) => c.startsWith("GET")), `only reads: ${calls.join(", ")}`);
|
||||
assert.equal(await grants.holds(grafana()), false);
|
||||
assert.equal(await grants.remove("mesh_ace_grafana"), "not ours");
|
||||
assert.equal(auths.length, 1, "never deleted");
|
||||
});
|
||||
|
||||
test("the predecessor's own v1 users and tokens are never touched", async () => {
|
||||
auths = [{ id: "hal", token: "grafana", orgID: "org1", status: "active", description: "",
|
||||
permissions: [{ action: "read", resource: { type: "buckets", orgID: "org1" } }], password: "old-password" }];
|
||||
await grants.ensure(grafana());
|
||||
assert.equal(auths.find((a) => a.id === "hal")!.password, "old-password");
|
||||
assert.equal(await grants.remove("grafana"), "not ours");
|
||||
assert.equal(marked({ token: "grafana", description: `${MARK} x` }), false, "the mark needs the mesh's name too");
|
||||
});
|
||||
|
||||
test("an org the instance does not have, or a non-mesh name, makes nothing", async () => {
|
||||
const elsewhere = new ApiGrants(new InfluxDBClient(`http://127.0.0.1:${port}`, ADMIN, "nope"), "nope");
|
||||
await assert.rejects(elsewhere.ensure(grafana()), /no org "nope"/);
|
||||
await assert.rejects(grants.ensure({ ...grafana(), as: "grafana" }), /not a mesh identity/);
|
||||
assert.equal(auths.length, 0);
|
||||
});
|
||||
|
||||
test("a withdrawn consumer's authorization is removed, and an absent one is not an error", async () => {
|
||||
await grants.ensure(grafana());
|
||||
assert.equal(await grants.remove("mesh_ace_grafana"), "removed");
|
||||
assert.equal(auths.length, 0);
|
||||
assert.equal(await grants.remove("mesh_ace_grafana"), "absent");
|
||||
});
|
||||
@@ -8,10 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": [
|
||||
"client.ts",
|
||||
"grants.ts",
|
||||
"provisioner/index.ts",
|
||||
"tools/index.ts"
|
||||
]
|
||||
"include": ["client.ts", "tools/index.ts"]
|
||||
}
|
||||
|
||||
@@ -87,10 +87,7 @@
|
||||
},
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "api",
|
||||
@@ -108,10 +105,7 @@
|
||||
"ports": [
|
||||
"9000"
|
||||
],
|
||||
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (invoicing-app server/src/config.js); converting is that repository's change",
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (invoicing-app server/src/config.js); converting is that repository's change"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
+16
-53
@@ -2,8 +2,7 @@
|
||||
// an indexer proxy: it normalises many torrent trackers behind one Torznab surface. This client
|
||||
// talks its /api/v2.0 REST API, and only jackett's tools import it.
|
||||
|
||||
import { existsSync, readFileSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
export interface JackettIndexer {
|
||||
id: string;
|
||||
@@ -44,36 +43,18 @@ export class JackettClient {
|
||||
|
||||
/**
|
||||
* Build from the module's resolved environment. Jackett's REST API is keyed, so both the URL and
|
||||
* the key must be present. The key is read from the settings-merged config or MESH_JACKETT_API_KEY,
|
||||
* or, failing those, discovered from Jackett's own ServerConfig.json under MESH_JACKETT_CONFIG_DIR
|
||||
* — the file Jackett writes it to, as sonarr/radarr read theirs from config.xml — so a running
|
||||
* server needs no key configured by hand and no secret has to be put in an assignment. Without a
|
||||
* URL or key there is nothing to talk to, so this throws and the module contributes no tools
|
||||
* rather than failing half-configured.
|
||||
* the key must be present — without them there is nothing to talk to, so this throws and the
|
||||
* module contributes no tools rather than failing half-configured.
|
||||
*/
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): JackettClient {
|
||||
const cfg = meshConfig(env.MESH_JACKETT_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_JACKETT_URL;
|
||||
const apiKey = cfg.apiKey ?? env.MESH_JACKETT_API_KEY
|
||||
?? JackettClient.detectApiKey(env.MESH_JACKETT_CONFIG_DIR ?? "/config");
|
||||
const apiKey = cfg.apiKey ?? env.MESH_JACKETT_API_KEY;
|
||||
if (!url) throw new Error("no Jackett URL — set MESH_JACKETT_URL");
|
||||
if (!apiKey) throw new Error("no Jackett API key — set MESH_JACKETT_API_KEY or make the config dir readable");
|
||||
if (!apiKey) throw new Error("no Jackett API key — set MESH_JACKETT_API_KEY");
|
||||
return new JackettClient(url, apiKey);
|
||||
}
|
||||
|
||||
/** Discover the API key from Jackett's ServerConfig.json (the linuxserver image keeps it at
|
||||
* <config>/Jackett/ServerConfig.json), falling back to null. */
|
||||
static detectApiKey(configDir: string): string | null {
|
||||
for (const file of [join(configDir, "Jackett", "ServerConfig.json"), join(configDir, "ServerConfig.json")]) {
|
||||
if (!existsSync(file)) continue;
|
||||
try {
|
||||
const key = (JSON.parse(readFileSync(file, "utf8")) as { APIKey?: unknown }).APIKey;
|
||||
if (typeof key === "string" && key) return key;
|
||||
} catch { /* unreadable or mid-write: try the next, then give up */ }
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private async get(path: string, params: Record<string, string> = {}): Promise<any> {
|
||||
const url = new URL(`${this.baseUrl}${path}`);
|
||||
url.searchParams.set("apikey", this.apiKey);
|
||||
@@ -83,36 +64,18 @@ export class JackettClient {
|
||||
return res.json();
|
||||
}
|
||||
|
||||
/**
|
||||
* The configured indexers Jackett proxies. `configured=false` also lists the ones not set up.
|
||||
* Read from the Torznab `t=indexers` feed, not /api/v2.0/indexers: that one is the web UI's and
|
||||
* wants a login cookie (it answers an API-key request with a redirect), while the Torznab feed is
|
||||
* what the key is for. The feed carries no last error, so `lastError` stays unset.
|
||||
*/
|
||||
/** The configured indexers Jackett proxies. `configured=false` also lists the ones not set up. */
|
||||
async getIndexers(configuredOnly = true): Promise<JackettIndexer[]> {
|
||||
const url = new URL(`${this.baseUrl}/api/v2.0/indexers/all/results/torznab/api`);
|
||||
url.searchParams.set("apikey", this.apiKey);
|
||||
url.searchParams.set("t", "indexers");
|
||||
url.searchParams.set("configured", configuredOnly ? "true" : "false");
|
||||
const res = await fetch(url.toString(), { headers: { Accept: "application/xml" } });
|
||||
if (!res.ok) throw new Error(`Jackett API torznab t=indexers: ${res.status} ${await res.text()}`);
|
||||
const xml = await res.text();
|
||||
// Torznab reports failures (a wrong key among them) as 200 with an <error> body.
|
||||
const err = xml.match(/<error code="(\d+)" description="([^"]*)"/);
|
||||
if (err) throw new Error(`Jackett API torznab t=indexers: error ${err[1]} ${err[2]}`);
|
||||
const text = (block: string, tag: string) =>
|
||||
block.match(new RegExp(`<${tag}>([^<]*)</${tag}>`))?.[1];
|
||||
const out: JackettIndexer[] = [];
|
||||
for (const m of xml.matchAll(/<indexer id="([^"]+)" configured="([^"]+)">([\s\S]*?)<\/indexer>/g)) {
|
||||
out.push({
|
||||
id: m[1],
|
||||
name: text(m[3], "title") ?? m[1],
|
||||
type: text(m[3], "type") ?? "unknown",
|
||||
configured: m[2] === "true",
|
||||
siteLink: text(m[3], "link"),
|
||||
});
|
||||
}
|
||||
return out;
|
||||
const raw = await this.get("/api/v2.0/indexers", { configured: configuredOnly ? "true" : "false" });
|
||||
const list = Array.isArray(raw) ? raw : [];
|
||||
return list.map((i: any) => ({
|
||||
id: i.id,
|
||||
name: i.name,
|
||||
type: i.type,
|
||||
configured: i.configured ?? false,
|
||||
siteLink: i.site_link,
|
||||
lastError: i.last_error || undefined,
|
||||
}));
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -1,19 +1,6 @@
|
||||
{
|
||||
"module": "jackett",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "jackett-api",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"jackett-api": {
|
||||
"scheme": "http",
|
||||
"port": 9117,
|
||||
"url-base": ""
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -23,7 +10,7 @@
|
||||
"port": 9117,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the indexer proxy: its web UI, and the Torznab feeds the *arr apps search through, which other modules reach as jackett-api"
|
||||
"why": "the indexer proxy"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -33,15 +20,10 @@
|
||||
"path": "/var/lib/mesh/jackett",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "directory",
|
||||
"path": "/services/jackett/config",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
@@ -49,7 +31,7 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "jackett",
|
||||
"image": "lscr.io/linuxserver/jackett@sha256:7b19f4f6ac33d855ca9226600ecbd096ee678f66da28b13a7c09980b035ff583",
|
||||
"image": "lscr.io/linuxserver/jackett@sha256:fd72d42b731ebf750b5de9711127251cf3b3f609419c32083ea8b3b3ee840b77",
|
||||
"env": {
|
||||
"PUID": "1000",
|
||||
"PGID": "1000",
|
||||
@@ -59,13 +41,13 @@
|
||||
"9117"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:config}:/config"
|
||||
"/services/jackett/config:/config"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/config.json",
|
||||
"path": "/var/lib/mesh/jackett/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
@@ -77,12 +59,12 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/jackett/broker:/run/secrets/broker:ro",
|
||||
"${dir:state}/config.json:/run/config/config.json:ro",
|
||||
"${dir:config}:/var/lib/jackett/config:ro"
|
||||
"/var/lib/mesh/jackett/config.json:/run/config/config.json:ro",
|
||||
"/services/jackett/config:/var/lib/jackett/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_JACKETT_URL": "http://127.0.0.1:${port:9117}",
|
||||
"MESH_JACKETT_URL": "http://127.0.0.1:9117",
|
||||
"MESH_JACKETT_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_JACKETT_CONFIG_DIR": "/var/lib/jackett/config"
|
||||
},
|
||||
@@ -105,7 +87,7 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
"route": "/var/lib/mesh/jackett/route.json"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
@@ -9,7 +9,7 @@ export function getJackettTools(jackett: JackettClient): ToolDefinition[] {
|
||||
return [
|
||||
{
|
||||
name: "jackett_indexers",
|
||||
description: "List the indexers Jackett proxies, with their type and site.",
|
||||
description: "List the indexers Jackett proxies, with their type and any last error.",
|
||||
input: { all: { type: "boolean", description: "include indexers not yet configured (default false)" } },
|
||||
run: async (args) => {
|
||||
const indexers = await jackett.getIndexers(!args.all);
|
||||
|
||||
@@ -17,7 +17,7 @@ FROM ${BUILD_BASE} AS build
|
||||
# resolved away.
|
||||
WORKDIR /app/modules/keycloak
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts oidc.ts index.ts provisioner/index.ts tools/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
@@ -27,4 +27,4 @@ COPY --from=build /app/modules/keycloak/dist /app/modules/keycloak/dist
|
||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
||||
# ran no provisioner at all.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/keycloak/dist/index.js,/app/modules/keycloak/dist/tools/index.js,/app/modules/keycloak/dist/provisioner/index.js
|
||||
ENV MESH_TOOL_MODULES=/app/modules/keycloak/dist/index.js,/app/modules/keycloak/dist/tools/index.js
|
||||
|
||||
@@ -12,45 +12,6 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** A secret file's value, trailing newline trimmed; undefined when unset or unreadable. */
|
||||
function secretFile(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").replace(/\n$/, "") || undefined; }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
/** A client as the admin API represents it — only the fields this module reads or writes are typed;
|
||||
* the rest travel through untouched, so an update never drops what somebody else set. */
|
||||
export interface ClientRepresentation {
|
||||
id?: string;
|
||||
clientId: string;
|
||||
name?: string;
|
||||
enabled?: boolean;
|
||||
protocol?: string;
|
||||
publicClient?: boolean;
|
||||
clientAuthenticatorType?: string;
|
||||
secret?: string;
|
||||
rootUrl?: string;
|
||||
baseUrl?: string;
|
||||
redirectUris?: string[];
|
||||
webOrigins?: string[];
|
||||
standardFlowEnabled?: boolean;
|
||||
implicitFlowEnabled?: boolean;
|
||||
directAccessGrantsEnabled?: boolean;
|
||||
serviceAccountsEnabled?: boolean;
|
||||
attributes?: Record<string, string>;
|
||||
protocolMappers?: ProtocolMapperRepresentation[];
|
||||
[other: string]: unknown;
|
||||
}
|
||||
|
||||
export interface ProtocolMapperRepresentation {
|
||||
id?: string;
|
||||
name: string;
|
||||
protocol: string;
|
||||
protocolMapper: string;
|
||||
config: Record<string, string>;
|
||||
}
|
||||
|
||||
export class KeycloakClient {
|
||||
readonly baseUrl: string;
|
||||
readonly defaultRealm: string;
|
||||
@@ -79,13 +40,8 @@ export class KeycloakClient {
|
||||
const cfg = meshConfig(env.MESH_KEYCLOAK_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_KEYCLOAK_URL ?? `http://127.0.0.1:${env.KEYCLOAK_PORT ?? "8080"}`;
|
||||
const adminUser = cfg.user ?? env.MESH_KEYCLOAK_ADMIN ?? env.KEYCLOAK_ADMIN ?? "admin";
|
||||
// The admin password reaches the runtime as a file (novox/hq ADR 0086): the module's own `admin`
|
||||
// secret, mounted read-only. The environment forms stay for a co-located server that has them.
|
||||
const adminPass = cfg.password ?? secretFile(env.MESH_KEYCLOAK_PASSWORD_FILE)
|
||||
?? env.MESH_KEYCLOAK_PASSWORD ?? env.KEYCLOAK_ADMIN_PASSWORD;
|
||||
if (!adminPass) {
|
||||
throw new Error("no Keycloak admin password — set MESH_KEYCLOAK_PASSWORD_FILE (or MESH_KEYCLOAK_PASSWORD)");
|
||||
}
|
||||
const adminPass = cfg.password ?? env.MESH_KEYCLOAK_PASSWORD ?? env.KEYCLOAK_ADMIN_PASSWORD;
|
||||
if (!adminPass) throw new Error("no Keycloak admin password — set MESH_KEYCLOAK_PASSWORD");
|
||||
const realm = cfg.realm ?? env.MESH_KEYCLOAK_REALM ?? "master";
|
||||
return new KeycloakClient(url, adminUser, adminPass, realm);
|
||||
}
|
||||
@@ -203,50 +159,6 @@ export class KeycloakClient {
|
||||
return client.id as string;
|
||||
}
|
||||
|
||||
/** The one client with exactly this clientId, or undefined. The admin API's `clientId` filter is an
|
||||
* exact match unless `search=true` is asked for. */
|
||||
async findClient(realm: string, clientId: string): Promise<ClientRepresentation | undefined> {
|
||||
const found = await this.request<ClientRepresentation[]>(
|
||||
`/${realm}/clients?clientId=${encodeURIComponent(clientId)}`);
|
||||
return found.find((c) => c.clientId === clientId);
|
||||
}
|
||||
|
||||
async createClientFrom(realm: string, rep: ClientRepresentation): Promise<void> {
|
||||
await this.request(`/${realm}/clients`, { method: "POST", body: JSON.stringify(rep) });
|
||||
}
|
||||
|
||||
/** Replace a client's representation, addressed by its internal id. */
|
||||
async updateClient(realm: string, id: string, rep: ClientRepresentation): Promise<void> {
|
||||
await this.request(`/${realm}/clients/${id}`, { method: "PUT", body: JSON.stringify(rep) });
|
||||
}
|
||||
|
||||
async deleteClientById(realm: string, id: string): Promise<void> {
|
||||
await this.request(`/${realm}/clients/${id}`, { method: "DELETE" });
|
||||
}
|
||||
|
||||
async clientSecretById(realm: string, id: string): Promise<string | undefined> {
|
||||
const result = await this.request<{ value?: string }>(`/${realm}/clients/${id}/client-secret`);
|
||||
return result.value;
|
||||
}
|
||||
|
||||
async listClientMappers(realm: string, id: string): Promise<ProtocolMapperRepresentation[]> {
|
||||
return this.request(`/${realm}/clients/${id}/protocol-mappers/models`);
|
||||
}
|
||||
|
||||
async addClientMapper(realm: string, id: string, mapper: ProtocolMapperRepresentation): Promise<void> {
|
||||
await this.request(`/${realm}/clients/${id}/protocol-mappers/models`, {
|
||||
method: "POST",
|
||||
body: JSON.stringify(mapper),
|
||||
});
|
||||
}
|
||||
|
||||
async updateClientMapper(realm: string, id: string, mapper: ProtocolMapperRepresentation): Promise<void> {
|
||||
await this.request(`/${realm}/clients/${id}/protocol-mappers/models/${mapper.id}`, {
|
||||
method: "PUT",
|
||||
body: JSON.stringify(mapper),
|
||||
});
|
||||
}
|
||||
|
||||
async deleteClient(realm: string, clientId: string): Promise<void> {
|
||||
await this.request(`/${realm}/clients/${await this.resolveClientId(realm, clientId)}`, { method: "DELETE" });
|
||||
}
|
||||
|
||||
@@ -1,12 +1,6 @@
|
||||
{
|
||||
"module": "keycloak",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "oidc-client",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"postgres-database",
|
||||
"route"
|
||||
@@ -47,19 +41,6 @@
|
||||
"why": "anything the mesh runs that authenticates a person"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"oidc-client": {
|
||||
"authorization-path": "/protocol/openid-connect/auth",
|
||||
"token-path": "/protocol/openid-connect/token",
|
||||
"userinfo-path": "/protocol/openid-connect/userinfo"
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"oidc-client": "/var/lib/keycloak/grants/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"oidc-client": "/var/lib/keycloak/grants"
|
||||
},
|
||||
"own-secrets": {
|
||||
"admin": "/var/lib/keycloak/admin.secret",
|
||||
"broker": "/var/lib/mesh/keycloak/broker"
|
||||
@@ -77,12 +58,6 @@
|
||||
"path": "/var/lib/keycloak",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/keycloak/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "admin-env",
|
||||
"type": "file",
|
||||
@@ -102,13 +77,6 @@
|
||||
"type": "network",
|
||||
"name": "keycloak"
|
||||
},
|
||||
{
|
||||
"id": "hostname",
|
||||
"type": "file",
|
||||
"path": "/var/lib/keycloak/hostname.env",
|
||||
"mode": "0644",
|
||||
"content": "KC_HOSTNAME=https://${bound:route:name}\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
@@ -122,20 +90,17 @@
|
||||
"KC_DB": "postgres",
|
||||
"KC_HTTP_ENABLED": "true",
|
||||
"KC_HEALTH_ENABLED": "true",
|
||||
"KC_HOSTNAME": "https://keycloak.novox.be",
|
||||
"KC_PROXY_HEADERS": "xforwarded"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/keycloak/admin.env",
|
||||
"/var/lib/keycloak/database.env",
|
||||
"/var/lib/keycloak/hostname.env"
|
||||
"/var/lib/keycloak/database.env"
|
||||
],
|
||||
"ports": [
|
||||
"8080"
|
||||
],
|
||||
"secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted",
|
||||
"restart-on": [
|
||||
"hostname"
|
||||
]
|
||||
"secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
@@ -152,16 +117,12 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/keycloak/admin.secret:/run/secrets/admin:ro",
|
||||
"/var/lib/keycloak/grants:/var/lib/keycloak/grants:ro"
|
||||
"/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
||||
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin",
|
||||
"MESH_RECEIVES": "/var/lib/keycloak/grants/mesh.json"
|
||||
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
|
||||
@@ -1,185 +0,0 @@
|
||||
// What the `oidc-client` provision means in Keycloak: one confidential OpenID Connect client per
|
||||
// consumer, in the realm this module serves, under the name and secret the mesh gave both ends.
|
||||
// The provisioner (provisioner/index.ts) is the sdk harness calling these; they are here, apart from
|
||||
// it, so they can be exercised against a fake admin API without a broker or a contributions file.
|
||||
//
|
||||
// **The client id and the secret are the mesh's, not Keycloak's (novox/hq ADR 0048).** The mesh
|
||||
// derives the consumer's identity (`as`, e.g. `mesh_ace_grafana`) and hands it to both ends — the
|
||||
// consumer names it as its client id through `${bound:oidc-client:as}` — and mints the secret, which
|
||||
// this sets as the client's secret. Keycloak generates neither.
|
||||
//
|
||||
// **Where the consumer's browser comes back to is the consumer's to say.** Its contribution carries
|
||||
// `callback` (a path, e.g. `/login/generic_oauth`) and the `label`/`endpoint` of the endpoint it is
|
||||
// reached on; the mesh composes that endpoint's names into `name` (public) and `internal-name`
|
||||
// (private network) exactly as it does for a route (novox/hq ADR 0056, 0138), so the redirect URI
|
||||
// registered here is built from the same names the proxy serves the consumer under.
|
||||
//
|
||||
// **Only what the mesh made is touched.** A client this module creates carries the attribute
|
||||
// `mesh.provisioned=true`, and its id starts with the mesh's own prefix. A client with the same id
|
||||
// that lacks the mark is somebody else's: it is refused, never adopted, never updated, never deleted.
|
||||
|
||||
import type { ClientRepresentation, KeycloakClient, ProtocolMapperRepresentation } from "./client.js";
|
||||
|
||||
/** The attribute marking a client as the mesh's own work. */
|
||||
export const MARK = "mesh.provisioned";
|
||||
|
||||
/** The mapper every mesh client carries: realm roles as a flat `roles` claim in the id token, the
|
||||
* access token and userinfo — what a consumer maps its own roles from (grafana's role path reads
|
||||
* `roles[*]`), and what the predecessor added to its hand-made clients by hand. */
|
||||
export const ROLES_MAPPER: ProtocolMapperRepresentation = {
|
||||
name: "realm roles",
|
||||
protocol: "openid-connect",
|
||||
protocolMapper: "oidc-usermodel-realm-role-mapper",
|
||||
config: {
|
||||
"claim.name": "roles",
|
||||
"jsonType.label": "String",
|
||||
multivalued: "true",
|
||||
"id.token.claim": "true",
|
||||
"access.token.claim": "true",
|
||||
"userinfo.token.claim": "true",
|
||||
},
|
||||
};
|
||||
|
||||
/** One consumer, as the harness hands it over. */
|
||||
export interface OidcGrant {
|
||||
readonly as: string;
|
||||
readonly password: string;
|
||||
readonly values: Readonly<Record<string, unknown>>;
|
||||
readonly consumer?: string;
|
||||
}
|
||||
|
||||
/** The realm named by an issuer URL — `https://id.example/realms/Novox` is realm `Novox`. The issuer is
|
||||
* the one value an assignment sets (it is also what consumers are served), so the realm is read
|
||||
* out of it rather than set a second time where the two could disagree. */
|
||||
export function realmOf(issuer: string): string {
|
||||
let path: string;
|
||||
try {
|
||||
path = new URL(issuer).pathname;
|
||||
} catch {
|
||||
throw new Error(`the issuer ${JSON.stringify(issuer)} is not a URL`);
|
||||
}
|
||||
const m = /\/realms\/([^/]+)\/?$/.exec(path);
|
||||
if (!m) throw new Error(`the issuer ${JSON.stringify(issuer)} does not end in /realms/<realm>`);
|
||||
return decodeURIComponent(m[1]);
|
||||
}
|
||||
|
||||
/** The redirect URIs a consumer's contribution asks for: its callback under each name the mesh
|
||||
* composed for its endpoint. Refused when there is nothing to register — a client that accepts no
|
||||
* redirect is a client nobody can log in through, and one that accepts any is worse. */
|
||||
export function redirectsOf(values: Readonly<Record<string, unknown>>): { root: string; redirects: string[] } {
|
||||
const callback = values.callback;
|
||||
if (typeof callback !== "string" || !callback.startsWith("/")) {
|
||||
throw new Error(`contributes no callback path (\`callback\`, starting with "/"): ${JSON.stringify(callback)}`);
|
||||
}
|
||||
const names: string[] = [];
|
||||
for (const key of ["name", "internal-name"]) {
|
||||
const n = values[key];
|
||||
if (typeof n === "string" && n.trim() !== "" && !names.includes(n.trim())) names.push(n.trim());
|
||||
}
|
||||
if (names.length === 0) {
|
||||
throw new Error("has no name the mesh composed (`name` / `internal-name`) — contribute a `label` and the `endpoint` it is reached on");
|
||||
}
|
||||
return { root: `https://${names[0]}`, redirects: names.map((n) => `https://${n}${callback}`) };
|
||||
}
|
||||
|
||||
/** The fields the mesh owns on a client it made. Everything else on the client is left as found. */
|
||||
function wanted(g: OidcGrant): ClientRepresentation {
|
||||
const { root, redirects } = redirectsOf(g.values);
|
||||
return {
|
||||
clientId: g.as,
|
||||
name: g.as,
|
||||
description: `made by the mesh for ${g.consumer ? `a module on ${g.consumer}` : "a consumer"} — do not edit; it is reset`,
|
||||
enabled: true,
|
||||
protocol: "openid-connect",
|
||||
publicClient: false,
|
||||
clientAuthenticatorType: "client-secret",
|
||||
secret: g.password,
|
||||
rootUrl: root,
|
||||
baseUrl: root,
|
||||
redirectUris: redirects,
|
||||
standardFlowEnabled: true,
|
||||
implicitFlowEnabled: false,
|
||||
directAccessGrantsEnabled: false,
|
||||
serviceAccountsEnabled: false,
|
||||
};
|
||||
}
|
||||
|
||||
function sameSet(a: readonly string[] | undefined, b: readonly string[]): boolean {
|
||||
const x = [...(a ?? [])].sort();
|
||||
const y = [...b].sort();
|
||||
return x.length === y.length && x.every((v, i) => v === y[i]);
|
||||
}
|
||||
|
||||
function marked(c: ClientRepresentation): boolean {
|
||||
return c.attributes?.[MARK] === "true";
|
||||
}
|
||||
|
||||
export class OidcClients {
|
||||
constructor(private readonly kc: KeycloakClient, readonly realm: string) {}
|
||||
|
||||
/** Create the consumer's client, or bring the mesh's existing one back to what the grant says.
|
||||
* Returns whether it was newly created. Idempotent: applying the same grant twice changes nothing
|
||||
* the second time beyond re-asserting it. */
|
||||
async ensure(g: OidcGrant): Promise<"created" | "updated"> {
|
||||
const want = wanted(g);
|
||||
const found = await this.kc.findClient(this.realm, g.as);
|
||||
if (found && !marked(found)) {
|
||||
throw new Error(
|
||||
`realm ${this.realm} already has a client ${g.as} the mesh did not make — left alone; ` +
|
||||
`delete or rename it if the mesh should own that id`);
|
||||
}
|
||||
if (!found) {
|
||||
await this.kc.createClientFrom(this.realm, {
|
||||
...want,
|
||||
attributes: { [MARK]: "true" },
|
||||
protocolMappers: [ROLES_MAPPER],
|
||||
});
|
||||
return "created";
|
||||
}
|
||||
// Overlay what the mesh owns on what is there, so a field Keycloak added or an operator set on a
|
||||
// field the mesh does not own survives the update.
|
||||
await this.kc.updateClient(this.realm, found.id!, {
|
||||
...found,
|
||||
...want,
|
||||
attributes: { ...(found.attributes ?? {}), [MARK]: "true" },
|
||||
});
|
||||
await this.ensureMapper(found.id!);
|
||||
return "updated";
|
||||
}
|
||||
|
||||
private async ensureMapper(id: string): Promise<void> {
|
||||
const mappers = await this.kc.listClientMappers(this.realm, id);
|
||||
const have = mappers.find((m) => m.name === ROLES_MAPPER.name);
|
||||
if (!have) {
|
||||
await this.kc.addClientMapper(this.realm, id, ROLES_MAPPER);
|
||||
return;
|
||||
}
|
||||
const drifted =
|
||||
have.protocolMapper !== ROLES_MAPPER.protocolMapper ||
|
||||
Object.entries(ROLES_MAPPER.config).some(([k, v]) => have.config?.[k] !== v);
|
||||
if (drifted) {
|
||||
await this.kc.updateClientMapper(this.realm, id, { ...ROLES_MAPPER, id: have.id });
|
||||
}
|
||||
}
|
||||
|
||||
/** Whether Keycloak still holds this consumer's client exactly as the grant says: present, the
|
||||
* mesh's, enabled, confidential, with the mesh's secret and the redirects asked for. Reads only. */
|
||||
async holds(g: OidcGrant): Promise<boolean> {
|
||||
const want = wanted(g);
|
||||
const found = await this.kc.findClient(this.realm, g.as);
|
||||
if (!found || !marked(found) || found.enabled === false || found.publicClient) return false;
|
||||
if (!sameSet(found.redirectUris, want.redirectUris!)) return false;
|
||||
const mappers = await this.kc.listClientMappers(this.realm, found.id!);
|
||||
if (!mappers.some((m) => m.name === ROLES_MAPPER.name)) return false;
|
||||
return (await this.kc.clientSecretById(this.realm, found.id!)) === g.password;
|
||||
}
|
||||
|
||||
/** Withdraw a consumer's client — only one the mesh made. Returns what happened, for the log. */
|
||||
async remove(as: string): Promise<"removed" | "absent" | "not ours"> {
|
||||
const found = await this.kc.findClient(this.realm, as);
|
||||
if (!found) return "absent";
|
||||
if (!marked(found)) return "not ours";
|
||||
await this.kc.deleteClientById(this.realm, found.id!);
|
||||
return "removed";
|
||||
}
|
||||
}
|
||||
@@ -1,15 +1,11 @@
|
||||
{
|
||||
"name": "@novox/module-keycloak",
|
||||
"version": "0.1.0",
|
||||
"description": "keycloak — identity and access; provides the mesh oidc-client interface. Its admin API client, provisioner, tools and events live here (novox/hq ADR 0039).",
|
||||
"description": "keycloak — identity and access. Its admin API client, tools and events live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts oidc.ts index.ts provisioner/index.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"test": "npm run build && node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.1"
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/node": "^22.0.0",
|
||||
|
||||
@@ -1,73 +0,0 @@
|
||||
// keycloak's provisioner — the adapter that makes keycloak a provider of the mesh `oidc-client`
|
||||
// interface. The reconcile loop, the contributions file and reading the mesh's minted secret are the
|
||||
// sdk harness's; this writes only the per-service half: how Keycloak creates, checks and removes a
|
||||
// consumer's client (novox/hq ADR 0039/0040/0048). What a client is, and which ones are the mesh's,
|
||||
// is in ../oidc.ts.
|
||||
//
|
||||
// The `oidc-client` interface: a consumer logs people in through the realm this module serves, as
|
||||
// the confidential client `as` with the secret the mesh minted, and is redirected back to the
|
||||
// callback it contributed under the names the mesh composed for its endpoint. What it is served —
|
||||
// the issuer and the endpoint paths under it — is in the manifest's `serves`, settled with the
|
||||
// assignment's settings.
|
||||
//
|
||||
// **The realm is read out of the issuer**, the one value an assignment sets (settings reach both the
|
||||
// served facts and this module's config.json): a realm set in one place and an issuer in another
|
||||
// would let the consumer be told one realm while its client is made in another.
|
||||
|
||||
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||
import { emit } from "@novox/mesh-sdk/events";
|
||||
import { readFileSync } from "node:fs";
|
||||
import { KeycloakClient } from "../client.js";
|
||||
import { OidcClients, realmOf } from "../oidc.js";
|
||||
|
||||
/** The issuer this assignment serves, from the settings-merged config the mesh delivers. */
|
||||
function issuer(): string {
|
||||
const file = process.env.MESH_KEYCLOAK_CONFIG_FILE;
|
||||
let cfg: Record<string, unknown> = {};
|
||||
if (file) {
|
||||
try {
|
||||
cfg = JSON.parse(readFileSync(file, "utf8")) as Record<string, unknown>;
|
||||
} catch {
|
||||
// Absent or unreadable: fall through to the environment, and refuse below if that is empty too.
|
||||
}
|
||||
}
|
||||
const said = typeof cfg.issuer === "string" ? cfg.issuer : process.env.MESH_KEYCLOAK_ISSUER;
|
||||
if (!said) throw new Error("no issuer — the module's config.json carries none and MESH_KEYCLOAK_ISSUER is unset");
|
||||
return said;
|
||||
}
|
||||
|
||||
const clients = new OidcClients(KeycloakClient.fromEnv(), realmOf(issuer()));
|
||||
|
||||
/** Emit a lifecycle event without letting a broker hiccup fail the provisioning itself. */
|
||||
async function announce(type: string, body: Record<string, string>): Promise<void> {
|
||||
try {
|
||||
await emit(type, body);
|
||||
} catch (err) {
|
||||
console.error(`[provisioner:oidc-client] emit ${type} failed: ${err}`);
|
||||
}
|
||||
}
|
||||
|
||||
runProvisioner("oidc-client", {
|
||||
async create(p: Provision): Promise<void> {
|
||||
const done = await clients.ensure(p);
|
||||
if (done === "created") {
|
||||
console.log(`[provisioner:oidc-client] created client ${p.as} in realm ${clients.realm}`);
|
||||
await announce("client.created", { realm: clients.realm, clientId: p.as, consumer: p.consumer ?? "" });
|
||||
}
|
||||
},
|
||||
|
||||
async remove(p: { as: string }): Promise<void> {
|
||||
const done = await clients.remove(p.as);
|
||||
if (done === "not ours") {
|
||||
console.error(`[provisioner:oidc-client] ${p.as}: a client of that id exists that the mesh did not make — left alone`);
|
||||
} else if (done === "removed") {
|
||||
console.log(`[provisioner:oidc-client] removed client ${p.as} from realm ${clients.realm}`);
|
||||
}
|
||||
},
|
||||
|
||||
// Asked every minute by the harness: whether Keycloak still holds this consumer's client exactly as
|
||||
// the mesh gave it, so a client deleted or edited behind the mesh's back is made again (hq issue 120).
|
||||
async holds(p: Provision): Promise<boolean> {
|
||||
return clients.holds(p);
|
||||
},
|
||||
});
|
||||
@@ -1,239 +0,0 @@
|
||||
// What holds keycloak to the `oidc-client` provision (oidc.ts): one confidential client per consumer,
|
||||
// under the id and secret the mesh gave, redirecting only to the consumer's own callback under the
|
||||
// names the mesh composed; made once and brought back on every apply; and a client the mesh did not
|
||||
// make — same id or not — never adopted, changed or deleted.
|
||||
//
|
||||
// Keycloak is a fake: the admin routes the module touches, answering with the status codes and the
|
||||
// shapes Keycloak gives. Run against the compiled module (npm test builds first), the way the runtime
|
||||
// loads it.
|
||||
|
||||
import { test, after } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import { createServer, type IncomingMessage, type ServerResponse } from "node:http";
|
||||
import { randomUUID } from "node:crypto";
|
||||
|
||||
import { KeycloakClient } from "../dist/client.js";
|
||||
import { MARK, OidcClients, ROLES_MAPPER, realmOf, redirectsOf } from "../dist/oidc.js";
|
||||
|
||||
type Client = Record<string, any>;
|
||||
|
||||
/** The realm's clients, by internal id, and what the fake was asked. */
|
||||
const realm = "Novox";
|
||||
const clients = new Map<string, Client>();
|
||||
const calls: string[] = [];
|
||||
|
||||
function body(req: IncomingMessage): Promise<any> {
|
||||
return new Promise((resolve) => {
|
||||
let raw = "";
|
||||
req.on("data", (c) => (raw += c));
|
||||
req.on("end", () => resolve(raw ? JSON.parse(raw) : undefined));
|
||||
});
|
||||
}
|
||||
|
||||
function send(res: ServerResponse, status: number, value?: unknown): void {
|
||||
res.writeHead(status, { "Content-Type": "application/json" });
|
||||
res.end(value === undefined ? "" : JSON.stringify(value));
|
||||
}
|
||||
|
||||
const server = createServer(async (req, res) => {
|
||||
const url = new URL(req.url!, "http://fake");
|
||||
calls.push(`${req.method} ${url.pathname}`);
|
||||
if (url.pathname === "/realms/master/protocol/openid-connect/token") {
|
||||
return send(res, 200, { access_token: "t", expires_in: 300 });
|
||||
}
|
||||
const base = `/admin/realms/${realm}/clients`;
|
||||
if (!url.pathname.startsWith(base)) return send(res, 404, { error: "Realm not found." });
|
||||
const rest = url.pathname.slice(base.length).split("/").filter(Boolean);
|
||||
if (rest.length === 0 && req.method === "GET") {
|
||||
const want = url.searchParams.get("clientId");
|
||||
return send(res, 200, [...clients.values()].filter((c) => !want || c.clientId === want));
|
||||
}
|
||||
if (rest.length === 0 && req.method === "POST") {
|
||||
const rep = await body(req);
|
||||
if ([...clients.values()].some((c) => c.clientId === rep.clientId)) {
|
||||
return send(res, 409, { errorMessage: `Client ${rep.clientId} already exists` });
|
||||
}
|
||||
const id = randomUUID();
|
||||
const mappers = (rep.protocolMappers ?? []).map((m: Client) => ({ ...m, id: randomUUID() }));
|
||||
clients.set(id, { ...rep, id, protocolMappers: mappers });
|
||||
return send(res, 201);
|
||||
}
|
||||
const c = clients.get(rest[0]);
|
||||
if (!c) return send(res, 404, { error: "Could not find client" });
|
||||
if (rest.length === 1 && req.method === "PUT") {
|
||||
// Keycloak ignores protocolMappers on a client update: they have their own endpoints.
|
||||
const rep = await body(req);
|
||||
clients.set(c.id, { ...rep, id: c.id, protocolMappers: c.protocolMappers });
|
||||
return send(res, 204);
|
||||
}
|
||||
if (rest.length === 1 && req.method === "DELETE") {
|
||||
clients.delete(c.id);
|
||||
return send(res, 204);
|
||||
}
|
||||
if (rest[1] === "client-secret" && req.method === "GET") {
|
||||
return send(res, 200, { type: "secret", value: c.secret });
|
||||
}
|
||||
if (rest[1] === "protocol-mappers") {
|
||||
if (req.method === "GET") return send(res, 200, c.protocolMappers ?? []);
|
||||
if (req.method === "POST") {
|
||||
c.protocolMappers = [...(c.protocolMappers ?? []), { ...(await body(req)), id: randomUUID() }];
|
||||
return send(res, 201);
|
||||
}
|
||||
if (req.method === "PUT") {
|
||||
const m = await body(req);
|
||||
c.protocolMappers = c.protocolMappers.map((x: Client) => (x.id === rest[4] ? m : x));
|
||||
return send(res, 204);
|
||||
}
|
||||
}
|
||||
send(res, 405);
|
||||
});
|
||||
await new Promise<void>((r) => server.listen(0, "127.0.0.1", r));
|
||||
after(() => server.close());
|
||||
const port = (server.address() as { port: number }).port;
|
||||
|
||||
const oidc = new OidcClients(new KeycloakClient(`http://127.0.0.1:${port}`, "admin", "pw"), realm);
|
||||
|
||||
/** Grafana on ace, as the mesh hands it to the provisioner. */
|
||||
function grafana(secret = "s3cret", values: Record<string, unknown> = {}) {
|
||||
return {
|
||||
as: "mesh_ace_grafana",
|
||||
password: secret,
|
||||
consumer: "ace",
|
||||
values: {
|
||||
label: "grafana", endpoint: "web", port: 20010, callback: "/login/generic_oauth",
|
||||
name: "grafana.zurag.be", "internal-name": "grafana.ace.internal", ...values,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
function only(clientId: string): Client {
|
||||
const found = [...clients.values()].filter((c) => c.clientId === clientId);
|
||||
assert.equal(found.length, 1, `exactly one client ${clientId}, found ${found.length}`);
|
||||
return found[0];
|
||||
}
|
||||
|
||||
test("the realm is read out of the issuer, and an issuer that names none is refused", () => {
|
||||
assert.equal(realmOf("https://keycloak.novox.be/realms/Novox"), "Novox");
|
||||
assert.equal(realmOf("https://keycloak.novox.be/realms/Novox/"), "Novox");
|
||||
assert.equal(realmOf("http://127.0.0.1:18500/realms/master"), "master");
|
||||
assert.throws(() => realmOf("https://keycloak.novox.be"), /realms/);
|
||||
assert.throws(() => realmOf("keycloak"), /not a URL/);
|
||||
});
|
||||
|
||||
test("the redirect is the consumer's callback under every name the mesh composed for it", () => {
|
||||
assert.deepEqual(redirectsOf(grafana().values), {
|
||||
root: "https://grafana.zurag.be",
|
||||
redirects: ["https://grafana.zurag.be/login/generic_oauth", "https://grafana.ace.internal/login/generic_oauth"],
|
||||
});
|
||||
// A route reaching only the private network has only the internal name, and that is enough.
|
||||
assert.deepEqual(redirectsOf({ callback: "/cb", "internal-name": "x.ace.internal" }).redirects,
|
||||
["https://x.ace.internal/cb"]);
|
||||
assert.throws(() => redirectsOf({ name: "grafana.zurag.be" }), /callback/);
|
||||
assert.throws(() => redirectsOf({ name: "grafana.zurag.be", callback: "login" }), /callback/);
|
||||
assert.throws(() => redirectsOf({ callback: "/cb" }), /label/);
|
||||
});
|
||||
|
||||
test("a consumer is given one confidential client, under its id and the mesh's secret", async () => {
|
||||
clients.clear();
|
||||
assert.equal(await oidc.ensure(grafana()), "created");
|
||||
const c = only("mesh_ace_grafana");
|
||||
assert.equal(c.publicClient, false);
|
||||
assert.equal(c.clientAuthenticatorType, "client-secret");
|
||||
assert.equal(c.secret, "s3cret");
|
||||
assert.equal(c.enabled, true);
|
||||
assert.equal(c.standardFlowEnabled, true);
|
||||
assert.equal(c.directAccessGrantsEnabled, false);
|
||||
assert.equal(c.implicitFlowEnabled, false);
|
||||
assert.deepEqual(c.redirectUris, [
|
||||
"https://grafana.zurag.be/login/generic_oauth", "https://grafana.ace.internal/login/generic_oauth"]);
|
||||
assert.equal(c.attributes[MARK], "true");
|
||||
assert.deepEqual(c.protocolMappers.map((m: Client) => m.name), [ROLES_MAPPER.name]);
|
||||
assert.equal(await oidc.holds(grafana()), true);
|
||||
});
|
||||
|
||||
test("applying the same grant again makes no second client", async () => {
|
||||
clients.clear();
|
||||
await oidc.ensure(grafana());
|
||||
assert.equal(await oidc.ensure(grafana()), "updated");
|
||||
assert.equal(await oidc.ensure(grafana()), "updated");
|
||||
only("mesh_ace_grafana");
|
||||
assert.equal(only("mesh_ace_grafana").protocolMappers.length, 1, "the roles mapper is not added twice");
|
||||
});
|
||||
|
||||
test("a new secret or a moved name is applied in place, and what the mesh does not own survives", async () => {
|
||||
clients.clear();
|
||||
await oidc.ensure(grafana());
|
||||
const id = only("mesh_ace_grafana").id;
|
||||
// Something the mesh does not own, set on the client after it was made.
|
||||
clients.get(id)!.consentRequired = true;
|
||||
clients.get(id)!.attributes["post.logout.redirect.uris"] = "+";
|
||||
|
||||
assert.equal(await oidc.holds(grafana("rotated")), false, "a rotated secret is not held until applied");
|
||||
await oidc.ensure(grafana("rotated", { name: "dash.zurag.be" }));
|
||||
const c = only("mesh_ace_grafana");
|
||||
assert.equal(c.id, id, "updated, not replaced");
|
||||
assert.equal(c.secret, "rotated");
|
||||
assert.deepEqual(c.redirectUris, [
|
||||
"https://dash.zurag.be/login/generic_oauth", "https://grafana.ace.internal/login/generic_oauth"]);
|
||||
assert.equal(c.rootUrl, "https://dash.zurag.be");
|
||||
assert.equal(c.consentRequired, true);
|
||||
assert.equal(c.attributes["post.logout.redirect.uris"], "+");
|
||||
assert.equal(c.attributes[MARK], "true");
|
||||
assert.equal(await oidc.holds(grafana("rotated", { name: "dash.zurag.be" })), true);
|
||||
});
|
||||
|
||||
test("a client lost or edited behind the mesh's back is not held, and is made whole again", async () => {
|
||||
clients.clear();
|
||||
await oidc.ensure(grafana());
|
||||
const c = only("mesh_ace_grafana");
|
||||
c.redirectUris = ["*"];
|
||||
assert.equal(await oidc.holds(grafana()), false, "a widened redirect is not what the mesh gave");
|
||||
await oidc.ensure(grafana());
|
||||
assert.equal(await oidc.holds(grafana()), true);
|
||||
|
||||
only("mesh_ace_grafana").protocolMappers = [];
|
||||
assert.equal(await oidc.holds(grafana()), false, "a client without its roles mapper is not held");
|
||||
await oidc.ensure(grafana());
|
||||
assert.equal(await oidc.holds(grafana()), true);
|
||||
|
||||
clients.clear();
|
||||
assert.equal(await oidc.holds(grafana()), false);
|
||||
});
|
||||
|
||||
test("a client of the same id the mesh did not make is refused, and left exactly as it was", async () => {
|
||||
clients.clear();
|
||||
clients.set("theirs", { id: "theirs", clientId: "mesh_ace_grafana", secret: "their-secret", redirectUris: ["*"] });
|
||||
const before = JSON.stringify(clients.get("theirs"));
|
||||
const writes = calls.length;
|
||||
await assert.rejects(oidc.ensure(grafana()), /did not make/);
|
||||
assert.equal(JSON.stringify(clients.get("theirs")), before);
|
||||
assert.ok(calls.slice(writes).every((c) => c.startsWith("GET") || c.startsWith("POST /realms/master")),
|
||||
`only reads were made: ${calls.slice(writes).join(", ")}`);
|
||||
assert.equal(await oidc.holds(grafana()), false);
|
||||
assert.equal(await oidc.remove("mesh_ace_grafana"), "not ours");
|
||||
assert.ok(clients.has("theirs"), "a client the mesh did not make is never deleted");
|
||||
});
|
||||
|
||||
test("the predecessor's hand-made client is never touched: the mesh's has its own id", async () => {
|
||||
clients.clear();
|
||||
clients.set("hal", { id: "hal", clientId: "grafana", secret: "old", redirectUris: ["https://grafana.zurag.be/*"] });
|
||||
await oidc.ensure(grafana());
|
||||
assert.equal(clients.get("hal")!.secret, "old");
|
||||
only("mesh_ace_grafana");
|
||||
assert.equal(await oidc.remove("grafana"), "not ours");
|
||||
assert.ok(clients.has("hal"));
|
||||
});
|
||||
|
||||
test("a withdrawn consumer's client is removed, and an absent one is not an error", async () => {
|
||||
clients.clear();
|
||||
await oidc.ensure(grafana());
|
||||
assert.equal(await oidc.remove("mesh_ace_grafana"), "removed");
|
||||
assert.equal([...clients.values()].length, 0);
|
||||
assert.equal(await oidc.remove("mesh_ace_grafana"), "absent");
|
||||
});
|
||||
|
||||
test("a contribution with no callback makes no client at all", async () => {
|
||||
clients.clear();
|
||||
await assert.rejects(oidc.ensure({ ...grafana(), values: { name: "grafana.zurag.be" } }), /callback/);
|
||||
assert.equal(clients.size, 0);
|
||||
});
|
||||
@@ -8,5 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": ["client.ts", "oidc.ts", "index.ts", "provisioner/index.ts", "tools/index.ts"]
|
||||
"include": ["client.ts", "index.ts", "tools/index.ts"]
|
||||
}
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
// The Letta API client — letta's own code, living in the module (novox/hq ADR 0039). Its tools
|
||||
// import it; nothing outside letta does.
|
||||
//
|
||||
// Letta authenticates with a single server password. That password is a mesh own-secret handed to
|
||||
// both the server (LETTA_SERVER_PASSWORD) and this client, through the runtime config file the mesh
|
||||
// mounts (its `password` key) — so the module's tools are live without anything configured by hand.
|
||||
// Where a server already has clients, the password is accepted rather than minted.
|
||||
// Letta authenticates with a single server password, presented as a Bearer token. That password is
|
||||
// a mesh own-secret, minted once and handed to both the server (LETTA_SERVER_PASSWORD) and this
|
||||
// client (MESH_LETTA_PASSWORD) — so the module's tools are live without anything configured by hand.
|
||||
// The runtime config file may still override the URL or password.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
@@ -58,10 +58,6 @@ export class LettaClient {
|
||||
...options,
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
// The server's --secure mode checks X-BARE-PASSWORD ("password <it>") and answers a Bearer
|
||||
// token alone with 401 (letta/server/rest_api/app.py, 0.6.x). Both are sent: Bearer is what
|
||||
// later servers read.
|
||||
"X-BARE-PASSWORD": `password ${this.password}`,
|
||||
Authorization: `Bearer ${this.password}`,
|
||||
...(options.headers as Record<string, string> | undefined),
|
||||
},
|
||||
|
||||
+25
-21
@@ -5,28 +5,21 @@
|
||||
"container-runtime"
|
||||
],
|
||||
"requires": [
|
||||
"postgres-database",
|
||||
"route"
|
||||
"postgres-database"
|
||||
],
|
||||
"contributes": {
|
||||
"postgres-database": {
|
||||
"name": "letta"
|
||||
},
|
||||
"route": {
|
||||
"label": "letta",
|
||||
"endpoint": "web"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"postgres-database": "${dir:state}/database.json",
|
||||
"route": "${dir:state}/route.json"
|
||||
"postgres-database": "/var/lib/letta/database.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "${dir:state}/database.secret"
|
||||
"postgres-database": "/var/lib/letta/database.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"server-password": "${dir:state}/server-password.secret",
|
||||
"openai-api-key": "${dir:state}/openai-api-key.secret",
|
||||
"server-password": "/var/lib/letta/server-password.secret",
|
||||
"broker": "/var/lib/mesh/letta/broker"
|
||||
},
|
||||
"listens": [
|
||||
@@ -35,7 +28,7 @@
|
||||
"port": 8283,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the Letta agent server REST API and web UI, password-protected (--secure); a public name is the route's"
|
||||
"why": "the Letta agent server REST API and web UI; a public name is a route grant later"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -48,15 +41,15 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/letta",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"path": "/var/lib/letta/server.env",
|
||||
"mode": "0600",
|
||||
"content": "LETTA_PG_URI=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nLETTA_SERVER_PASSWORD=${secret:server-password}\nOPENAI_API_KEY=${secret:openai-api-key}\nSECURE=true\nTZ=Europe/Brussels\n"
|
||||
"content": "LETTA_PG_URI=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nLETTA_SERVER_PASSWORD=${secret:server-password}\nSECURE=true\nTZ=Europe/Brussels\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
@@ -67,24 +60,31 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "letta",
|
||||
"image": "letta/letta@sha256:bfd1e49ce45b9a208c941e832c1d1d194017ff210a3784b0ca6c323aed767a29",
|
||||
"image": "letta/letta@sha256:1d2e0692514287c5ed1a483e14e16ed945f8632d315539f5e66373bb7d7c471b",
|
||||
"network": "letta",
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
"/var/lib/letta/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"8283"
|
||||
],
|
||||
"secrets-in-environment": "letta 0.6.x reads its settings from the environment only (pydantic settings, no secrets_dir or _FILE twin), and its startup.sh starts an embedded PostgreSQL unless LETTA_PG_URI is set - so the database password travels inside that URI (startup.sh also echoes it to the log); LETTA_SERVER_PASSWORD and OPENAI_API_KEY have no file source either"
|
||||
"secrets-in-environment": "the letta image is env-driven and its file-source support could not be verified; the mesh runtime can take its password from config.json (client.ts) \u2014 not yet converted"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/letta/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"password\": \"${secret:server-password}\"\n}\n",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
"id": "runtime-env",
|
||||
"type": "file",
|
||||
"path": "/var/lib/letta/runtime.env",
|
||||
"mode": "0600",
|
||||
"content": "MESH_LETTA_PASSWORD=${secret:server-password}\n"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
@@ -99,10 +99,14 @@
|
||||
"MESH_LETTA_URL": "http://letta:8283",
|
||||
"MESH_LETTA_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/letta/runtime.env"
|
||||
],
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
"artifact": "runtime",
|
||||
"secrets-in-environment": "the letta image is env-driven and its file-source support could not be verified; the mesh runtime can take its password from config.json (client.ts) \u2014 not yet converted"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
|
||||
@@ -1,6 +1,19 @@
|
||||
{
|
||||
"module": "lidarr",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "lidarr-api",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"lidarr-api": {
|
||||
"scheme": "http",
|
||||
"port": 8686,
|
||||
"url-base": ""
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -75,7 +88,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_LIDARR_URL": "http://127.0.0.1:8686",
|
||||
"MESH_LIDARR_URL": "http://127.0.0.1:${port:8686}",
|
||||
"MESH_LIDARR_CONFIG_DIR": "/var/lib/lidarr/config"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
|
||||
@@ -1,17 +0,0 @@
|
||||
# mailu
|
||||
|
||||
Mail — Mailu, with its provisioner (the `smtp` provision) and tools, on the tool runtime.
|
||||
|
||||
## Settings
|
||||
|
||||
A definition names no mesh (novox/hq ADR 0112, ADR 0155), so the values that are this
|
||||
installation's are settings on the assignment, `settings set mailu <file>`:
|
||||
|
||||
```json
|
||||
{"domain": "…", "sitename": "…", "website": "https://…", "proxy-address": "…"}
|
||||
```
|
||||
|
||||
`domain` is the mail domain (also the provisioner's, for a consumer's address); `sitename` and
|
||||
`website` are shown by the web front; `proxy-address` is what `REAL_IP_FROM` trusts a real-IP
|
||||
header from — the address the proxy forwards with. The front's own hostname is the name of its
|
||||
`web` route, told to it by the mesh.
|
||||
@@ -120,21 +120,21 @@
|
||||
"port": 7080,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here — everything else 301s to https and would loop a proxy"
|
||||
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
|
||||
},
|
||||
{
|
||||
"name": "web-tls",
|
||||
"port": 7443,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the web front over its own TLS (admin, webmail, API); its public name is a route grant reaching it here"
|
||||
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
|
||||
},
|
||||
{
|
||||
"name": "autoconfig",
|
||||
"port": 4243,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "automx: mail client autoconfiguration; the autoconfig, autodiscover and automx names are route grants reaching it here"
|
||||
"why": "automx: mail client autoconfiguration; autoconfig/autodiscover/automx.novox.be are route grants reaching it here"
|
||||
}
|
||||
],
|
||||
"own-secrets": {
|
||||
@@ -168,7 +168,7 @@
|
||||
"type": "file",
|
||||
"path": "${dir:state}/mailu.env",
|
||||
"mode": "0644",
|
||||
"content": "ADMIN_ADDRESS=mailu-admin\nANTISPAM_ADDRESS=mailu-antispam\nANTIVIRUS_ADDRESS=mailu-antivirus\nIMAP_ADDRESS=mailu-imap\nSMTP_ADDRESS=mailu-smtp\nFRONT_ADDRESS=mailu-front\nWEBMAIL_ADDRESS=mailu-webmail\nWEBDAV_ADDRESS=mailu-webdav\nREDIS_ADDRESS=mailu-redis\nPORTS=25,80,443,465,993,995,4190,110,143,587\nDOMAIN=${setting:domain}\nHOSTNAMES=${bound:route:name-web}\nPOSTMASTER=admin\nSITENAME=${setting:sitename}\nWEBSITE=${setting:website}\nTLS_FLAVOR=letsencrypt\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=${setting:domain}\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=7080\nHTTPS_PORT=7443\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=${bound:route:name-web}\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=${bound:route:name-web}\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=${setting:domain}\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=${setting:proxy-address}\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\nWELCOME_SUBJECT=Welcome to your new email account\nWELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!\n"
|
||||
"content": "ADMIN_ADDRESS=mailu-admin\nANTISPAM_ADDRESS=mailu-antispam\nANTIVIRUS_ADDRESS=mailu-antivirus\nIMAP_ADDRESS=mailu-imap\nSMTP_ADDRESS=mailu-smtp\nFRONT_ADDRESS=mailu-front\nWEBMAIL_ADDRESS=mailu-webmail\nWEBDAV_ADDRESS=mailu-webdav\nREDIS_ADDRESS=mailu-redis\nPORTS=25,80,443,465,993,995,4190,110,143,587\nDOMAIN=novox.be\nHOSTNAMES=mail.novox.be\nPOSTMASTER=admin\nSITENAME=Novox\nWEBSITE=https://novox.be\nTLS_FLAVOR=letsencrypt\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=novox.be\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=7080\nHTTPS_PORT=7443\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=mail.novox.be\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=mail.novox.be\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=novox.be\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=142.132.152.141\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\nWELCOME_SUBJECT=Welcome to your new email account\nWELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!\n"
|
||||
},
|
||||
{
|
||||
"id": "secret-env",
|
||||
@@ -315,7 +315,10 @@
|
||||
"${dir:data-data}:/data",
|
||||
"${dir:data-dkim}:/dkim"
|
||||
],
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
|
||||
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified",
|
||||
"dns": [
|
||||
"192.168.203.254"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "imap",
|
||||
@@ -490,6 +493,7 @@
|
||||
"MESH_MAILU_API_KEY_FILE": "/run/secrets/api-token",
|
||||
"MESH_MAILU_IMAP_CONTAINER": "mailu-imap",
|
||||
"MESH_MAILU_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_MAILU_DOMAIN": "novox.be",
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"restart-on": [
|
||||
@@ -552,7 +556,9 @@
|
||||
],
|
||||
"serves": {
|
||||
"smtp": {
|
||||
"port": 587
|
||||
"port": 587,
|
||||
"domain": "novox.be",
|
||||
"name": "mail.novox.be"
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
|
||||
@@ -13,32 +13,17 @@
|
||||
// it to both ends; mailu sets exactly that password every run — so a rotation takes — and seals
|
||||
// nothing: the consumer already has its copy through the mesh's own channel.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||
import { MailuClient } from "../client.js";
|
||||
|
||||
const mailu = MailuClient.fromEnv();
|
||||
|
||||
// The mail server's own domain: the operator's value, from the settings the mesh merges into this
|
||||
// module's config file (`settings set mailu` with {"domain": …}; novox/hq ADR 0112, ADR 0155). A
|
||||
// definition names no mesh, so it is never a literal in the manifest — and it used to be, as
|
||||
// MESH_MAILU_DOMAIN, which is still read for a mesh that has not re-registered the manifest.
|
||||
// The mail server's own domain. From the environment the manifest composes, because the client's
|
||||
// config file carries the admin API's coordinates, not the mail domain.
|
||||
function domain(): string {
|
||||
const file = process.env.MESH_MAILU_CONFIG_FILE;
|
||||
if (file) {
|
||||
try {
|
||||
const config = JSON.parse(readFileSync(file, "utf8")) as { domain?: unknown };
|
||||
if (typeof config.domain === "string" && config.domain.trim() !== "") return config.domain.trim();
|
||||
} catch {
|
||||
// Unreadable or not JSON: fall through to the environment, and the error below names both.
|
||||
}
|
||||
}
|
||||
const named = (process.env.MESH_MAILU_DOMAIN ?? "").trim();
|
||||
if (named === "") {
|
||||
throw new Error(
|
||||
"no mail domain is set, so a consumer's address cannot be composed — `settings set mailu <file>` " +
|
||||
'with {"domain": "<the mail domain>"}',
|
||||
);
|
||||
throw new Error("MESH_MAILU_DOMAIN is not set, so a consumer's address cannot be composed");
|
||||
}
|
||||
return named;
|
||||
}
|
||||
|
||||
@@ -1,125 +0,0 @@
|
||||
{
|
||||
"module": "matrix",
|
||||
"version": "1",
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"listens": [
|
||||
{
|
||||
"name": "client",
|
||||
"port": 6167,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "Conduit's client-server and federation APIs over plain HTTP. Both arrive through the route on 443: Conduit answers /.well-known/matrix/server with <its name>:443, so other homeservers federate through the proxy and nothing needs the traditional 8448"
|
||||
},
|
||||
{
|
||||
"name": "web",
|
||||
"port": 80,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "Element Web, the static browser client, served by the image's nginx; reached through its route"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"homeserver": {
|
||||
"label": "matrix",
|
||||
"endpoint": "client"
|
||||
},
|
||||
"element": {
|
||||
"label": "element",
|
||||
"endpoint": "web"
|
||||
}
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"resources": [
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "db",
|
||||
"type": "directory",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "conduit-conf",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/conduit.toml",
|
||||
"mode": "0644",
|
||||
"content": "# Written by the mesh (modules/matrix). Conduit reads this file (CONDUIT_CONFIG); nothing comes\n# from the environment. server_name is the homeserver's permanent identity: every user id, room id\n# and signature in the database carries it, so it is the name this module is served under\n# (${bound:route:name-homeserver}) and never changes once a database exists.\n[global]\nserver_name = \"${bound:route:name-homeserver}\"\ndatabase_backend = \"rocksdb\"\ndatabase_path = \"/var/lib/matrix-conduit/\"\naddress = \"0.0.0.0\"\nport = 6167\nmax_request_size = 20000000\nallow_registration = false\nallow_federation = true\nallow_check_for_updates = true\ntrusted_servers = [\"matrix.org\"]\n",
|
||||
"names-on-purpose": {
|
||||
"matrix.org": "the federation's public key server, trusted by default; the world's, not this mesh's"
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "element-conf",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/element.json",
|
||||
"mode": "0644",
|
||||
"merge": "json",
|
||||
"content": "{\n \"default_server_name\": \"${bound:route:name-homeserver}\",\n \"default_server_config\": {\n \"m.homeserver\": {\n \"base_url\": \"https://${bound:route:name-homeserver}\"\n },\n \"m.identity_server\": {\n \"base_url\": \"https://vector.im\"\n }\n },\n \"brand\": \"Element\",\n \"integrations_ui_url\": \"https://scalar.vector.im/\",\n \"integrations_rest_url\": \"https://scalar.vector.im/api\",\n \"integrations_widgets_urls\": [\n \"https://scalar.vector.im/_matrix/integrations/v1\",\n \"https://scalar.vector.im/api\",\n \"https://scalar-staging.vector.im/_matrix/integrations/v1\",\n \"https://scalar-staging.vector.im/api\",\n \"https://scalar-staging.riot.im/scalar/api\"\n ],\n \"bug_report_endpoint_url\": \"https://element.io/bugreports/submit\",\n \"uisi_autorageshake_app\": \"element-auto-uisi\",\n \"show_labs_settings\": true,\n \"room_directory\": {\n \"servers\": [\n \"${bound:route:name-homeserver}\",\n \"matrix.org\",\n \"gitter.im\",\n \"libera.chat\"\n ]\n },\n \"enable_presence_by_hs_url\": {\n \"https://matrix.org\": false,\n \"https://matrix-client.matrix.org\": false\n },\n \"terms_and_conditions_links\": [\n {\n \"url\": \"https://element.io/privacy\",\n \"text\": \"Privacy Policy\"\n },\n {\n \"url\": \"https://element.io/cookie-policy\",\n \"text\": \"Cookie Policy\"\n }\n ],\n \"features\": {\n \"feature_video_rooms\": true,\n \"feature_rust_crypto\": true\n },\n \"element_call\": {\n \"url\": \"https://call.element.dev\"\n }\n}\n",
|
||||
"names-on-purpose": {
|
||||
"matrix.org": "the public room directory and the federation's largest homeserver; the world's",
|
||||
"matrix-client.matrix.org": "the same homeserver's client endpoint; the world's",
|
||||
"vector.im": "Element's public identity server; the world's",
|
||||
"scalar.vector.im": "Element's public integration manager; the world's",
|
||||
"scalar-staging.vector.im": "Element's staging integration manager, named by the upstream default config; the world's",
|
||||
"scalar-staging.riot.im": "the same, under its former name; the world's",
|
||||
"element.io": "Element's bug reports, privacy and cookie pages; the world's",
|
||||
"gitter.im": "a public room directory; the world's",
|
||||
"libera.chat": "a public room directory; the world's",
|
||||
"call.element.dev": "Element Call's public instance; the world's"
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
"type": "network",
|
||||
"name": "matrix"
|
||||
},
|
||||
{
|
||||
"id": "homeserver",
|
||||
"type": "container",
|
||||
"name": "matrix",
|
||||
"image": "matrixconduit/matrix-conduit@sha256:b0d24248e94f944ca49f90f10c429e3d65f4472bdde25661ecea9840134fb133",
|
||||
"network": "matrix",
|
||||
"env": {
|
||||
"CONDUIT_CONFIG": "/etc/conduit/conduit.toml"
|
||||
},
|
||||
"ports": [
|
||||
"6167"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:db}:/var/lib/matrix-conduit",
|
||||
"${dir:state}/conduit.toml:/etc/conduit/conduit.toml:ro"
|
||||
],
|
||||
"restart-on": [
|
||||
"conduit-conf"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "element",
|
||||
"type": "container",
|
||||
"name": "element-web",
|
||||
"image": "vectorim/element-web@sha256:a8f415462ab8d2600a592ba1b92bea51efe5a4d10eb738aab9bed769f7099613",
|
||||
"network": "matrix",
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:state}/element.json:/app/config.json:ro"
|
||||
],
|
||||
"restart-on": [
|
||||
"element-conf"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,13 +0,0 @@
|
||||
# The console (novox/hq ADR 0152, design 34): the mesh's tools for whoever is on a machine, served
|
||||
# over MCP on that machine's loopback.
|
||||
#
|
||||
# **Nothing is compiled here.** The console is the tool runtime's own client — `mesh serve` — which
|
||||
# the runtime image already carries beside the runtime it runs modules with. This recipe changes the
|
||||
# program the image starts and nothing else, so the console is exactly the client a person can run by
|
||||
# hand, started by the mesh instead, on the credential the mesh sealed to the machine.
|
||||
#
|
||||
# One base, named rather than pinned: the mesh answers with the copy it holds (novox/hq issue 044).
|
||||
ARG RUNTIME_BASE
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
ENTRYPOINT ["node", "dist/mesh.js"]
|
||||
@@ -1,38 +0,0 @@
|
||||
# mesh-console
|
||||
|
||||
The mesh's tools, on the machine a person sits at, served by a module the mesh assigned there
|
||||
(novox/hq [ADR 0152](https://git.novox.be/novox/hq), design 34).
|
||||
|
||||
Assign it to a machine and an agent on that machine has the mesh's tools at
|
||||
`http://127.0.0.1:<port>/mcp` — MCP over HTTP, `initialize`, `tools/list`, `tools/call`. A person at
|
||||
a terminal reaches the same endpoint with `mesh tools --console http://127.0.0.1:<port>` and
|
||||
`mesh call <module>.<tool> --console …`, with no credential of their own: the console holds it.
|
||||
|
||||
## What it is
|
||||
|
||||
The tool runtime's own client, `mesh serve`, started by the mesh on the credential it sealed to the
|
||||
machine for `<node>.mesh-console`. The manifest says three things nothing else in the catalogue says
|
||||
together:
|
||||
|
||||
- `invokes: ["*"]` — it calls every tool on the mesh, and the bus grants exactly that publish side;
|
||||
- a listener `from: machine` — loopback only, and the filter opens nothing for it;
|
||||
- no `emits`, no `consumes`, no `tools` — nothing on the bus can address it.
|
||||
|
||||
**Loopback is the authority boundary.** Whoever can connect is on the machine, and whoever is on the
|
||||
machine is the account that owns the mesh there (ADR 0034, ADR 0144). There is no token and no login,
|
||||
and `mesh serve` refuses to bind anything but a loopback address.
|
||||
|
||||
## What it lists
|
||||
|
||||
What the running modules answer: every tool runtime serves a `tools` verb for its module, and the
|
||||
console asks the catalogue which modules the mesh holds and each module what it serves. A module that
|
||||
did not answer — not assigned, not up, or built before the runtime answered `tools` — is named in the
|
||||
list's `_meta.notAnswering` and can still be called by `<module>.<tool>`.
|
||||
|
||||
The mesh's own verbs (`status`, `push`, `assign`) are the `mesh-controller` seat's tools under
|
||||
ADR 0132 and are not served on the bus yet; they appear here when they are.
|
||||
|
||||
## Port
|
||||
|
||||
The manifest declares port 4270 and the mesh assigns the machine port as it does for any listener;
|
||||
the console binds `127.0.0.1:${port:4270}`. `node show <machine>` says which port a machine was given.
|
||||
@@ -1,64 +0,0 @@
|
||||
{
|
||||
"module": "mesh-console",
|
||||
"version": "1",
|
||||
"slug": "console",
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"invokes": [
|
||||
"*"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/mesh-console/broker"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
"name": "mcp",
|
||||
"port": 4270,
|
||||
"protocol": "tcp",
|
||||
"from": "machine",
|
||||
"why": "the mesh's tools for whoever is on this machine, over MCP on loopback; the machine's login is the authority (novox/hq ADR 0152)"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "mesh-state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh/mesh-console",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "mesh-console",
|
||||
"network": "host",
|
||||
"args": [
|
||||
"serve"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_CONSOLE_LISTEN": "127.0.0.1:${port:4270}"
|
||||
},
|
||||
"volumes": [
|
||||
"/var/lib/mesh/mesh-console/broker:/run/secrets/broker:ro"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
"arg": "RUNTIME_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "runtime",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -86,7 +86,7 @@
|
||||
"type": "file",
|
||||
"path": "/var/lib/minio/root.env",
|
||||
"mode": "0600",
|
||||
"content": "MINIO_ROOT_USER=meshroot\nMINIO_BROWSER_REDIRECT_URL=https://${bound:route:name-console}\n"
|
||||
"content": "MINIO_ROOT_USER=meshroot\n"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
@@ -124,6 +124,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
||||
"MINIO_BROWSER_REDIRECT_URL": "https://files.novox.be",
|
||||
"MINIO_REGION": "eu-west"
|
||||
}
|
||||
},
|
||||
|
||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/mosquitto
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc topics.ts client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
|
||||
+24
-38
@@ -20,8 +20,6 @@ import { readFileSync } from "node:fs";
|
||||
import { execFile } from "node:child_process";
|
||||
import { promisify } from "node:util";
|
||||
|
||||
import { missingAcls, parseRoleAcls, staleAcls, wantedAcls } from "./topics.js";
|
||||
|
||||
const run = promisify(execFile);
|
||||
|
||||
export interface MqttConn {
|
||||
@@ -143,19 +141,14 @@ export class MosquittoClient {
|
||||
}
|
||||
|
||||
/**
|
||||
* Create (or reset to a known state) a client granted exactly these topic filters, idempotently.
|
||||
* The grant is a same-named role carrying, for every filter, publish, receive and subscribe — and
|
||||
* nothing else: an ACL the role carries that the filters no longer name is removed, so narrowing a
|
||||
* consumer's `topics` narrows what it may do. By default the filters are the consumer's own
|
||||
* subtree, `<as>/#` (see topics.ts). Called again for an existing client, it resets the password
|
||||
* and re-asserts the ACLs.
|
||||
*
|
||||
* Only the role named for this client is ever changed. A client or role the mesh did not make —
|
||||
* a device carried from the predecessor's password file, its `legacy-full-access` role — is never
|
||||
* read, changed or removed here.
|
||||
* Create (or reset to a known state) a client scoped to one topic namespace, idempotently. The
|
||||
* client is confined to `<prefix>/#` by a same-named role: it may publish to, subscribe to and
|
||||
* receive on exactly its own subtree and nothing else — the MQTT analog of redis's keyspace-scoped
|
||||
* ACL user. Called again for an existing client, it resets the password and re-asserts the ACLs.
|
||||
*/
|
||||
async createScopedClient(username: string, password: string, filters: readonly string[]): Promise<void> {
|
||||
async createScopedClient(username: string, password: string, topicPrefix: string): Promise<void> {
|
||||
const role = username; // one role per client, named for it
|
||||
const pattern = `${topicPrefix}/#`;
|
||||
|
||||
if (await this.clientExists(username)) {
|
||||
await this.ctl("setClientPassword", username, password);
|
||||
@@ -168,18 +161,17 @@ export class MosquittoClient {
|
||||
await this.ctl("createClient", username, "-p", password);
|
||||
}
|
||||
|
||||
// createRole and addRoleACL are one-shot: each rejects with an "already exists" when re-run
|
||||
// against a role/ACL it created on a previous reconcile. That rejection is the intended terminal
|
||||
// state, so it is swallowed.
|
||||
// A role carrying exactly this client's topic ACLs. createRole, addRoleACL and addClientRole are
|
||||
// all one-shot: each rejects with an "already exists" when re-run against a role/ACL/binding it
|
||||
// created on a previous reconcile. That rejection is the intended terminal state — the ACL is
|
||||
// deterministic (`<prefix>/#`, allow), so re-adding the identical entry is a no-op — so it is
|
||||
// swallowed. (Until the exit code was fixed this was invisible: the tool returned 0 and the
|
||||
// rejection was lost; now it surfaces, and each of these adds must tolerate its own idempotent
|
||||
// re-run explicitly.)
|
||||
await ignoreExisting(this.ctl("createRole", role));
|
||||
const wanted = wantedAcls(filters);
|
||||
const current = parseRoleAcls(await this.ctl("getRole", role));
|
||||
for (const acl of missingAcls(current, wanted)) {
|
||||
await ignoreExisting(this.ctl("addRoleACL", role, acl.type, acl.topic, "allow"));
|
||||
}
|
||||
// What the consumer no longer asks for — added before it narrowed its topics — is taken away.
|
||||
for (const acl of staleAcls(current, wanted)) {
|
||||
await ignoreMissing(this.ctl("removeRoleACL", role, acl.type, acl.topic));
|
||||
for (const acl of ["publishClientSend", "publishClientReceive", "subscribePattern"]) {
|
||||
// allow (1) this client to send to, receive on, and subscribe under its own subtree.
|
||||
await ignoreExisting(this.ctl("addRoleACL", role, acl, pattern, "allow"));
|
||||
}
|
||||
// Bind the role only when it is not already bound — addClientRole is the one call whose
|
||||
// idempotent re-run cannot be recognised by message (see clientHasRole).
|
||||
@@ -189,31 +181,25 @@ export class MosquittoClient {
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether a consumer's client accepts exactly this password, still carries its own role, and that
|
||||
* role grants exactly these filters. Read-only. The password is checked the way the consumer is
|
||||
* checked, by an MQTT CONNECT as it, and the broker's CONNACK code is the answer: 0 accepted,
|
||||
* 4 bad credentials, 5 not authorised. Nothing rides on argv. An unreachable broker rejects
|
||||
* (novox/hq issue 120).
|
||||
* Whether a consumer's client accepts exactly this password and still carries its own role.
|
||||
* Read-only. The password is checked the way the consumer is checked, by an MQTT CONNECT as it,
|
||||
* and the broker's CONNACK code is the answer: 0 accepted, 4 bad credentials, 5 not authorised.
|
||||
* Nothing rides on argv. An unreachable broker rejects (novox/hq issue 120).
|
||||
*/
|
||||
async holdsClient(username: string, password: string, filters: readonly string[]): Promise<boolean> {
|
||||
async holdsClient(username: string, password: string): Promise<boolean> {
|
||||
const code = await mqttConnack(this.conn.host, this.conn.port, username, password);
|
||||
if (code === 4 || code === 5) return false;
|
||||
if (code !== 0) throw new Error(`mosquitto refused ${username} with CONNACK ${code}`);
|
||||
// The role, asked directly: only "not found" means absent. Any other failure to ask rejects,
|
||||
// unlike clientHasRole, which reads every failure as "no role".
|
||||
let client: string;
|
||||
let role: string;
|
||||
let out: string;
|
||||
try {
|
||||
client = await this.ctl("getClient", username);
|
||||
role = await this.ctl("getRole", username);
|
||||
out = await this.ctl("getClient", username);
|
||||
} catch (err) {
|
||||
if (/not\s*found|does not exist|no such/i.test(String(err))) return false;
|
||||
throw err;
|
||||
}
|
||||
if (!new RegExp(`(^|\\s)${escapeRegExp(username)}\\s+\\(priority`, "m").test(client)) return false;
|
||||
const current = parseRoleAcls(role);
|
||||
const wanted = wantedAcls(filters);
|
||||
return missingAcls(current, wanted).length === 0 && staleAcls(current, wanted).length === 0;
|
||||
return new RegExp(`(^|\\s)${escapeRegExp(username)}\\s+\\(priority`, "m").test(out);
|
||||
}
|
||||
|
||||
/** Remove a client and the per-client role created for it, idempotently. */
|
||||
|
||||
@@ -20,19 +20,16 @@
|
||||
"mosquitto.topic.deprovisioned"
|
||||
],
|
||||
"serves": {
|
||||
"mqtt-topic": {
|
||||
"scheme": "mqtt",
|
||||
"port": 1883
|
||||
}
|
||||
"mqtt-topic": {}
|
||||
},
|
||||
"receives": {
|
||||
"mqtt-topic": "${dir:grants}/mesh.json"
|
||||
"mqtt-topic": "/var/lib/mosquitto-module/grants/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"mqtt-topic": "${dir:grants}"
|
||||
"mqtt-topic": "/var/lib/mosquitto-module/grants"
|
||||
},
|
||||
"own-secrets": {
|
||||
"admin": "/var/lib/mesh/mosquitto/admin",
|
||||
"admin": "/var/lib/mosquitto-module/admin.secret",
|
||||
"broker": "/var/lib/mesh/mosquitto/broker"
|
||||
},
|
||||
"listens": [
|
||||
@@ -61,24 +58,26 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/mosquitto-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"id": "grants-dir",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mosquitto-module/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/mosquitto/data",
|
||||
"mode": "0700",
|
||||
"owner": "1883:1883"
|
||||
},
|
||||
{
|
||||
"id": "server-conf",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/mosquitto.conf",
|
||||
"path": "/var/lib/mosquitto-module/mosquitto.conf",
|
||||
"mode": "0600",
|
||||
"owner": "1883:1883",
|
||||
"content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n"
|
||||
@@ -94,8 +93,8 @@
|
||||
"name": "mosquitto-bootstrap",
|
||||
"run-once": true,
|
||||
"volumes": [
|
||||
"${dir:data}:/mosquitto/data",
|
||||
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
|
||||
"/services/mosquitto/data:/mosquitto/data",
|
||||
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
||||
@@ -113,15 +112,15 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "mosquitto",
|
||||
"image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408",
|
||||
"image": "eclipse-mosquitto@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797",
|
||||
"network": "mosquitto",
|
||||
"ports": [
|
||||
"1883",
|
||||
"8081"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/mosquitto/data",
|
||||
"${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
|
||||
"/services/mosquitto/data:/mosquitto/data",
|
||||
"/var/lib/mosquitto-module/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -131,12 +130,12 @@
|
||||
"network": "mosquitto",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro",
|
||||
"${dir:grants}:${dir:grants}:ro",
|
||||
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
|
||||
"/var/lib/mosquitto-module/grants:/var/lib/mosquitto-module/grants:ro",
|
||||
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||
"MESH_RECEIVES": "/var/lib/mosquitto-module/grants/mesh.json",
|
||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin"
|
||||
|
||||
@@ -1,14 +1,9 @@
|
||||
{
|
||||
"name": "@novox/module-mosquitto",
|
||||
"version": "0.1.0",
|
||||
"description": "mosquitto \u2014 provides the mesh mqtt-topic interface. Its admin client, provisioner, tools and events live here (novox/hq ADR 0039).",
|
||||
"description": "mosquitto — provides the mesh mqtt-topic interface. Its admin client, provisioner, tools and events live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc topics.ts client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"typecheck": "tsc -p tsconfig.json",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.1"
|
||||
},
|
||||
|
||||
@@ -5,14 +5,7 @@
|
||||
//
|
||||
// The `mqtt-topic` interface: a consumer connects as `as` with the password the mesh minted, and
|
||||
// publishes and subscribes under `<as>/#`, isolated from every other consumer by a Dynamic Security
|
||||
// role scoped to exactly that subtree — unless it contributed `topics`, the MQTT topic filters its
|
||||
// work needs (a home-automation hub needs the devices' topics); then the role grants exactly those
|
||||
// (topics.ts). A list that is not valid topic filters is refused, and the consumer is not created
|
||||
// or changed until it is fixed.
|
||||
//
|
||||
// What a consumer is told (its binding): `at` — the broker's machine — and `port`, the machine port
|
||||
// of the MQTT listener (the manifest's `serves`); `as` is its login, and its copy of the password is
|
||||
// the pair credential the mesh delivers to it.
|
||||
// role scoped to exactly that subtree.
|
||||
//
|
||||
// **The login and password are the mesh's, not the provisioner's (ADR 0048).** The mesh derives the
|
||||
// login and hands it to both ends so they agree, and mints the password and delivers a copy to each.
|
||||
@@ -22,7 +15,6 @@
|
||||
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
|
||||
import { emit } from "@novox/mesh-sdk/events";
|
||||
import { MosquittoClient } from "../client.js";
|
||||
import { topicFilters } from "../topics.js";
|
||||
|
||||
const mosquitto = MosquittoClient.fromEnv();
|
||||
|
||||
@@ -37,20 +29,13 @@ async function announce(type: string, body: Record<string, string>): Promise<voi
|
||||
|
||||
runProvisioner("mqtt-topic", {
|
||||
async create(p: Provision): Promise<void> {
|
||||
// By default the consumer's own subtree, so one cannot read another's topics; what it
|
||||
// contributed as `topics` otherwise.
|
||||
const granted = topicFilters(p.values, p.as);
|
||||
if ("problem" in granted) {
|
||||
// Thrown, so the harness logs it and retries: the consumer stays as it was (or absent) until
|
||||
// its contribution is valid, rather than being given a grant it did not ask for.
|
||||
throw new Error(`${p.as}: ${granted.problem}`);
|
||||
}
|
||||
await mosquitto.createScopedClient(p.as, p.password, granted.filters);
|
||||
// The topic subtree is scoped to the consumer's own login, so one cannot read another's topics.
|
||||
const topicPrefix = p.as;
|
||||
await mosquitto.createScopedClient(p.as, p.password, topicPrefix);
|
||||
await announce("topic.provisioned", {
|
||||
consumer: p.consumer ?? "",
|
||||
username: p.as,
|
||||
topicPrefix: granted.own ? p.as : "",
|
||||
topics: granted.filters.join(" "),
|
||||
topicPrefix,
|
||||
});
|
||||
},
|
||||
|
||||
@@ -61,9 +46,6 @@ runProvisioner("mqtt-topic", {
|
||||
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
|
||||
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
|
||||
async holds(p: Provision): Promise<boolean> {
|
||||
const granted = topicFilters(p.values, p.as);
|
||||
// An invalid list was never applied; create refuses it again, loudly, on every pass.
|
||||
if ("problem" in granted) return false;
|
||||
return mosquitto.holdsClient(p.as, p.password, granted.filters);
|
||||
return mosquitto.holdsClient(p.as, p.password);
|
||||
},
|
||||
});
|
||||
|
||||
@@ -1,72 +0,0 @@
|
||||
// What a consumer of mqtt-topic is granted (topics.ts): its own subtree unless it contributed
|
||||
// `topics`; a contributed list is granted exactly, refused whole when it is not topic filters; and
|
||||
// the role is brought to exactly the wanted ACLs — missing ones added, stale ones removed — read from
|
||||
// `mosquitto_ctrl dynsec getRole` as eclipse-mosquitto 2.1.2 prints it.
|
||||
|
||||
import { test } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
|
||||
import { filterProblem, missingAcls, parseRoleAcls, staleAcls, topicFilters, wantedAcls } from "../topics.ts";
|
||||
|
||||
test("a consumer that contributed nothing gets its own subtree", () => {
|
||||
assert.deepEqual(topicFilters({}, "mesh_ace_hass"), { ok: true, filters: ["mesh_ace_hass/#"], own: true });
|
||||
assert.deepEqual(topicFilters(undefined, "x"), { ok: true, filters: ["x/#"], own: true });
|
||||
// Settings merge into every contribution: keys that are not `topics` change nothing.
|
||||
assert.deepEqual(topicFilters({ endpoints: { web: {} } }, "x"), { ok: true, filters: ["x/#"], own: true });
|
||||
});
|
||||
|
||||
test("a contributed list is granted exactly, duplicates once", () => {
|
||||
assert.deepEqual(topicFilters({ topics: ["#"] }, "x"), { ok: true, filters: ["#"], own: false });
|
||||
assert.deepEqual(topicFilters({ topics: ["stat/+/POWER", "tele/#", "tele/#", "/octoprint/x"] }, "x"), {
|
||||
ok: true,
|
||||
filters: ["stat/+/POWER", "tele/#", "/octoprint/x"],
|
||||
own: false,
|
||||
});
|
||||
});
|
||||
|
||||
test("a list that is not topic filters is refused whole", () => {
|
||||
for (const topics of [[], "#", [""], ["a/#/b"], ["a#"], ["a/b+"], [42], ["a\u0000b"], {}]) {
|
||||
const out = topicFilters({ topics } as Record<string, unknown>, "x");
|
||||
assert.equal(out.ok, false, JSON.stringify(topics));
|
||||
}
|
||||
assert.equal(filterProblem("+/+/#"), undefined);
|
||||
assert.equal(filterProblem("#"), undefined);
|
||||
});
|
||||
|
||||
const GET_ROLE = `Warning: You are running mosquitto_ctrl without encryption.
|
||||
This means all of the configuration changes you are making are visible on the network, including passwords.
|
||||
|
||||
Rolename: u1
|
||||
ACLs: publishClientSend : allow : # (priority: 0)
|
||||
subscribePattern : allow : u1/# (priority: 0)
|
||||
publishClientReceive : deny : secret topic/with space (priority: -1)
|
||||
`;
|
||||
|
||||
test("getRole's ACL lines are read, the warning and headings are not", () => {
|
||||
assert.deepEqual(parseRoleAcls(GET_ROLE), [
|
||||
{ type: "publishClientSend", allow: true, topic: "#" },
|
||||
{ type: "subscribePattern", allow: true, topic: "u1/#" },
|
||||
{ type: "publishClientReceive", allow: false, topic: "secret topic/with space" },
|
||||
]);
|
||||
assert.deepEqual(parseRoleAcls("Rolename: empty\nACLs:\n"), []);
|
||||
});
|
||||
|
||||
test("the role is brought to exactly the wanted ACLs", () => {
|
||||
const current = parseRoleAcls(GET_ROLE);
|
||||
const wanted = wantedAcls(["u1/#"]);
|
||||
assert.deepEqual(wanted, [
|
||||
{ type: "publishClientSend", allow: true, topic: "u1/#" },
|
||||
{ type: "publishClientReceive", allow: true, topic: "u1/#" },
|
||||
{ type: "subscribePattern", allow: true, topic: "u1/#" },
|
||||
]);
|
||||
assert.deepEqual(missingAcls(current, wanted), [
|
||||
{ type: "publishClientSend", allow: true, topic: "u1/#" },
|
||||
{ type: "publishClientReceive", allow: true, topic: "u1/#" },
|
||||
]);
|
||||
assert.deepEqual(staleAcls(current, wanted), [
|
||||
{ type: "publishClientSend", allow: true, topic: "#" },
|
||||
{ type: "publishClientReceive", allow: false, topic: "secret topic/with space" },
|
||||
]);
|
||||
assert.deepEqual(staleAcls(wanted, wanted), []);
|
||||
assert.deepEqual(missingAcls(wanted, wanted), []);
|
||||
});
|
||||
@@ -1,107 +0,0 @@
|
||||
// Which topics a consumer of `mqtt-topic` may use — the one choice a consumer makes about its grant.
|
||||
//
|
||||
// **By default, its own subtree and nothing else.** A consumer connects as the login the mesh derived
|
||||
// (`as`) and may publish, receive and subscribe under `<as>/#` — isolated from every other consumer,
|
||||
// which is the point of a per-consumer client (novox/hq ADR 0039/0048).
|
||||
//
|
||||
// **A consumer whose work IS the shared topic space says so.** Home Assistant discovers devices
|
||||
// under `homeassistant/#` and `tasmota/discovery/#` and follows whatever state topics they announce;
|
||||
// Node-RED's flows subscribe to the topics devices publish on (`stat/<device>/POWER`, …). Confined
|
||||
// to `<as>/#` neither could do its job. So a consumer contributes `topics` to its `mqtt-topic`
|
||||
// requirement — a list of MQTT topic filters — and the provisioner grants exactly those, both ways.
|
||||
// Because assignment settings merge into every contribution, an operator narrows (or widens) the
|
||||
// list per machine with the same key, without editing a manifest.
|
||||
//
|
||||
// Pure, so it is tested without a broker (test/topics.test.ts).
|
||||
|
||||
/** The dynsec ACL types a granted filter carries: send to it, receive from it, subscribe to it. */
|
||||
export const GRANTED_ACL_TYPES = ["publishClientSend", "publishClientReceive", "subscribePattern"] as const;
|
||||
|
||||
/** One ACL on a role, as `mosquitto_ctrl dynsec getRole` reports it. */
|
||||
export interface Acl {
|
||||
type: string;
|
||||
allow: boolean;
|
||||
topic: string;
|
||||
}
|
||||
|
||||
export type Filters = { ok: true; filters: string[]; own: boolean } | { ok: false; problem: string };
|
||||
|
||||
/**
|
||||
* The topic filters a consumer is granted: what it contributed as `topics`, or its own subtree when
|
||||
* it contributed nothing. Refused — never silently narrowed or widened — when the list is not a
|
||||
* list of valid MQTT topic filters: a grant that quietly differs from what was asked is a consumer
|
||||
* that fails somewhere far from the cause.
|
||||
*/
|
||||
export function topicFilters(values: Readonly<Record<string, unknown>> | undefined, as: string): Filters {
|
||||
const given = values?.topics;
|
||||
if (given === undefined || given === null) {
|
||||
return { ok: true, filters: [`${as}/#`], own: true };
|
||||
}
|
||||
if (!Array.isArray(given) || given.length === 0) {
|
||||
return { ok: false, problem: `topics must be a non-empty list of MQTT topic filters, not ${JSON.stringify(given)}` };
|
||||
}
|
||||
const out: string[] = [];
|
||||
for (const f of given) {
|
||||
if (typeof f !== "string") {
|
||||
return { ok: false, problem: `topics holds ${JSON.stringify(f)}, which is not a topic filter` };
|
||||
}
|
||||
const problem = filterProblem(f);
|
||||
if (problem) return { ok: false, problem: `topic filter ${JSON.stringify(f)}: ${problem}` };
|
||||
if (!out.includes(f)) out.push(f);
|
||||
}
|
||||
return { ok: true, filters: out, own: out.length === 1 && out[0] === `${as}/#` };
|
||||
}
|
||||
|
||||
/** Why a string is not a valid MQTT topic filter (MQTT 3.1.1 §4.7), or undefined when it is one. */
|
||||
export function filterProblem(filter: string): string | undefined {
|
||||
if (filter.length === 0) return "it is empty";
|
||||
if (Buffer.byteLength(filter, "utf8") > 65535) return "it is longer than MQTT allows";
|
||||
if (filter.includes("\u0000")) return "it contains a NUL character";
|
||||
const levels = filter.split("/");
|
||||
for (let i = 0; i < levels.length; i++) {
|
||||
const level = levels[i];
|
||||
if (level.includes("#") && (level !== "#" || i !== levels.length - 1)) {
|
||||
return "'#' must be a whole level, and the last one";
|
||||
}
|
||||
if (level.includes("+") && level !== "+") return "'+' must be a whole level";
|
||||
}
|
||||
return undefined;
|
||||
}
|
||||
|
||||
/** The ACLs a role must carry to grant these filters: every granted type, allowed, on every filter. */
|
||||
export function wantedAcls(filters: readonly string[]): Acl[] {
|
||||
const out: Acl[] = [];
|
||||
for (const topic of filters) {
|
||||
for (const type of GRANTED_ACL_TYPES) out.push({ type, allow: true, topic });
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/**
|
||||
* The ACLs `mosquitto_ctrl dynsec getRole` lists, one per line under its "ACLs:" heading:
|
||||
* `ACLs: publishClientSend : allow : # (priority: 0)`
|
||||
* ` subscribePattern : allow : u1/# (priority: 0)`
|
||||
*/
|
||||
export function parseRoleAcls(output: string): Acl[] {
|
||||
const out: Acl[] = [];
|
||||
const line = /^(?:ACLs:)?\s*([A-Za-z]+)\s*:\s*(allow|deny)\s*:\s*(.*?)\s+\(priority:\s*-?\d+\)\s*$/;
|
||||
for (const raw of output.split(/\r?\n/)) {
|
||||
const m = raw.match(line);
|
||||
if (m) out.push({ type: m[1], allow: m[2] === "allow", topic: m[3] });
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
const key = (a: Acl): string => `${a.type}\u0000${a.allow ? "allow" : "deny"}\u0000${a.topic}`;
|
||||
|
||||
/** ACLs a role carries that it should not: in `current` and not in `wanted`. */
|
||||
export function staleAcls(current: readonly Acl[], wanted: readonly Acl[]): Acl[] {
|
||||
const want = new Set(wanted.map(key));
|
||||
return current.filter((a) => !want.has(key(a)));
|
||||
}
|
||||
|
||||
/** ACLs a role should carry and does not. */
|
||||
export function missingAcls(current: readonly Acl[], wanted: readonly Acl[]): Acl[] {
|
||||
const have = new Set(current.map(key));
|
||||
return wanted.filter((a) => !have.has(key(a)));
|
||||
}
|
||||
@@ -8,5 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": ["topics.ts", "client.ts", "index.ts", "provisioner/index.ts", "tools/index.ts", "bootstrap/index.ts"]
|
||||
"include": ["client.ts", "index.ts", "provisioner/index.ts", "tools/index.ts", "bootstrap/index.ts"]
|
||||
}
|
||||
|
||||
+12
-11
@@ -21,23 +21,23 @@
|
||||
"listens": [
|
||||
{
|
||||
"name": "database",
|
||||
"port": 1433,
|
||||
"port": 4848,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "modules on any machine that were granted a database, and the people who were given its address; the machine port is the assignment's to pin"
|
||||
"why": "modules on any machine that were granted a database. 4848, not 1433: the machine this replaces has served it there since it was installed, and every consumer was handed that number"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"mssql-database": {}
|
||||
},
|
||||
"receives": {
|
||||
"mssql-database": "${dir:grants}/mesh.json"
|
||||
"mssql-database": "/var/lib/mssql/grants/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"mssql-database": "${dir:grants}"
|
||||
"mssql-database": "/var/lib/mssql/grants"
|
||||
},
|
||||
"own-secrets": {
|
||||
"sa": "${dir:state}/sa.secret",
|
||||
"sa": "/var/lib/mssql/sa.secret",
|
||||
"broker": "/var/lib/mesh/mssql/broker"
|
||||
},
|
||||
"resources": [
|
||||
@@ -50,18 +50,19 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/mssql",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mssql/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "sa-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/sa.env",
|
||||
"path": "/var/lib/mssql/sa.env",
|
||||
"mode": "0600",
|
||||
"content": "ACCEPT_EULA=Y\nMSSQL_SA_PASSWORD=${secret:sa}\n"
|
||||
},
|
||||
@@ -83,7 +84,7 @@
|
||||
"image": "mcr.microsoft.com/mssql/server@sha256:4402d880dd4c34bfa7d8705e56a86cd6c88da80a1f6bbbe741f999e76264a090",
|
||||
"network": "mssql",
|
||||
"env-file": [
|
||||
"${dir:state}/sa.env"
|
||||
"/var/lib/mssql/sa.env"
|
||||
],
|
||||
"ports": [
|
||||
"1433"
|
||||
@@ -100,8 +101,8 @@
|
||||
"network": "mssql",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/mssql/broker:/run/secrets/broker:ro",
|
||||
"${dir:grants}:/var/lib/mssql/grants:ro",
|
||||
"${dir:state}/sa.secret:/run/secrets/sa:ro"
|
||||
"/var/lib/mssql/grants:/var/lib/mssql/grants:ro",
|
||||
"/var/lib/mssql/sa.secret:/run/secrets/sa:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_PROVISION_MSSQL": "mssql://sa@mssql:1433/master",
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
# n8n with what its workflows reach for beyond the upstream image.
|
||||
#
|
||||
# The base is named, not pinned here (novox/hq issue 044): module.json's `build.on` declares N8N_BASE
|
||||
# as the upstream image by digest, and the mesh hands the build its own copy (ADR 0097).
|
||||
ARG N8N_BASE
|
||||
FROM ${N8N_BASE}
|
||||
|
||||
USER root
|
||||
# - `media` (GID 2000), with `node` in it: the shared media library is group-writable by the
|
||||
# operator's media group, and a workflow files downloads into it. A container resource cannot add
|
||||
# a supplementary group, so the image's own /etc/group carries it. 2000 is the operator's media
|
||||
# group today; novox/hq 153 proposes reading it from the accessed data (${access:<id>:gid}).
|
||||
# - uuid, pinned to the version the workflows were written against: Code nodes require() it
|
||||
# (NODE_FUNCTION_ALLOW_EXTERNAL=*), and a Code node can only require what is installed.
|
||||
RUN apk add --no-cache shadow \
|
||||
&& groupadd -g 2000 media \
|
||||
&& usermod -aG media node \
|
||||
&& npm install -g uuid@14.0.1
|
||||
|
||||
USER node
|
||||
+18
-77
@@ -18,60 +18,44 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"postgres-database": "${dir:state}/database.json",
|
||||
"route": "${dir:state}/route.json"
|
||||
"postgres-database": "/var/lib/n8n/database.json",
|
||||
"route": "/var/lib/n8n/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "${dir:state}/database.secret"
|
||||
"postgres-database": "/var/lib/n8n/database.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"basic-auth": "/var/lib/n8n/basic-auth.secret"
|
||||
},
|
||||
"accesses": [
|
||||
{
|
||||
"path": "/services/media",
|
||||
"mode": "read-write"
|
||||
}
|
||||
],
|
||||
"listens": [
|
||||
{
|
||||
"name": "web",
|
||||
"port": 5678,
|
||||
"port": 5682,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the n8n editor, its REST API and the webhook endpoints workflows are triggered through; a public name is the route's"
|
||||
"why": "the n8n editor and webhook endpoints over http; the public name n8n.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/n8n",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/n8n/n8n-data",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "cache",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "database-secret",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/n8n-database.secret",
|
||||
"mode": "0400",
|
||||
"owner": "1000:1000",
|
||||
"content": "${secret:postgres-database}"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"path": "/var/lib/n8n/server.env",
|
||||
"mode": "0600",
|
||||
"content": "N8N_HOST=${bound:route:name}\nN8N_PORT=5678\nN8N_PROTOCOL=https\nWEBHOOK_URL=https://${bound:route:name}/\nNODE_FUNCTION_ALLOW_BUILTIN=*\nNODE_FUNCTION_ALLOW_EXTERNAL=*\nDB_TYPE=postgresdb\nDB_POSTGRESDB_HOST=${bound:postgres-database:at}\nDB_POSTGRESDB_PORT=${bound:postgres-database:port}\nDB_POSTGRESDB_DATABASE=${bound:postgres-database:as}\nDB_POSTGRESDB_USER=${bound:postgres-database:as}\nDB_POSTGRESDB_PASSWORD_FILE=/run/secrets/database\n"
|
||||
"content": "N8N_HOST=n8n.novox.be\nN8N_PORT=5678\nN8N_PROTOCOL=https\nWEBHOOK_URL=https://n8n.novox.be/\nN8N_BASIC_AUTH_ACTIVE=true\nN8N_BASIC_AUTH_USER=admin\nN8N_BASIC_AUTH_PASSWORD=${secret:basic-auth}\nNODE_FUNCTION_ALLOW_BUILTIN=*\nNODE_FUNCTION_ALLOW_EXTERNAL=*\nDB_TYPE=postgresdb\nDB_POSTGRESDB_HOST=${bound:postgres-database:at}\nDB_POSTGRESDB_PORT=${bound:postgres-database:port}\nDB_POSTGRESDB_DATABASE=${bound:postgres-database:as}\nDB_POSTGRESDB_USER=${bound:postgres-database:as}\nDB_POSTGRESDB_PASSWORD=${secret:postgres-database}\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
@@ -82,61 +66,18 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "n8n",
|
||||
"artifact": "server",
|
||||
"image": "n8nio/n8n@sha256:4846eb2f4b874ab04cde7fc1e249d2ddaec66e9aea64439beb2972cfea88e3c0",
|
||||
"network": "n8n",
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
"/var/lib/n8n/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"5678"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/home/node/.n8n",
|
||||
"${dir:state}/n8n-database.secret:/run/secrets/database:ro",
|
||||
"/services/media:/media-library"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "cache-server",
|
||||
"type": "container",
|
||||
"name": "n8n-redis",
|
||||
"image": "redis@sha256:8a1efc5f479551822b47424ccae982026b633f28818eab0387348120a61e10e2",
|
||||
"network": "n8n",
|
||||
"args": [
|
||||
"redis-server",
|
||||
"--appendonly",
|
||||
"yes"
|
||||
"/services/n8n/n8n-data:/home/node/.n8n"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:cache}:/data"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "browser",
|
||||
"type": "container",
|
||||
"name": "n8n-selenium",
|
||||
"image": "selenium/standalone-chrome@sha256:9ae1c78e9b2ca9fe4b22e57873b5ee34aeb8e814e3122293eef4c3abe4c5f448",
|
||||
"network": "n8n",
|
||||
"env": {
|
||||
"SE_ENABLE_TRACING": "false",
|
||||
"SE_NODE_MAX_SESSIONS": "5",
|
||||
"SE_NODE_OVERRIDE_MAX_SESSIONS": "true"
|
||||
}
|
||||
"secrets-in-environment": "n8n's loader honours <VAR>_FILE for every setting; convertible, awaiting a bed that proves it (N8N_BASIC_AUTH_* was removed in n8n 1.0 and is likely dead)"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
"arg": "N8N_BASE",
|
||||
"image": "n8nio/n8n@sha256:4846eb2f4b874ab04cde7fc1e249d2ddaec66e9aea64439beb2972cfea88e3c0"
|
||||
}
|
||||
],
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "server",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/nodered
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts mqtt/probe.ts mqtt/connection.ts mqtt/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
@@ -22,6 +22,3 @@ COPY --from=build /app/modules/nodered/dist /app/modules/nodered/dist
|
||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||
# the convention novox/hq issues 060/061 settled.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/nodered/dist/tools/index.js
|
||||
# NOT dist/mqtt/index.js: that is a step the host runs to completion, named by the `mqtt`
|
||||
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
||||
# serving sidecar too, and exit it.
|
||||
|
||||
@@ -3,8 +3,7 @@
|
||||
//
|
||||
// Node-RED exposes a runtime admin API under its base URL: GET/POST /flows for the whole flow
|
||||
// configuration, GET /nodes for installed node modules. A default install has no auth; when
|
||||
// adminAuth is on, a bearer token is required — the module's settings accept the mesh-minted
|
||||
// api-token, which the runtime config file carries as `token`.
|
||||
// adminAuth is on, a bearer token (minted at /auth/token) is required.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
@@ -82,35 +81,6 @@ export class NodeRedClient {
|
||||
return modules.map((m) => ({ name: m.name, version: m.version, types: m.types ?? [] }));
|
||||
}
|
||||
|
||||
/** The whole flow configuration with its revision (API v2), for a deploy that must not clobber
|
||||
* a change made meanwhile. */
|
||||
async flowsWithRev(): Promise<{ rev: string; flows: any[] }> {
|
||||
const body = await this.req("/flows", { headers: this.headers({ "Node-RED-API-Version": "v2" }) });
|
||||
return { rev: String(body?.rev ?? ""), flows: Array.isArray(body?.flows) ? body.flows : [] };
|
||||
}
|
||||
|
||||
/** A node's stored credentials as Node-RED shows them: plain fields, and `has_<field>` for secret ones. */
|
||||
async credentials(type: string, id: string): Promise<{ user?: string; has_password?: boolean }> {
|
||||
return (await this.req(`/credentials/${encodeURIComponent(type)}/${encodeURIComponent(id)}`, { headers: this.headers() })) ?? {};
|
||||
}
|
||||
|
||||
/**
|
||||
* Deploy the flow configuration read at `rev`. Node-RED answers 409 when the flows changed since,
|
||||
* rather than overwriting what someone deployed in between. A node carrying `credentials` has them
|
||||
* stored (encrypted) and counts as changed, so a "nodes" deploy restarts it and nothing else.
|
||||
*/
|
||||
async deployFlowsAt(rev: string, config: any[], type = "nodes"): Promise<void> {
|
||||
await this.req("/flows", {
|
||||
method: "POST",
|
||||
headers: this.headers({
|
||||
"Content-Type": "application/json",
|
||||
"Node-RED-API-Version": "v2",
|
||||
"Node-RED-Deployment-Type": type,
|
||||
}),
|
||||
body: JSON.stringify({ rev, flows: config }),
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Replace the whole flow configuration and deploy. Returns the new revision. `type` maps to
|
||||
* Node-RED's deployment types — "full" (default), "nodes", or "flows".
|
||||
@@ -118,13 +88,8 @@ export class NodeRedClient {
|
||||
async deployFlows(config: any[], type = "full"): Promise<{ rev?: string; nodeCount: number }> {
|
||||
const body = await this.req("/flows", {
|
||||
method: "POST",
|
||||
// v2 answers { rev }; v1 answers 204 with no body, which req() cannot parse.
|
||||
headers: this.headers({
|
||||
"Content-Type": "application/json",
|
||||
"Node-RED-API-Version": "v2",
|
||||
"Node-RED-Deployment-Type": type,
|
||||
}),
|
||||
body: JSON.stringify({ flows: config }),
|
||||
headers: this.headers({ "Content-Type": "application/json", "Node-RED-Deployment-Type": type }),
|
||||
body: JSON.stringify(config),
|
||||
});
|
||||
return { rev: body?.rev, nodeCount: config.length };
|
||||
}
|
||||
|
||||
@@ -5,8 +5,6 @@
|
||||
"flows.deployed"
|
||||
],
|
||||
"own-secrets": {
|
||||
"admin": "/var/lib/mesh/nodered/admin",
|
||||
"api-token": "/var/lib/mesh/nodered/api-token",
|
||||
"broker": "/var/lib/mesh/nodered/broker"
|
||||
},
|
||||
"capabilities": [
|
||||
@@ -28,63 +26,26 @@
|
||||
"path": "/var/lib/mesh/nodered",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/nodered/data",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "written",
|
||||
"type": "directory",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "settings-code",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/settings.js",
|
||||
"mode": "0600",
|
||||
"owner": "1000:1000",
|
||||
"content": "// Node-RED's settings, written by the mesh from the nodered module. What an assignment may change\n// is settings.json beside this file (merged key by key); the credentials are the mesh's secrets and\n// reach Node-RED only through this file. The flows' own credentials stay encrypted in the user\n// directory under the key Node-RED keeps there (.config.runtime.json), which is data, not this.\nconst fs = require(\"fs\");\nconst path = require(\"path\");\nconst crypto = require(\"crypto\");\n\nconst ADMIN_PASSWORD = \"${secret:admin}\";\nconst API_TOKEN = \"${secret:api-token}\";\nconst ADMIN = { username: \"admin\", permissions: \"*\" };\n\nconst settings = JSON.parse(fs.readFileSync(path.join(__dirname, \"settings.json\"), \"utf8\"));\n// The mesh's keys, not Node-RED's: endpoints lands in every merged file; timeZone is the\n// assignment's way to set the zone flows schedule and format in; mqtt names the broker nodes the\n// module's MQTT step keeps pointed at the mesh's broker; topics is what nodered asks the broker for.\nif (settings.timeZone) process.env.TZ = settings.timeZone;\ndelete settings.timeZone;\ndelete settings.endpoints;\ndelete settings.mqtt;\ndelete settings.topics;\n\nfunction same(a, b) {\n const x = crypto.createHash(\"sha256\").update(String(a)).digest();\n const y = crypto.createHash(\"sha256\").update(String(b)).digest();\n return crypto.timingSafeEqual(x, y);\n}\n\n// The admin secret is a password, or, accepted from an existing install, the bcrypt hash its\n// settings held, so the password people already use keeps working.\nfunction passwordMatches(given) {\n if (/^\\$2[aby]\\$\\d\\d\\$/.test(ADMIN_PASSWORD)) return require(\"bcryptjs\").compare(String(given), ADMIN_PASSWORD);\n return Promise.resolve(same(given, ADMIN_PASSWORD));\n}\n\nmodule.exports = Object.assign(settings, {\n uiPort: 1880,\n adminAuth: {\n type: \"credentials\",\n users: (username) => Promise.resolve(username === ADMIN.username ? ADMIN : null),\n authenticate: (username, password) =>\n username === ADMIN.username\n ? passwordMatches(password).then((ok) => (ok ? ADMIN : null))\n : Promise.resolve(null),\n // The module's own tools call the admin API with this bearer token.\n tokens: (token) => Promise.resolve(same(token, API_TOKEN) ? { username: \"mesh\", permissions: \"*\" } : null),\n },\n});\n"
|
||||
},
|
||||
{
|
||||
"id": "settings",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/settings.json",
|
||||
"mode": "0600",
|
||||
"owner": "1000:1000",
|
||||
"merge": "json",
|
||||
"content": "{\n \"flowFile\": \"flows.json\",\n \"flowFilePretty\": true,\n \"diagnostics\": { \"enabled\": true, \"ui\": true },\n \"runtimeState\": { \"enabled\": false, \"ui\": false },\n \"logging\": { \"console\": { \"level\": \"info\", \"metrics\": false, \"audit\": false } },\n \"exportGlobalContextKeys\": false,\n \"externalModules\": {},\n \"editorTheme\": { \"projects\": { \"enabled\": false } },\n \"functionExternalModules\": true,\n \"debugMaxLength\": 1000,\n \"mqttReconnectTime\": 15000,\n \"serialReconnectTime\": 15000\n}\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "nodered",
|
||||
"image": "nodered/node-red@sha256:a649dd711d55490151a2c39a8e48ad0c44325488fbc0e66315f2d2e19e5e1ace",
|
||||
"image": "nodered/node-red@sha256:02a2b92a41b73d2bc388238b86e4fcaab7fb5466373adb24e1df6aa5845265ff",
|
||||
"env": {
|
||||
"TZ": "Etc/UTC"
|
||||
},
|
||||
"ports": [
|
||||
"1880"
|
||||
],
|
||||
"args": [
|
||||
"--settings",
|
||||
"/data/settings.js"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/data",
|
||||
"${dir:state}/settings.js:/data/settings.js:ro",
|
||||
"${dir:state}/settings.json:/data/settings.json:ro"
|
||||
],
|
||||
"restart-on": [
|
||||
"settings-code",
|
||||
"settings"
|
||||
"/services/nodered/data:/data"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -92,7 +53,8 @@
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/nodered/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"token\": \"${secret:api-token}\"\n}\n"
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
@@ -105,66 +67,26 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_NODERED_URL": "http://127.0.0.1:${port:1880}",
|
||||
"MESH_NODERED_URL": "http://127.0.0.1:1880",
|
||||
"MESH_NODERED_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
},
|
||||
{
|
||||
"id": "mqtt",
|
||||
"type": "container",
|
||||
"name": "mesh-nodered-mqtt",
|
||||
"network": "host",
|
||||
"run-once": true,
|
||||
"volumes": [
|
||||
"/var/lib/mesh/nodered/config.json:/run/config/config.json:ro",
|
||||
"${dir:written}:/var/lib/nodered-provisions",
|
||||
"${dir:state}/mqtt-topic.json:/run/provisions/mqtt-topic.json:ro",
|
||||
"${dir:state}/mqtt-topic.secret:/run/provisions/mqtt-topic.secret:ro",
|
||||
"${dir:state}/settings.json:/run/provisions/settings.json:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_NODERED_URL": "http://127.0.0.1:${port:1880}",
|
||||
"MESH_NODERED_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_PROVISIONS_DIR": "/run/provisions",
|
||||
"MESH_WRITTEN_DIR": "/var/lib/nodered-provisions"
|
||||
},
|
||||
"args": [
|
||||
"run",
|
||||
"/app/modules/nodered/dist/mqtt/index.js"
|
||||
],
|
||||
"restart-on": [
|
||||
"bound-mqtt-topic",
|
||||
"secret-mqtt-topic",
|
||||
"settings"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"mqtt-topic",
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"mqtt-topic": {
|
||||
"topics": [
|
||||
"#"
|
||||
]
|
||||
},
|
||||
"route": {
|
||||
"label": "nodered",
|
||||
"endpoint": "web"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json",
|
||||
"mqtt-topic": "${dir:state}/mqtt-topic.json"
|
||||
},
|
||||
"secrets": {
|
||||
"mqtt-topic": "${dir:state}/mqtt-topic.secret"
|
||||
"route": "/var/lib/mesh/nodered/route.json"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
@@ -1,232 +0,0 @@
|
||||
// Node-RED's MQTT broker config node, pointed at the broker the mesh bound — `mqtt-topic`.
|
||||
//
|
||||
// **Why a step.** Node-RED keeps a broker as a config node in its flows (`flows.json`) and the login
|
||||
// and password in its encrypted credentials file, both of them Node-RED's to write. So this reads the
|
||||
// binding and the pair credential and makes the broker node say the same thing through Node-RED's
|
||||
// admin API — `GET /flows`, then `POST /flows` with the changed node and its `credentials`, deployed
|
||||
// as "nodes" so only what changed restarts — with the module's own `api-token`.
|
||||
//
|
||||
// **Which broker nodes are the mesh's.** Never guessed: a flow may talk to a broker that has nothing
|
||||
// to do with this mesh. The step owns the node it creates itself (id `mesh-mqtt-topic`, "mesh:
|
||||
// mqtt-topic") and the ones an assignment names in settings (`mqtt.brokers`: node ids — how ace's
|
||||
// existing broker node, which every one of its MQTT flows uses, is handed over). With none named and
|
||||
// none made yet, it makes one, so a fresh Node-RED has a broker the flows can pick.
|
||||
//
|
||||
// **Only the connection, and only when it differs.** Host, port, TLS off (the broker serves plain
|
||||
// MQTT), login, password. Every other field of the node — client id, keepalive, birth/close/will
|
||||
// messages — is left as it is. Node-RED never hands a stored password back, so the step keeps a
|
||||
// digest of what it last wrote: equal host/port/login and an equal digest is "already as the mesh
|
||||
// says".
|
||||
//
|
||||
// **Nothing loses its connection without someone seeing it.** The broker is asked first whether it
|
||||
// takes the delivered login; if not, nothing is written and the step fails saying why.
|
||||
//
|
||||
// Pure logic over two seams (Node-RED, the broker), tested against fakes (test/mqtt.test.ts).
|
||||
|
||||
import { createHash } from "node:crypto";
|
||||
|
||||
import type { Probe } from "./probe.js";
|
||||
|
||||
export const PROVISION = "mqtt-topic";
|
||||
/** The id and name of the broker node the step makes when none is named. */
|
||||
export const MESH_BROKER_ID = "mesh-mqtt-topic";
|
||||
export const MESH_BROKER_NAME = "mesh: mqtt-topic";
|
||||
|
||||
/** What the mesh wrote at `binds.mqtt-topic`. */
|
||||
export interface Binding {
|
||||
provision?: string;
|
||||
from?: string;
|
||||
at?: string;
|
||||
as?: string;
|
||||
serves?: Record<string, unknown>;
|
||||
}
|
||||
|
||||
export type Outcome =
|
||||
| { what: string; result: "unchanged"; note?: string }
|
||||
| { what: string; result: "written"; fields: string[]; note?: string }
|
||||
| { what: string; result: "refused"; problem: string };
|
||||
|
||||
/** A flow node; a broker config node carries `broker`, `port`, `usetls`. */
|
||||
export interface FlowNode {
|
||||
id: string;
|
||||
type: string;
|
||||
[key: string]: unknown;
|
||||
}
|
||||
|
||||
/** Node-RED's admin API, as the step uses it. */
|
||||
export interface NodeRed {
|
||||
/** The whole flow configuration and its revision (API v2). */
|
||||
flows(): Promise<{ rev: string; flows: FlowNode[] }>;
|
||||
/** A node's stored credentials as Node-RED shows them: the user, and only whether a password is set. */
|
||||
credentials(type: string, id: string): Promise<{ user?: string; has_password?: boolean }>;
|
||||
/** Deploy the configuration against the revision it was read at; "nodes" restarts only what changed. */
|
||||
deploy(rev: string, flows: FlowNode[]): Promise<void>;
|
||||
}
|
||||
|
||||
export interface Marks {
|
||||
get(name: string): Promise<string | undefined>;
|
||||
set(name: string, digest: string): Promise<void>;
|
||||
}
|
||||
|
||||
export interface Deps {
|
||||
nodered: NodeRed;
|
||||
probe: Probe;
|
||||
marks: Marks;
|
||||
}
|
||||
|
||||
export interface Wanted {
|
||||
host: string;
|
||||
port: number;
|
||||
user: string;
|
||||
password: string;
|
||||
}
|
||||
|
||||
export function digest(...parts: (string | number)[]): string {
|
||||
return createHash("sha256").update(parts.map(String).join("\u0000")).digest("hex");
|
||||
}
|
||||
|
||||
function isLoopback(host: string): boolean {
|
||||
const h = host.toLowerCase();
|
||||
return h === "localhost" || h === "::1" || h === "[::1]" || /^127\./.test(h);
|
||||
}
|
||||
|
||||
/**
|
||||
* The broker and login the mesh says Node-RED uses. A loopback `at` — what the mesh hands a machine
|
||||
* that is not on the private network — is refused: from Node-RED's own container it is Node-RED.
|
||||
*/
|
||||
export function wanted(binding: Binding | undefined, credential: string | undefined): { ok: true; want: Wanted } | { ok: false; problem: string } {
|
||||
if (!binding) return { ok: false, problem: `no binding for ${PROVISION} was delivered — the mesh writes it before this step runs` };
|
||||
const host = typeof binding.at === "string" ? binding.at.trim() : "";
|
||||
if (!host) return { ok: false, problem: `the ${PROVISION} binding names no host (at)` };
|
||||
if (isLoopback(host)) {
|
||||
return {
|
||||
ok: false,
|
||||
problem:
|
||||
`the ${PROVISION} binding says the broker is at ${host}, which from Node-RED's own container is Node-RED ` +
|
||||
`itself; put the machine on the private network so the broker has an address Node-RED can dial`,
|
||||
};
|
||||
}
|
||||
const port = Number(binding.serves?.port);
|
||||
if (!Number.isInteger(port) || port <= 0 || port > 65535) {
|
||||
return { ok: false, problem: `the ${PROVISION} binding serves no usable port (${String(binding.serves?.port)})` };
|
||||
}
|
||||
const scheme = binding.serves?.scheme;
|
||||
if (scheme !== undefined && scheme !== "mqtt") return { ok: false, problem: `the ${PROVISION} binding serves scheme ${String(scheme)}; this step writes plain MQTT` };
|
||||
const user = typeof binding.as === "string" ? binding.as.trim() : "";
|
||||
if (!user) return { ok: false, problem: `the ${PROVISION} binding names no login (as)` };
|
||||
const password = (credential ?? "").replace(/\n$/, "");
|
||||
if (!password) return { ok: false, problem: `the ${PROVISION} credential is empty or was not delivered` };
|
||||
return { ok: true, want: { host, port, user, password } };
|
||||
}
|
||||
|
||||
/** The broker node ids an assignment named in settings (`mqtt.brokers`), or none. */
|
||||
export function namedBrokers(settings: unknown): string[] {
|
||||
const brokers = (settings as { mqtt?: { brokers?: unknown } } | undefined)?.mqtt?.brokers;
|
||||
return Array.isArray(brokers) ? brokers.filter((b): b is string => typeof b === "string" && b.length > 0) : [];
|
||||
}
|
||||
|
||||
/** A new broker node, Node-RED 5's defaults, pointed at the broker. */
|
||||
export function newBrokerNode(want: Wanted): FlowNode {
|
||||
return {
|
||||
id: MESH_BROKER_ID, type: "mqtt-broker", name: MESH_BROKER_NAME,
|
||||
broker: want.host, port: String(want.port), clientid: "", autoConnect: true, usetls: false,
|
||||
protocolVersion: "4", keepalive: "60", cleansession: true, autoUnsubscribe: true,
|
||||
birthTopic: "", birthQos: "0", birthRetain: "false", birthPayload: "", birthMsg: {},
|
||||
closeTopic: "", closeQos: "0", closeRetain: "false", closePayload: "", closeMsg: {},
|
||||
willTopic: "", willQos: "0", willRetain: "false", willPayload: "", willMsg: {},
|
||||
userProps: "", sessionExpiry: "",
|
||||
};
|
||||
}
|
||||
|
||||
const markFor = (id: string, w: Wanted): string => digest("nodered-mqtt", id, w.host, w.port, w.user, w.password);
|
||||
|
||||
function scrub(err: unknown, secret: string): string {
|
||||
let text = err instanceof Error ? err.message : String(err);
|
||||
for (const form of new Set([secret, encodeURIComponent(secret)])) text = text.split(form).join("***");
|
||||
return text;
|
||||
}
|
||||
|
||||
/**
|
||||
* Bring the mesh's broker nodes in line with the binding: one outcome per node. Never throws. A node
|
||||
* the settings name that is not in the flows is refused (the others are still put right).
|
||||
*/
|
||||
export async function reconcileBrokers(deps: Deps, binding: Binding | undefined, credential: string | undefined, named: readonly string[]): Promise<Outcome[]> {
|
||||
const w = wanted(binding, credential);
|
||||
if ("problem" in w) return [{ what: "mqtt", result: "refused", problem: w.problem }];
|
||||
const want = w.want;
|
||||
|
||||
let note: string | undefined;
|
||||
try {
|
||||
const probe = await deps.probe(want.host, want.port, want.user, want.password, "#");
|
||||
if (probe.connack === 4 || probe.connack === 5) {
|
||||
return [{
|
||||
what: "mqtt",
|
||||
result: "refused",
|
||||
problem:
|
||||
`the broker at ${want.host}:${want.port} does not (yet) take the login ${want.user} with the delivered password ` +
|
||||
`(CONNACK ${probe.connack}); mosquitto's provisioner creates it from the grant — nothing was written`,
|
||||
}];
|
||||
}
|
||||
if (probe.connack !== 0) return [{ what: "mqtt", result: "refused", problem: `the broker at ${want.host}:${want.port} answered CONNACK ${probe.connack}; nothing was written` }];
|
||||
if (probe.suback === 0x80) note = `warning: ${want.user} may not subscribe to every topic; flows subscribing outside its grant will get nothing`;
|
||||
} catch (err) {
|
||||
return [{ what: "mqtt", result: "refused", problem: `the broker at ${want.host}:${want.port} could not be asked: ${scrub(err, want.password)}; nothing was written` }];
|
||||
}
|
||||
|
||||
const outcomes: Outcome[] = [];
|
||||
for (let attempt = 0; attempt < 2; attempt++) {
|
||||
outcomes.length = 0;
|
||||
try {
|
||||
const { rev, flows } = await deps.nodered.flows();
|
||||
const targets = named.length > 0 ? [...named] : [MESH_BROKER_ID];
|
||||
const changed: { id: string; fields: string[] }[] = [];
|
||||
for (const id of targets) {
|
||||
let node = flows.find((n) => n.id === id);
|
||||
if (node && node.type !== "mqtt-broker") {
|
||||
outcomes.push({ what: `broker ${id}`, result: "refused", problem: `node ${id} is a ${node.type}, not an mqtt-broker` });
|
||||
continue;
|
||||
}
|
||||
if (!node) {
|
||||
if (id !== MESH_BROKER_ID) {
|
||||
outcomes.push({ what: `broker ${id}`, result: "refused", problem: `the settings name broker node ${id}, and Node-RED's flows have no such node` });
|
||||
continue;
|
||||
}
|
||||
node = newBrokerNode(want);
|
||||
flows.push(node);
|
||||
node.credentials = { user: want.user, password: want.password };
|
||||
changed.push({ id, fields: ["node"] });
|
||||
continue;
|
||||
}
|
||||
const fields: string[] = [];
|
||||
if (String(node.broker ?? "") !== want.host) fields.push("broker");
|
||||
if (Number(node.port ?? 0) !== want.port) fields.push("port");
|
||||
if (node.usetls === true) fields.push("usetls");
|
||||
const creds = await deps.nodered.credentials("mqtt-broker", id);
|
||||
if ((creds.user ?? "") !== want.user) fields.push("user");
|
||||
if (!creds.has_password || (await deps.marks.get(`broker-${id}`)) !== markFor(id, want)) fields.push("password");
|
||||
if (fields.length === 0) {
|
||||
outcomes.push(note ? { what: `broker ${id}`, result: "unchanged", note } : { what: `broker ${id}`, result: "unchanged" });
|
||||
continue;
|
||||
}
|
||||
node.broker = want.host;
|
||||
node.port = String(want.port);
|
||||
node.usetls = false;
|
||||
node.credentials = { user: want.user, password: want.password };
|
||||
changed.push({ id, fields });
|
||||
}
|
||||
if (changed.length > 0) {
|
||||
await deps.nodered.deploy(rev, flows);
|
||||
for (const c of changed) {
|
||||
await deps.marks.set(`broker-${c.id}`, markFor(c.id, want));
|
||||
outcomes.push({ what: `broker ${c.id}`, result: "written", fields: c.fields, ...(note ? { note } : {}) });
|
||||
}
|
||||
}
|
||||
return outcomes;
|
||||
} catch (err) {
|
||||
// A deploy against a revision someone else changed meanwhile (409) is read again once.
|
||||
if (attempt === 0 && /\b409\b/.test(String(err))) continue;
|
||||
return [...outcomes, { what: "mqtt", result: "refused", problem: scrub(err, want.password) }];
|
||||
}
|
||||
}
|
||||
return outcomes;
|
||||
}
|
||||
@@ -1,102 +0,0 @@
|
||||
// nodered's MQTT step — run once by the host after Node-RED starts, and again whenever the
|
||||
// `mqtt-topic` binding, its pair credential or the settings change (the container's `restart-on`,
|
||||
// novox/hq ADR 0099). It points the mesh's broker config nodes at the broker the mesh bound, through
|
||||
// Node-RED's admin API (connection.ts). It connects to no mesh broker.
|
||||
//
|
||||
// Exits non-zero when anything could not be put right, so the node reports the step failed and the
|
||||
// host runs it again on the next apply. Declared last in the manifest, so its failing gates nothing
|
||||
// else of nodered's (novox/hq ADR 0136). Never prints a password.
|
||||
|
||||
import { mkdir, readFile, rename, writeFile } from "node:fs/promises";
|
||||
import { join } from "node:path";
|
||||
|
||||
import { NodeRedClient } from "../client.js";
|
||||
import { namedBrokers, reconcileBrokers, type Binding, type Marks } from "./connection.js";
|
||||
import { probeBroker } from "./probe.js";
|
||||
|
||||
const dir = process.env.MESH_PROVISIONS_DIR ?? "/run/provisions";
|
||||
const writtenDir = process.env.MESH_WRITTEN_DIR ?? "/var/lib/nodered-provisions";
|
||||
const waitSeconds = Number(process.env.MESH_NODERED_WAIT_SECONDS ?? "180");
|
||||
|
||||
const readIfThere = (path: string): Promise<string | undefined> => readFile(path, "utf8").catch(() => undefined);
|
||||
const parse = <T>(raw: string | undefined): T | undefined => {
|
||||
if (raw === undefined) return undefined;
|
||||
try {
|
||||
return JSON.parse(raw) as T;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
};
|
||||
|
||||
const marks: Marks = {
|
||||
async get(name) {
|
||||
return (await readIfThere(join(writtenDir, `${name}.digest`)))?.trim() || undefined;
|
||||
},
|
||||
async set(name, value) {
|
||||
await mkdir(writtenDir, { recursive: true, mode: 0o700 });
|
||||
const path = join(writtenDir, `${name}.digest`);
|
||||
await writeFile(`${path}.tmp`, `${value}\n`, { mode: 0o600 });
|
||||
await rename(`${path}.tmp`, path);
|
||||
},
|
||||
};
|
||||
|
||||
let client: NodeRedClient;
|
||||
try {
|
||||
client = NodeRedClient.fromEnv();
|
||||
} catch (err) {
|
||||
console.error(`[nodered-mqtt] ${err instanceof Error ? err.message : String(err)}`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
/** Node-RED answers the admin API once its flows are loaded and the token is good. */
|
||||
async function ready(): Promise<boolean> {
|
||||
const until = Date.now() + waitSeconds * 1000;
|
||||
for (;;) {
|
||||
try {
|
||||
await client.flowsWithRev();
|
||||
return true;
|
||||
} catch (err) {
|
||||
if (/\b(401|403)\b/.test(String(err))) {
|
||||
console.error("[nodered-mqtt] Node-RED refuses the api-token — settings.js and this step disagree");
|
||||
return false;
|
||||
}
|
||||
}
|
||||
if (Date.now() >= until) return false;
|
||||
await new Promise((r) => setTimeout(r, 2000));
|
||||
}
|
||||
}
|
||||
|
||||
if (!(await ready())) {
|
||||
console.error(`[nodered-mqtt] Node-RED's admin API did not answer at ${client.baseUrl} within ${waitSeconds}s`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
const binding = parse<Binding>(await readIfThere(join(dir, "mqtt-topic.json")));
|
||||
const secret = await readIfThere(join(dir, "mqtt-topic.secret"));
|
||||
const settings = parse<unknown>(await readIfThere(join(dir, "settings.json")));
|
||||
|
||||
const outcomes = await reconcileBrokers(
|
||||
{
|
||||
nodered: {
|
||||
flows: () => client.flowsWithRev(),
|
||||
credentials: (type, id) => client.credentials(type, id),
|
||||
deploy: (rev, flows) => client.deployFlowsAt(rev, flows, "nodes"),
|
||||
},
|
||||
probe: probeBroker,
|
||||
marks,
|
||||
},
|
||||
binding,
|
||||
secret,
|
||||
namedBrokers(settings),
|
||||
);
|
||||
|
||||
let failed = 0;
|
||||
for (const o of outcomes) {
|
||||
if (o.result === "unchanged") console.log(`[nodered-mqtt] ${o.what}: already as the mesh says${o.note ? ` — ${o.note}` : ""}`);
|
||||
else if (o.result === "written") console.log(`[nodered-mqtt] ${o.what}: wrote ${o.fields.join(", ")}${o.note ? ` — ${o.note}` : ""}`);
|
||||
else {
|
||||
failed++;
|
||||
console.error(`[nodered-mqtt] ${o.what}: ${o.problem}`);
|
||||
}
|
||||
}
|
||||
process.exitCode = failed > 0 ? 1 : 0;
|
||||
@@ -1,117 +0,0 @@
|
||||
// Ask the broker, before Node-RED is told anything, whether it takes the login and password the
|
||||
// mesh delivered — and whether that login may subscribe to every topic, as flows expect.
|
||||
//
|
||||
// One MQTT 3.1.1 session: CONNECT (clean, a throwaway client id, so no flow's session is taken
|
||||
// over), read the CONNACK, optionally SUBSCRIBE once and read the SUBACK, DISCONNECT. No dependency:
|
||||
// the handful of bytes MQTT needs for this are written here.
|
||||
|
||||
import { randomBytes } from "node:crypto";
|
||||
import { connect } from "node:net";
|
||||
|
||||
export interface ProbeResult {
|
||||
/** 0 accepted; 4 bad username or password; 5 not authorised. */
|
||||
connack: number;
|
||||
/** The SUBACK return code for the filter asked about: 0–2 granted, 0x80 refused. */
|
||||
suback?: number;
|
||||
}
|
||||
|
||||
export type Probe = (host: string, port: number, username: string, password: string, subscribe?: string) => Promise<ProbeResult>;
|
||||
|
||||
function str(v: string): Buffer {
|
||||
const b = Buffer.from(v, "utf8");
|
||||
const len = Buffer.alloc(2);
|
||||
len.writeUInt16BE(b.length);
|
||||
return Buffer.concat([len, b]);
|
||||
}
|
||||
|
||||
function packet(type: number, body: Buffer): Buffer {
|
||||
let remaining = body.length;
|
||||
const lenBytes: number[] = [];
|
||||
do {
|
||||
let byte = remaining % 128;
|
||||
remaining = Math.floor(remaining / 128);
|
||||
if (remaining > 0) byte |= 0x80;
|
||||
lenBytes.push(byte);
|
||||
} while (remaining > 0);
|
||||
return Buffer.concat([Buffer.from([type, ...lenBytes]), body]);
|
||||
}
|
||||
|
||||
/** The first complete packet in `buf`: its type byte, its body, and how many bytes it took. */
|
||||
export function firstPacket(buf: Buffer): { type: number; body: Buffer; used: number } | undefined {
|
||||
if (buf.length < 2) return undefined;
|
||||
let length = 0;
|
||||
let multiplier = 1;
|
||||
let i = 1;
|
||||
for (;;) {
|
||||
if (i >= buf.length) return undefined;
|
||||
const byte = buf[i++];
|
||||
length += (byte & 0x7f) * multiplier;
|
||||
if ((byte & 0x80) === 0) break;
|
||||
multiplier *= 128;
|
||||
if (i > 4) throw new Error("malformed MQTT remaining length");
|
||||
}
|
||||
if (buf.length < i + length) return undefined;
|
||||
return { type: buf[0], body: buf.subarray(i, i + length), used: i + length };
|
||||
}
|
||||
|
||||
export const probeBroker: Probe = (host, port, username, password, subscribe) => {
|
||||
const connectBody = Buffer.concat([
|
||||
str("MQTT"),
|
||||
Buffer.from([4, 0xc2, 0, 10]), // level 4 (3.1.1); username + password + clean session; keepalive 10s
|
||||
str(`mesh-probe-${randomBytes(6).toString("hex")}`),
|
||||
str(username),
|
||||
str(password),
|
||||
]);
|
||||
return new Promise((resolve, reject) => {
|
||||
const socket = connect({ host, port });
|
||||
let buf = Buffer.alloc(0);
|
||||
const result: ProbeResult = { connack: -1 };
|
||||
const timer = setTimeout(() => {
|
||||
socket.destroy();
|
||||
reject(new Error(`no answer from the broker at ${host}:${port} within 10s`));
|
||||
}, 10_000);
|
||||
const finish = (): void => {
|
||||
clearTimeout(timer);
|
||||
if (result.connack === 0) socket.end(Buffer.from([0xe0, 0]));
|
||||
else socket.destroy();
|
||||
resolve(result);
|
||||
};
|
||||
socket.on("connect", () => socket.write(packet(0x10, connectBody)));
|
||||
socket.on("data", (chunk) => {
|
||||
buf = Buffer.concat([buf, chunk]);
|
||||
for (;;) {
|
||||
let p;
|
||||
try {
|
||||
p = firstPacket(buf);
|
||||
} catch (err) {
|
||||
clearTimeout(timer);
|
||||
socket.destroy();
|
||||
reject(err);
|
||||
return;
|
||||
}
|
||||
if (!p) return;
|
||||
buf = buf.subarray(p.used);
|
||||
const kind = p.type >> 4;
|
||||
if (kind === 2) {
|
||||
result.connack = p.body[1] ?? -1;
|
||||
if (result.connack !== 0 || !subscribe) return finish();
|
||||
// SUBSCRIBE, packet id 1, one filter at QoS 0.
|
||||
socket.write(packet(0x82, Buffer.concat([Buffer.from([0, 1]), str(subscribe), Buffer.from([0])])));
|
||||
} else if (kind === 9) {
|
||||
result.suback = p.body[2];
|
||||
return finish();
|
||||
}
|
||||
}
|
||||
});
|
||||
socket.on("error", (err) => {
|
||||
clearTimeout(timer);
|
||||
reject(err);
|
||||
});
|
||||
socket.on("close", () => {
|
||||
if (result.connack === -1) {
|
||||
clearTimeout(timer);
|
||||
reject(new Error(`the broker at ${host}:${port} closed the connection without answering`));
|
||||
}
|
||||
});
|
||||
});
|
||||
};
|
||||
@@ -1,14 +1,9 @@
|
||||
{
|
||||
"name": "@novox/module-nodered",
|
||||
"version": "0.1.0",
|
||||
"description": "nodered \u2014 flow-based automation. Its client and tools live here (novox/hq ADR 0039).",
|
||||
"description": "nodered — flow-based automation. Its client and tools live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts tools/index.ts mqtt/probe.ts mqtt/connection.ts mqtt/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"typecheck": "tsc -p tsconfig.json",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
},
|
||||
|
||||
@@ -1,124 +0,0 @@
|
||||
// What holds nodered's MQTT step (mqtt/connection.ts): the broker nodes the mesh owns — the one it
|
||||
// makes, or the ones settings name — are made to use the broker and login the mesh bound, only after
|
||||
// the broker takes that login; every other field of a node is kept; nothing is deployed when nothing
|
||||
// differs; a node that is not named is never touched; a loopback broker address is refused.
|
||||
//
|
||||
// Node-RED and the broker are fakes answering as the real ones do (admin API v2 of nodered/node-red
|
||||
// 5.0.7, the build ace runs).
|
||||
|
||||
import { test } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
|
||||
import { MESH_BROKER_ID, namedBrokers, reconcileBrokers, type Binding, type FlowNode, type Marks, type NodeRed } from "../mqtt/connection.ts";
|
||||
import type { Probe } from "../mqtt/probe.ts";
|
||||
|
||||
const MINTED = "mesh-minted-password";
|
||||
const binding = (at = "ace.internal"): Binding => ({ provision: "mqtt-topic", from: "ace", at, as: "mesh_ace_nodered", serves: { scheme: "mqtt", port: 1883 } });
|
||||
|
||||
/** ace's flows, reduced: its one broker node (dead, zurag.be:1884) and a node that uses it. */
|
||||
function aceFlows(): FlowNode[] {
|
||||
return [
|
||||
{ id: "2b0aece9c5f3b307", type: "mqtt-broker", name: "MQTT Broker", broker: "zurag.be", port: "1884", clientid: "", usetls: false, protocolVersion: "4", keepalive: "60" },
|
||||
{ id: "fe0cae96f1e3ae4d", type: "mqtt in", topic: "stat/sonoff_office_light_switch/RESULT", broker: "2b0aece9c5f3b307", z: "t" },
|
||||
{ id: "other-broker", type: "mqtt-broker", name: "someone else's", broker: "test.mosquitto.org", port: "1883" },
|
||||
];
|
||||
}
|
||||
|
||||
function fakeNodeRed(flows: FlowNode[], creds: Record<string, { user?: string; password?: string }> = {}) {
|
||||
let rev = "r1";
|
||||
const deploys: FlowNode[][] = [];
|
||||
const nodered: NodeRed = {
|
||||
async flows() {
|
||||
return { rev, flows: structuredClone(flows) };
|
||||
},
|
||||
async credentials(_type, id) {
|
||||
const c = creds[id] ?? {};
|
||||
return { user: c.user, has_password: Boolean(c.password) };
|
||||
},
|
||||
async deploy(at, next) {
|
||||
if (at !== rev) throw new Error("Node-RED /flows: 409 version_mismatch");
|
||||
for (const n of next) {
|
||||
if (n.credentials) creds[n.id] = { ...(creds[n.id] ?? {}), ...(n.credentials as object) };
|
||||
}
|
||||
flows.splice(0, flows.length, ...next.map(({ credentials: _c, ...n }) => n as FlowNode));
|
||||
deploys.push(next);
|
||||
rev = `r${deploys.length + 1}`;
|
||||
},
|
||||
};
|
||||
return { nodered, deploys, flows, creds };
|
||||
}
|
||||
|
||||
const marks = (): Marks & { store: Map<string, string> } => {
|
||||
const store = new Map<string, string>();
|
||||
return { store, get: async (k) => store.get(k), set: async (k, v) => void store.set(k, v) };
|
||||
};
|
||||
const takes: Probe = async (_h, _p, user, pass) => ({ connack: user === "mesh_ace_nodered" && pass === MINTED ? 0 : 5, suback: 0 });
|
||||
|
||||
test("ace: the named broker node is moved to the bound broker and login; the other broker is not touched", async () => {
|
||||
const f = fakeNodeRed(aceFlows(), { "2b0aece9c5f3b307": { user: "luffy", password: "old" }, "other-broker": { user: "x", password: "y" } });
|
||||
const m = marks();
|
||||
const out = await reconcileBrokers({ nodered: f.nodered, probe: takes, marks: m }, binding(), `${MINTED}\n`, ["2b0aece9c5f3b307"]);
|
||||
assert.deepEqual(out, [{ what: "broker 2b0aece9c5f3b307", result: "written", fields: ["broker", "port", "user", "password"] }]);
|
||||
const node = f.flows.find((n) => n.id === "2b0aece9c5f3b307");
|
||||
assert.deepEqual(node, { ...aceFlows()[0], broker: "ace.internal", port: "1883", usetls: false });
|
||||
assert.deepEqual(f.creds["2b0aece9c5f3b307"], { user: "mesh_ace_nodered", password: MINTED });
|
||||
assert.deepEqual(f.flows.find((n) => n.id === "other-broker"), aceFlows()[2]);
|
||||
assert.deepEqual(f.creds["other-broker"], { user: "x", password: "y" });
|
||||
// Only the changed node carried credentials in the deploy.
|
||||
assert.deepEqual(f.deploys[0].filter((n) => n.credentials).map((n) => n.id), ["2b0aece9c5f3b307"]);
|
||||
|
||||
// Again: nothing differs, nothing is deployed.
|
||||
const again = await reconcileBrokers({ nodered: f.nodered, probe: takes, marks: m }, binding(), MINTED, ["2b0aece9c5f3b307"]);
|
||||
assert.deepEqual(again, [{ what: "broker 2b0aece9c5f3b307", result: "unchanged" }]);
|
||||
assert.equal(f.deploys.length, 1);
|
||||
});
|
||||
|
||||
test("fresh: with nothing named, the step makes its own broker node", async () => {
|
||||
const f = fakeNodeRed([]);
|
||||
const out = await reconcileBrokers({ nodered: f.nodered, probe: takes, marks: marks() }, binding(), MINTED, []);
|
||||
assert.deepEqual(out, [{ what: `broker ${MESH_BROKER_ID}`, result: "written", fields: ["node"] }]);
|
||||
assert.equal(f.flows[0].type, "mqtt-broker");
|
||||
assert.equal(f.flows[0].broker, "ace.internal");
|
||||
assert.deepEqual(f.creds[MESH_BROKER_ID], { user: "mesh_ace_nodered", password: MINTED });
|
||||
});
|
||||
|
||||
test("a login the broker does not take is never written", async () => {
|
||||
const f = fakeNodeRed(aceFlows());
|
||||
const out = await reconcileBrokers({ nodered: f.nodered, probe: async () => ({ connack: 5 }), marks: marks() }, binding(), MINTED, ["2b0aece9c5f3b307"]);
|
||||
assert.equal(out[0].result, "refused");
|
||||
assert.equal(f.deploys.length, 0);
|
||||
});
|
||||
|
||||
test("a named node that is not there, or a loopback broker, is refused", async () => {
|
||||
const f = fakeNodeRed(aceFlows());
|
||||
const out = await reconcileBrokers({ nodered: f.nodered, probe: takes, marks: marks() }, binding(), MINTED, ["gone"]);
|
||||
assert.match((out[0] as { problem: string }).problem, /no such node/);
|
||||
const lo = await reconcileBrokers({ nodered: f.nodered, probe: takes, marks: marks() }, binding("127.0.0.1"), MINTED, []);
|
||||
assert.match((lo[0] as { problem: string }).problem, /Node-RED itself/);
|
||||
assert.equal(f.deploys.length, 0);
|
||||
});
|
||||
|
||||
test("a deploy that raced another is read again once", async () => {
|
||||
const f = fakeNodeRed(aceFlows());
|
||||
let first = true;
|
||||
const racing: NodeRed = {
|
||||
...f.nodered,
|
||||
async flows() {
|
||||
const got = await f.nodered.flows();
|
||||
if (first) {
|
||||
first = false;
|
||||
return { ...got, rev: "stale" };
|
||||
}
|
||||
return got;
|
||||
},
|
||||
};
|
||||
const out = await reconcileBrokers({ nodered: racing, probe: takes, marks: marks() }, binding(), MINTED, ["2b0aece9c5f3b307"]);
|
||||
assert.equal(out[0].result, "written");
|
||||
assert.equal(f.deploys.length, 1);
|
||||
});
|
||||
|
||||
test("settings name broker nodes under mqtt.brokers", () => {
|
||||
assert.deepEqual(namedBrokers({ mqtt: { brokers: ["a", "", 3, "b"] } }), ["a", "b"]);
|
||||
assert.deepEqual(namedBrokers({ endpoints: {} }), []);
|
||||
assert.deepEqual(namedBrokers(undefined), []);
|
||||
});
|
||||
@@ -8,11 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": [
|
||||
"client.ts",
|
||||
"tools/index.ts",
|
||||
"mqtt/probe.ts",
|
||||
"mqtt/connection.ts",
|
||||
"mqtt/index.ts"
|
||||
]
|
||||
"include": ["client.ts", "tools/index.ts"]
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"module": "website",
|
||||
"module": "novox.be",
|
||||
"version": "1",
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
@@ -14,41 +14,38 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
"route": "/var/lib/novox.be/route.json"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
"name": "web",
|
||||
"port": 8080,
|
||||
"port": 4000,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the public website over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the public website over http; the public name novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/novox.be",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
"type": "network",
|
||||
"name": "website"
|
||||
"name": "novox-be"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "website",
|
||||
"name": "novox-be",
|
||||
"image": "registry-api.novox.be/novox/www@sha256:aa7ed20a293e1d7444c5c5d59b6d8bdb382bad159559a22e006810e379cae69c",
|
||||
"network": "website",
|
||||
"network": "novox-be",
|
||||
"ports": [
|
||||
"8080"
|
||||
],
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -81,7 +81,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_NZBGET_URL": "http://127.0.0.1:6789",
|
||||
"MESH_NZBGET_URL": "http://127.0.0.1:${port:6789}",
|
||||
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
||||
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
||||
|
||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/ombi
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts servarr/settings.ts servarr/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
@@ -22,3 +22,6 @@ COPY --from=build /app/modules/ombi/dist /app/modules/ombi/dist
|
||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||
# the convention novox/hq issues 060/061 settled.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/ombi/dist/index.js,/app/modules/ombi/dist/tools/index.js
|
||||
# NOT dist/servarr/index.js: that is a step the host runs to completion, named by the `servarr`
|
||||
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
||||
# serving sidecar too, and exit it.
|
||||
|
||||
+58
-10
@@ -28,10 +28,15 @@
|
||||
"path": "/var/lib/mesh/ombi",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "directory",
|
||||
"path": "/services/ombi/config",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
@@ -39,7 +44,7 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "ombi",
|
||||
"image": "lscr.io/linuxserver/ombi@sha256:a6f76ac521ba01eee2e9f0c23a3fed22e56630d97a04d5eeaeaa36c1e681640d",
|
||||
"image": "lscr.io/linuxserver/ombi@sha256:22d6ebadbaaa728571353e74dc2173719e0fb02d4eaec551a7e9d2ee99ef68ac",
|
||||
"env": {
|
||||
"PUID": "1000",
|
||||
"PGID": "1000",
|
||||
@@ -49,7 +54,7 @@
|
||||
"3579"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/ombi/config:/config"
|
||||
"${dir:config}:/config"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -68,24 +73,59 @@
|
||||
"volumes": [
|
||||
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
|
||||
"/services/ombi/config:/var/lib/ombi/config:ro"
|
||||
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_OMBI_URL": "http://127.0.0.1:3579",
|
||||
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
|
||||
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
|
||||
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
},
|
||||
{
|
||||
"id": "servarr",
|
||||
"type": "container",
|
||||
"name": "mesh-ombi-servarr",
|
||||
"network": "host",
|
||||
"run-once": true,
|
||||
"volumes": [
|
||||
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||
"${dir:state}/sonarr-api.json:/run/servarr/sonarr-api.json:ro",
|
||||
"${dir:state}/sonarr-api.secret:/run/servarr/sonarr-api.secret:ro",
|
||||
"${dir:state}/radarr-api.json:/run/servarr/radarr-api.json:ro",
|
||||
"${dir:state}/radarr-api.secret:/run/servarr/radarr-api.secret:ro",
|
||||
"${dir:state}/lidarr-api.json:/run/servarr/lidarr-api.json:ro",
|
||||
"${dir:state}/lidarr-api.secret:/run/servarr/lidarr-api.secret:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
|
||||
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||
"MESH_SERVARR_DIR": "/run/servarr"
|
||||
},
|
||||
"args": [
|
||||
"run",
|
||||
"/app/modules/ombi/dist/servarr/index.js"
|
||||
],
|
||||
"restart-on": [
|
||||
"bound-sonarr-api",
|
||||
"secret-sonarr-api",
|
||||
"bound-radarr-api",
|
||||
"secret-radarr-api",
|
||||
"bound-lidarr-api",
|
||||
"secret-lidarr-api"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route"
|
||||
"lidarr-api",
|
||||
"radarr-api",
|
||||
"route",
|
||||
"sonarr-api"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
@@ -94,7 +134,15 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "/var/lib/mesh/ombi/route.json"
|
||||
"route": "${dir:state}/route.json",
|
||||
"sonarr-api": "${dir:state}/sonarr-api.json",
|
||||
"radarr-api": "${dir:state}/radarr-api.json",
|
||||
"lidarr-api": "${dir:state}/lidarr-api.json"
|
||||
},
|
||||
"secrets": {
|
||||
"sonarr-api": "${dir:state}/sonarr-api.secret",
|
||||
"radarr-api": "${dir:state}/radarr-api.secret",
|
||||
"lidarr-api": "${dir:state}/lidarr-api.secret"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
@@ -4,6 +4,11 @@
|
||||
"description": "ombi — media requests. Its API client, tools and events live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts index.ts tools/index.ts servarr/settings.ts servarr/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"typecheck": "tsc -p tsconfig.json",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
},
|
||||
|
||||
@@ -0,0 +1,59 @@
|
||||
// ombi's Servarr step — run once by the host after ombi's server starts, and run again whenever a
|
||||
// binding or pair credential it reads changes (the container's `restart-on`, novox/hq ADR 0099).
|
||||
//
|
||||
// **A step, not a loop**, for the reason route-adapter gives: everything it does is a function of
|
||||
// files the mesh writes, and the host already knows when they change. It connects to no broker.
|
||||
//
|
||||
// Exits non-zero when any app could not be put right — a refused credential, an unreachable app, an
|
||||
// ombi that cannot reach it — so the node reports the step failed and the host runs it again on the
|
||||
// next apply. It is declared last in the manifest, so its failing gates nothing else of ombi's
|
||||
// (novox/hq ADR 0136).
|
||||
//
|
||||
// Reads, per app, `<dir>/<provision>.json` (the binding) and `<dir>/<provision>.secret` (the pair
|
||||
// credential), where <dir> is MESH_SERVARR_DIR. Never prints a key.
|
||||
|
||||
import { join } from "node:path";
|
||||
|
||||
import { APPS, ombiReady, readBinding, readIfThere, reconcileApp, type Http } from "./settings.js";
|
||||
|
||||
const dir = process.env.MESH_SERVARR_DIR ?? "/run/servarr";
|
||||
const url = process.env.MESH_OMBI_URL ?? "http://127.0.0.1:3579";
|
||||
const apiKey = (await readIfThere(process.env.MESH_OMBI_API_KEY_FILE))?.trim() ?? process.env.MESH_OMBI_API_KEY ?? "";
|
||||
const waitSeconds = Number(process.env.MESH_OMBI_WAIT_SECONDS ?? "180");
|
||||
|
||||
const http: Http = { fetch: (u, init) => fetch(u, init) };
|
||||
|
||||
if (!apiKey) {
|
||||
console.error("[ombi-servarr] no ombi API key — ombi's own `api-key` secret has not been accepted");
|
||||
process.exit(1);
|
||||
}
|
||||
const ombi = { url, apiKey };
|
||||
|
||||
if (!(await ombiReady(http, ombi, waitSeconds * 1000))) {
|
||||
console.error(`[ombi-servarr] ombi did not answer at ${url} within ${waitSeconds}s`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
let failed = 0;
|
||||
for (const spec of APPS) {
|
||||
const outcome = await reconcileApp(
|
||||
http,
|
||||
ombi,
|
||||
spec,
|
||||
await readBinding(join(dir, `${spec.provision}.json`)),
|
||||
await readIfThere(join(dir, `${spec.provision}.secret`)),
|
||||
);
|
||||
switch (outcome.result) {
|
||||
case "unchanged":
|
||||
console.log(`[ombi-servarr] ${outcome.app}: already as the mesh says; connection tested`);
|
||||
break;
|
||||
case "written":
|
||||
console.log(`[ombi-servarr] ${outcome.app}: wrote ${outcome.fields.join(", ")}; connection tested`);
|
||||
break;
|
||||
case "refused":
|
||||
failed++;
|
||||
console.error(`[ombi-servarr] ${outcome.app}: ${outcome.problem}`);
|
||||
break;
|
||||
}
|
||||
}
|
||||
process.exitCode = failed > 0 ? 1 : 0;
|
||||
@@ -0,0 +1,304 @@
|
||||
// Where ombi reaches Sonarr, Radarr and Lidarr — decided by the mesh, written into ombi by ombi's
|
||||
// own API.
|
||||
//
|
||||
// **Why this exists.** ombi keeps its connection to each Servarr app in its own database
|
||||
// (OmbiSettings.db), not in a file, so the mesh has nowhere to write `${bound:sonarr-api:at}` for it.
|
||||
// ombi requires `sonarr-api`, `radarr-api` and `lidarr-api`; the mesh delivers, for each, a binding
|
||||
// (where the app is: `at`, and what it serves: `port`, `scheme`, `url-base`) and a pair credential
|
||||
// (the app's API key, accepted by the operator — a Servarr app has exactly one key and the mesh
|
||||
// cannot mint it). This step reads those files and makes ombi's settings say the same thing.
|
||||
//
|
||||
// **Only the connection, and only when it differs.** Host, port, TLS, base path and API key. The
|
||||
// quality profile, root folder, language profile, tags, "enabled" and every other choice an operator
|
||||
// made in ombi's settings screen are left exactly as they are: the mesh knows where the app is, not
|
||||
// what ombi should do with it. Radarr's 4K instance is a different Radarr and is not touched.
|
||||
//
|
||||
// **A credential the app refuses is never written.** Until the operator accepts the app's API key
|
||||
// for this pair, the mesh delivers a value it minted itself, which no Servarr app will ever accept
|
||||
// (novox/hq ADR 0092). Writing it would replace a working key in ombi with a dead one. So the key is
|
||||
// tried against the app first; refused, nothing for that app is written and the step fails naming
|
||||
// the `secret accept` that fixes it.
|
||||
//
|
||||
// Pure logic and a small HTTP seam, so it is tested against fake servers (test/servarr.test.ts).
|
||||
|
||||
import { readFile } from "node:fs/promises";
|
||||
|
||||
/** One Servarr app ombi connects to, and the shape of that connection in ombi's API. */
|
||||
export interface ServarrApp {
|
||||
/** The app, as ombi's API names it: /Settings/<app>, /Tester/<app>. */
|
||||
app: "sonarr" | "radarr" | "lidarr";
|
||||
/** The provision it is required as — the manifest's `requires`, `binds` and `secrets` key. */
|
||||
provision: string;
|
||||
/** The app's own status endpoint, which answers 401 to a wrong key. */
|
||||
statusPath: string;
|
||||
/**
|
||||
* Where the one connection sits in ombi's settings document. Radarr's is `{radarr, radarr4K}`
|
||||
* (two Radarr instances); only `radarr` is this provision's.
|
||||
*/
|
||||
within?: string;
|
||||
}
|
||||
|
||||
export const APPS: readonly ServarrApp[] = [
|
||||
{ app: "sonarr", provision: "sonarr-api", statusPath: "/api/v3/system/status" },
|
||||
{ app: "radarr", provision: "radarr-api", statusPath: "/api/v3/system/status", within: "radarr" },
|
||||
{ app: "lidarr", provision: "lidarr-api", statusPath: "/api/v1/system/status" },
|
||||
];
|
||||
|
||||
/** The connection fields ombi keeps for an app — the only ones this step ever writes. */
|
||||
export interface Connection {
|
||||
ip: string;
|
||||
port: number;
|
||||
ssl: boolean;
|
||||
/** ombi's name for the app's URL base; null when the app is served at the root. */
|
||||
subDir: string | null;
|
||||
apiKey: string;
|
||||
}
|
||||
|
||||
/** What the mesh wrote at `binds.<provision>`: the binding document (controller's boundFile). */
|
||||
export interface Binding {
|
||||
provision?: string;
|
||||
from?: string;
|
||||
at?: string;
|
||||
as?: string;
|
||||
serves?: Record<string, unknown>;
|
||||
}
|
||||
|
||||
export type Wanted = { ok: true; connection: Connection; from: string } | { ok: false; problem: string };
|
||||
|
||||
/**
|
||||
* The connection the mesh says ombi should use, from the binding and the pair credential.
|
||||
*
|
||||
* Refused rather than guessed when the binding cannot be dialled from ombi's own container: a
|
||||
* loopback `at` — what the mesh hands a machine that is not on the private network — is ombi's
|
||||
* container itself, not the app.
|
||||
*/
|
||||
export function wanted(spec: ServarrApp, binding: Binding | undefined, credential: string | undefined): Wanted {
|
||||
if (!binding) {
|
||||
return { ok: false, problem: `no binding for ${spec.provision} was delivered — the mesh writes it before this step runs` };
|
||||
}
|
||||
const at = typeof binding.at === "string" ? binding.at.trim() : "";
|
||||
const serves = binding.serves ?? {};
|
||||
const port = Number(serves.port);
|
||||
if (!at) {
|
||||
return { ok: false, problem: `the ${spec.provision} binding names no host (at)` };
|
||||
}
|
||||
if (isLoopback(at)) {
|
||||
return {
|
||||
ok: false,
|
||||
problem:
|
||||
`the ${spec.provision} binding says ${spec.app} is at ${at}, which from ombi's own container is ` +
|
||||
`ombi itself. The mesh hands loopback to a machine that is not on the private network; put it ` +
|
||||
`on the private network so ${spec.app} has an address ombi can dial`,
|
||||
};
|
||||
}
|
||||
if (!Number.isInteger(port) || port <= 0 || port > 65535) {
|
||||
return { ok: false, problem: `the ${spec.provision} binding serves no usable port (${String(serves.port)})` };
|
||||
}
|
||||
const scheme = typeof serves.scheme === "string" && serves.scheme ? serves.scheme : "http";
|
||||
if (scheme !== "http" && scheme !== "https") {
|
||||
return { ok: false, problem: `the ${spec.provision} binding serves scheme ${scheme}, which ombi cannot dial` };
|
||||
}
|
||||
const key = (credential ?? "").trim();
|
||||
if (!key) {
|
||||
return { ok: false, problem: `the ${spec.provision} credential is empty or was not delivered` };
|
||||
}
|
||||
return {
|
||||
ok: true,
|
||||
from: typeof binding.from === "string" ? binding.from : "",
|
||||
connection: { ip: at, port, ssl: scheme === "https", subDir: subDirOf(serves["url-base"]), apiKey: key },
|
||||
};
|
||||
}
|
||||
|
||||
/** ombi's `subDir`: the URL base with its slashes trimmed, null when there is none. */
|
||||
export function subDirOf(urlBase: unknown): string | null {
|
||||
const trimmed = typeof urlBase === "string" ? urlBase.trim().replace(/^\/+|\/+$/g, "") : "";
|
||||
return trimmed === "" ? null : trimmed;
|
||||
}
|
||||
|
||||
function isLoopback(host: string): boolean {
|
||||
const h = host.toLowerCase();
|
||||
return h === "localhost" || h === "::1" || h === "[::1]" || /^127\./.test(h);
|
||||
}
|
||||
|
||||
/** Which connection fields differ between what ombi holds and what the mesh says. Names only. */
|
||||
export function differing(current: Record<string, unknown> | undefined, want: Connection): (keyof Connection)[] {
|
||||
const now = current ?? {};
|
||||
const out: (keyof Connection)[] = [];
|
||||
if (String(now.ip ?? "") !== want.ip) out.push("ip");
|
||||
if (Number(now.port ?? 0) !== want.port) out.push("port");
|
||||
if (Boolean(now.ssl) !== want.ssl) out.push("ssl");
|
||||
if (subDirOf(now.subDir) !== want.subDir) out.push("subDir");
|
||||
if (String(now.apiKey ?? "") !== want.apiKey) out.push("apiKey");
|
||||
return out;
|
||||
}
|
||||
|
||||
/** ombi's settings for the app with the connection laid over them and nothing else changed. */
|
||||
export function withConnection(current: Record<string, unknown> | undefined, want: Connection): Record<string, unknown> {
|
||||
return { ...(current ?? {}), ip: want.ip, port: want.port, ssl: want.ssl, subDir: want.subDir, apiKey: want.apiKey };
|
||||
}
|
||||
|
||||
/** The app's base URL as the step dials it — the same host and port ombi will be given. */
|
||||
export function appUrl(want: Connection): string {
|
||||
const scheme = want.ssl ? "https" : "http";
|
||||
const host = want.ip.includes(":") && !want.ip.startsWith("[") ? `[${want.ip}]` : want.ip;
|
||||
return `${scheme}://${host}:${want.port}${want.subDir ? `/${want.subDir}` : ""}`;
|
||||
}
|
||||
|
||||
/** How one app came out. */
|
||||
export type Outcome =
|
||||
| { app: string; result: "unchanged" }
|
||||
| { app: string; result: "written"; fields: string[] }
|
||||
| { app: string; result: "refused"; problem: string };
|
||||
|
||||
/** The HTTP the step needs, so a test can stand fakes in for ombi and the apps. */
|
||||
export interface Http {
|
||||
fetch(url: string, init?: { method?: string; headers?: Record<string, string>; body?: string }): Promise<{
|
||||
status: number;
|
||||
text(): Promise<string>;
|
||||
}>;
|
||||
}
|
||||
|
||||
export interface Ombi {
|
||||
url: string;
|
||||
apiKey: string;
|
||||
}
|
||||
|
||||
async function ombiCall(http: Http, ombi: Ombi, method: string, path: string, body?: unknown): Promise<unknown> {
|
||||
const res = await http.fetch(`${ombi.url.replace(/\/$/, "")}/api/v1${path}`, {
|
||||
method,
|
||||
headers: {
|
||||
ApiKey: ombi.apiKey,
|
||||
Accept: "application/json",
|
||||
...(body !== undefined ? { "Content-Type": "application/json" } : {}),
|
||||
},
|
||||
body: body !== undefined ? JSON.stringify(body) : undefined,
|
||||
});
|
||||
const text = await res.text();
|
||||
if (res.status < 200 || res.status >= 300) {
|
||||
// The body is ombi's error, never a request echo, so it carries no key.
|
||||
throw new Error(`ombi ${method} ${path} answered ${res.status}${text ? `: ${text.slice(0, 200)}` : ""}`);
|
||||
}
|
||||
return text ? (JSON.parse(text) as unknown) : undefined;
|
||||
}
|
||||
|
||||
/**
|
||||
* Does the app take this key? `true` it does, `false` it refused it (401/403), and a thrown error
|
||||
* when it could not be asked — unreachable, or answering something that is neither.
|
||||
*/
|
||||
export async function appTakes(http: Http, spec: ServarrApp, want: Connection): Promise<boolean> {
|
||||
const res = await http.fetch(`${appUrl(want)}${spec.statusPath}`, {
|
||||
method: "GET",
|
||||
headers: { "X-Api-Key": want.apiKey, Accept: "application/json" },
|
||||
});
|
||||
if (res.status === 401 || res.status === 403) return false;
|
||||
if (res.status >= 200 && res.status < 300) return true;
|
||||
throw new Error(`${spec.app} answered ${res.status} at ${spec.statusPath}`);
|
||||
}
|
||||
|
||||
/** The remedy for a refused key, in the controller's own words (ADR 0092). */
|
||||
export function acceptRemedy(spec: ServarrApp, from: string): string {
|
||||
return (
|
||||
`${spec.app} refuses the ${spec.provision} credential the mesh delivered, so it was not written ` +
|
||||
`into ombi. A Servarr app has one API key and the mesh cannot make it: accept ${spec.app}'s own ` +
|
||||
`key for this pair — \`secret accept <this node> ombi ${spec.provision} --provider ${from || "<its node>"} ` +
|
||||
`--from <file holding ${spec.app}'s ApiKey>\``
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Bring ombi's connection to one app in line with the mesh: check the key against the app, compare,
|
||||
* write only the connection fields when they differ, then have ombi test the connection from its own
|
||||
* container. Never throws: every failure is an outcome with a reason.
|
||||
*/
|
||||
export async function reconcileApp(
|
||||
http: Http,
|
||||
ombi: Ombi,
|
||||
spec: ServarrApp,
|
||||
binding: Binding | undefined,
|
||||
credential: string | undefined,
|
||||
): Promise<Outcome> {
|
||||
const w = wanted(spec, binding, credential);
|
||||
// `in`, not `!w.ok`: the Dockerfile compiles without strict, where a boolean discriminant does not
|
||||
// narrow.
|
||||
if ("problem" in w) return { app: spec.app, result: "refused", problem: w.problem };
|
||||
const want = w.connection;
|
||||
|
||||
try {
|
||||
if (!(await appTakes(http, spec, want))) {
|
||||
return { app: spec.app, result: "refused", problem: acceptRemedy(spec, w.from) };
|
||||
}
|
||||
} catch (err) {
|
||||
return {
|
||||
app: spec.app,
|
||||
result: "refused",
|
||||
problem: `${spec.app} could not be asked whether it takes the key at ${want.ip}:${want.port}: ${message(err)}`,
|
||||
};
|
||||
}
|
||||
|
||||
try {
|
||||
const document = (await ombiCall(http, ombi, "GET", `/Settings/${spec.app}`)) as Record<string, unknown> | undefined;
|
||||
const current = spec.within ? (document?.[spec.within] as Record<string, unknown> | undefined) : document;
|
||||
const fields = differing(current, want);
|
||||
if (fields.length > 0) {
|
||||
const next = withConnection(current, want);
|
||||
const body = spec.within ? { ...(document ?? {}), [spec.within]: next } : next;
|
||||
const saved = await ombiCall(http, ombi, "POST", `/Settings/${spec.app}`, body);
|
||||
if (saved === false) {
|
||||
return { app: spec.app, result: "refused", problem: `ombi declined to save its ${spec.app} settings` };
|
||||
}
|
||||
}
|
||||
// ombi's own test, from ombi's own container — the path the step's check above did not take.
|
||||
const tested = (await ombiCall(http, ombi, "POST", `/Tester/${spec.app}`, withConnection(current, want))) as
|
||||
| { isValid?: boolean; expectedSubDir?: string | null }
|
||||
| undefined;
|
||||
if (!tested?.isValid) {
|
||||
const hint = tested?.expectedSubDir ? ` (ombi expected the base path ${tested.expectedSubDir})` : "";
|
||||
return {
|
||||
app: spec.app,
|
||||
result: "refused",
|
||||
problem:
|
||||
`ombi cannot reach ${spec.app} at ${want.ip}:${want.port} from its own container${hint}` +
|
||||
(fields.length > 0 ? `; its settings were written (${fields.join(", ")})` : ""),
|
||||
};
|
||||
}
|
||||
return fields.length > 0 ? { app: spec.app, result: "written", fields } : { app: spec.app, result: "unchanged" };
|
||||
} catch (err) {
|
||||
return { app: spec.app, result: "refused", problem: message(err) };
|
||||
}
|
||||
}
|
||||
|
||||
/** Wait for ombi to answer, because the step runs right after its container starts. */
|
||||
export async function ombiReady(http: Http, ombi: Ombi, waitMs: number, pauseMs = 2000): Promise<boolean> {
|
||||
const until = Date.now() + waitMs;
|
||||
for (;;) {
|
||||
try {
|
||||
const res = await http.fetch(`${ombi.url.replace(/\/$/, "")}/api/v1/Status`, { method: "GET" });
|
||||
if (res.status === 200) return true;
|
||||
} catch {
|
||||
// not listening yet
|
||||
}
|
||||
if (Date.now() >= until) return false;
|
||||
await new Promise((r) => setTimeout(r, pauseMs));
|
||||
}
|
||||
}
|
||||
|
||||
/** A file the mesh wrote, or undefined when it is not there. */
|
||||
export async function readIfThere(path: string | undefined): Promise<string | undefined> {
|
||||
if (!path) return undefined;
|
||||
return readFile(path, "utf8").catch(() => undefined);
|
||||
}
|
||||
|
||||
/** A binding file parsed, or undefined when absent or not JSON. */
|
||||
export async function readBinding(path: string | undefined): Promise<Binding | undefined> {
|
||||
const raw = await readIfThere(path);
|
||||
if (raw === undefined) return undefined;
|
||||
try {
|
||||
return JSON.parse(raw) as Binding;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
function message(err: unknown): string {
|
||||
return err instanceof Error ? err.message : String(err);
|
||||
}
|
||||
@@ -0,0 +1,147 @@
|
||||
// What holds ombi's Servarr step (servarr/settings.ts): the connection ombi keeps for each app is
|
||||
// made to say what the mesh bound — host, port, TLS, base path, key — and nothing else it keeps is
|
||||
// touched; nothing is written when nothing differs; Radarr's 4K instance is left alone; and a key the
|
||||
// app refuses (the mesh's own minted value, before the operator accepts the app's key) is never
|
||||
// written, with the `secret accept` that fixes it named.
|
||||
//
|
||||
// ombi and the apps are fakes: the routes the step touches, answering as the real ones do (checked
|
||||
// against lscr.io/linuxserver/ombi 4.53.10 and the catalogue's pinned sonarr/radarr/lidarr).
|
||||
|
||||
import { test } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
|
||||
import { APPS, differing, reconcileApp, subDirOf, wanted, type Binding, type Http, type ServarrApp } from "../servarr/settings.ts";
|
||||
|
||||
const SONARR = APPS.find((a) => a.app === "sonarr") as ServarrApp;
|
||||
const RADARR = APPS.find((a) => a.app === "radarr") as ServarrApp;
|
||||
const LIDARR = APPS.find((a) => a.app === "lidarr") as ServarrApp;
|
||||
const THE_KEY = "the-apps-own-key";
|
||||
|
||||
function binding(provision: string, port: number, at = "ace.internal"): Binding {
|
||||
return { binding: 1, provision, from: "ace", at, as: "mesh_ace_ombi", serves: { scheme: "http", port, "url-base": "" } } as Binding;
|
||||
}
|
||||
|
||||
interface Call {
|
||||
method: string;
|
||||
url: string;
|
||||
body?: unknown;
|
||||
}
|
||||
|
||||
/** ombi's settings store and the apps' key check, behind one fetch. */
|
||||
function fakes(settings: Record<string, unknown>, opts: { appKey?: string; reachable?: boolean } = {}) {
|
||||
const calls: Call[] = [];
|
||||
const appKey = opts.appKey ?? THE_KEY;
|
||||
const http: Http = {
|
||||
async fetch(url, init) {
|
||||
const method = init?.method ?? "GET";
|
||||
const body = init?.body ? (JSON.parse(init.body) as unknown) : undefined;
|
||||
calls.push({ method, url, body });
|
||||
const reply = (status: number, value?: unknown) => ({
|
||||
status,
|
||||
text: async () => (value === undefined ? "" : JSON.stringify(value)),
|
||||
});
|
||||
const u = new URL(url);
|
||||
if (u.pathname.endsWith("/system/status")) {
|
||||
if (opts.reachable === false) throw new Error("connect ECONNREFUSED");
|
||||
return init?.headers?.["X-Api-Key"] === appKey ? reply(200, { version: "4" }) : reply(401);
|
||||
}
|
||||
if (init?.headers?.ApiKey !== "ombi-key") return reply(401);
|
||||
const m = u.pathname.match(/^\/api\/v1\/(Settings|Tester)\/(\w+)$/);
|
||||
if (!m) return reply(404);
|
||||
const [, kind, app] = m;
|
||||
if (kind === "Settings" && method === "GET") return reply(200, settings[app]);
|
||||
if (kind === "Settings" && method === "POST") {
|
||||
settings[app] = body;
|
||||
return reply(200, true);
|
||||
}
|
||||
const tried = body as { apiKey?: string };
|
||||
return reply(200, { isValid: tried.apiKey === appKey, expectedSubDir: null });
|
||||
},
|
||||
};
|
||||
return { http, calls, settings };
|
||||
}
|
||||
|
||||
const OMBI = { url: "http://127.0.0.1:3579", apiKey: "ombi-key" };
|
||||
|
||||
const operatorSonarr = () => ({
|
||||
enabled: true, apiKey: "old-key", qualityProfile: "3", seasonFolders: true, rootPath: "10",
|
||||
qualityProfileAnime: "7", rootPathAnime: "9", languageProfile: 1, ssl: false, subDir: null,
|
||||
ip: "sonarr", port: 8989, id: 5,
|
||||
});
|
||||
|
||||
test("it writes the connection the mesh bound, and keeps every other setting ombi had", async () => {
|
||||
const f = fakes({ sonarr: operatorSonarr() });
|
||||
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), `${THE_KEY}\n`);
|
||||
assert.deepEqual(out, { app: "sonarr", result: "written", fields: ["ip", "port", "apiKey"] });
|
||||
assert.deepEqual(f.settings.sonarr, {
|
||||
...operatorSonarr(), ip: "ace.internal", port: 20101, apiKey: THE_KEY, ssl: false, subDir: null,
|
||||
});
|
||||
// Checked against the app itself, at the bound address, before anything was written.
|
||||
assert.equal(f.calls[0].url, "http://ace.internal:20101/api/v3/system/status");
|
||||
});
|
||||
|
||||
test("nothing is written when ombi already says what the mesh says", async () => {
|
||||
const f = fakes({ sonarr: { ...operatorSonarr(), ip: "ace.internal", port: 20101, apiKey: THE_KEY } });
|
||||
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), THE_KEY);
|
||||
assert.deepEqual(out, { app: "sonarr", result: "unchanged" });
|
||||
assert.equal(f.calls.filter((c) => c.method === "POST" && c.url.includes("/Settings/")).length, 0);
|
||||
});
|
||||
|
||||
test("a key the app refuses is never written, and the accept that fixes it is named", async () => {
|
||||
const f = fakes({ sonarr: operatorSonarr() });
|
||||
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), "a-value-the-mesh-minted");
|
||||
assert.equal(out.result, "refused");
|
||||
assert.match((out as { problem: string }).problem, /secret accept <this node> ombi sonarr-api --provider ace/);
|
||||
assert.doesNotMatch((out as { problem: string }).problem, /a-value-the-mesh-minted/);
|
||||
assert.deepEqual(f.settings.sonarr, operatorSonarr(), "ombi's working settings were left alone");
|
||||
assert.equal(f.calls.some((c) => c.url.includes("/api/v1/")), false, "ombi was not even asked");
|
||||
});
|
||||
|
||||
test("an app it cannot reach is reported, and ombi is left alone", async () => {
|
||||
const f = fakes({ sonarr: operatorSonarr() }, { reachable: false });
|
||||
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), THE_KEY);
|
||||
assert.equal(out.result, "refused");
|
||||
assert.match((out as { problem: string }).problem, /could not be asked.*ECONNREFUSED/);
|
||||
assert.deepEqual(f.settings.sonarr, operatorSonarr());
|
||||
});
|
||||
|
||||
test("radarr's connection is written inside its combined document, and the 4K instance is untouched", async () => {
|
||||
const fourK = { enabled: true, apiKey: "4k-key", ip: "radarr4k", port: 7879, defaultQualityProfile: "9", id: 7 };
|
||||
const f = fakes({ radarr: { radarr: { enabled: true, apiKey: "old", ip: "radarr", port: 7878, defaultRootPath: "/movies", id: 6 }, radarr4K: fourK } });
|
||||
const out = await reconcileApp(f.http, OMBI, RADARR, binding("radarr-api", 20102), THE_KEY);
|
||||
assert.equal(out.result, "written");
|
||||
const doc = f.settings.radarr as { radarr: Record<string, unknown>; radarr4K: unknown };
|
||||
assert.deepEqual(doc.radarr4K, fourK);
|
||||
assert.equal(doc.radarr.ip, "ace.internal");
|
||||
assert.equal(doc.radarr.port, 20102);
|
||||
assert.equal(doc.radarr.defaultRootPath, "/movies");
|
||||
});
|
||||
|
||||
test("lidarr is checked on its own API version", async () => {
|
||||
const f = fakes({ lidarr: { enabled: true, apiKey: null, ip: null, port: 0, id: 0 } });
|
||||
const out = await reconcileApp(f.http, OMBI, LIDARR, binding("lidarr-api", 20103), THE_KEY);
|
||||
assert.equal(out.result, "written");
|
||||
assert.equal(f.calls[0].url, "http://ace.internal:20103/api/v1/system/status");
|
||||
});
|
||||
|
||||
test("a loopback binding is refused: from ombi's container it is ombi itself", () => {
|
||||
const w = wanted(SONARR, binding("sonarr-api", 20101, "127.0.0.1"), THE_KEY);
|
||||
assert.equal(w.ok, false);
|
||||
assert.match((w as { problem: string }).problem, /private network/);
|
||||
});
|
||||
|
||||
test("the base path is ombi's subDir, slashes trimmed; empty is none", () => {
|
||||
assert.equal(subDirOf(""), null);
|
||||
assert.equal(subDirOf("/sonarr/"), "sonarr");
|
||||
assert.deepEqual(
|
||||
differing({ ip: "h", port: 1, ssl: false, subDir: "", apiKey: "k" }, { ip: "h", port: 1, ssl: false, subDir: null, apiKey: "k" }),
|
||||
[],
|
||||
);
|
||||
});
|
||||
|
||||
test("an https binding sets ombi's ssl flag", () => {
|
||||
const b = binding("sonarr-api", 443);
|
||||
(b.serves as Record<string, unknown>).scheme = "https";
|
||||
const w = wanted(SONARR, b, THE_KEY);
|
||||
assert.equal(w.ok && w.connection.ssl, true);
|
||||
});
|
||||
@@ -8,5 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": ["client.ts", "index.ts", "tools/index.ts"]
|
||||
"include": ["client.ts", "index.ts", "tools/index.ts", "servarr/settings.ts", "servarr/index.ts"]
|
||||
}
|
||||
|
||||
@@ -26,7 +26,7 @@
|
||||
"port": 9070,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the document server over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the document server over http; the public name office.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
|
||||
@@ -23,7 +23,7 @@
|
||||
"port": 4012,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the eef photos client site over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the eef photos client site over http; the public name eef.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -46,10 +46,7 @@
|
||||
"network": "photos-eef",
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -23,7 +23,7 @@
|
||||
"port": 4013,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the filip photos client site over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the filip photos client site over http; the public name filip.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -46,10 +46,7 @@
|
||||
"network": "photos-filip",
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -43,7 +43,7 @@
|
||||
"port": 4001,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the admin client site over http; its public name is a route grant, and route-proxy reaches it on this published port"
|
||||
"why": "the admin client site over http; the public name photos.novox.be is a route grant, and route-proxy reaches it on this published port"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -77,10 +77,7 @@
|
||||
"ports": [
|
||||
"9000"
|
||||
],
|
||||
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (photos server/src/config.js); converting is that repository's change",
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (photos server/src/config.js); converting is that repository's change"
|
||||
},
|
||||
{
|
||||
"id": "admin-client",
|
||||
@@ -90,10 +87,7 @@
|
||||
"network": "photos",
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"names-on-purpose": {
|
||||
"registry-api.novox.be": "built outside the mesh, from the application's own repository, and pulled from the registry that built it; moves when that repository is a build source on the git seat (novox/hq ADR 0155, issue 122)"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -8,10 +8,10 @@
|
||||
"listens": [
|
||||
{
|
||||
"name": "web",
|
||||
"port": 9000,
|
||||
"port": 9090,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the dashboard over http; its public name is a route grant and the proxy reaches it here"
|
||||
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
||||
},
|
||||
{
|
||||
"name": "web-tls",
|
||||
@@ -39,8 +39,8 @@
|
||||
"name": "portainer",
|
||||
"image": "portainer/portainer-ce@sha256:4d616db18cfeb5dd41a69c0958bc825c84483ea9cde1106eb82a5d26f3bd8b0e",
|
||||
"ports": [
|
||||
"9000",
|
||||
"9443"
|
||||
"9090:9000",
|
||||
"9443:9443"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/data",
|
||||
|
||||
@@ -105,7 +105,7 @@
|
||||
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
|
||||
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:5432/postgres?sslmode=disable",
|
||||
"MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}",
|
||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
|
||||
@@ -82,7 +82,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
|
||||
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8080}",
|
||||
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
||||
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
||||
|
||||
@@ -1,6 +1,19 @@
|
||||
{
|
||||
"module": "radarr",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "radarr-api",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"radarr-api": {
|
||||
"scheme": "http",
|
||||
"port": 7878,
|
||||
"url-base": ""
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -75,7 +88,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RADARR_URL": "http://127.0.0.1:7878",
|
||||
"MESH_RADARR_URL": "http://127.0.0.1:${port:7878}",
|
||||
"MESH_RADARR_CONFIG_DIR": "/var/lib/radarr/config"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
|
||||
@@ -1,26 +0,0 @@
|
||||
# records' runtime: the tool runtime, carrying this module's compiled reader and its tools.
|
||||
#
|
||||
# **Built from this module's own directory and nothing else.** The sdk is in the base image, so
|
||||
# nothing is copied out of a neighbouring checkout (novox/hq ADR 0069).
|
||||
#
|
||||
# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in
|
||||
# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults.
|
||||
ARG BUILD_BASE
|
||||
ARG RUNTIME_BASE
|
||||
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/records
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc records.ts index.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
# **A module may need something the base image does not carry.** The reader keeps a checkout of the
|
||||
# repository it reads (novox/hq ADR 0153) — a git working copy, kept current, not a derived copy — and
|
||||
# the base image has no git. Certificates too, because the origin may be reached over TLS.
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends git ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
COPY --from=build /app/modules/records/dist /app/modules/records/dist
|
||||
# Both entrypoints, loaded in serve mode: the consumer that pulls on a merge, and the tools.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/records/dist/index.js,/app/modules/records/dist/tools/index.js
|
||||
@@ -1,41 +0,0 @@
|
||||
# records
|
||||
|
||||
The record, read where it is written (novox/hq [ADR 0025](https://git.novox.be/novox/hq), ADR 0153).
|
||||
|
||||
A module that keeps a checkout of a repository of decisions, designs and issues — the mesh's own
|
||||
`hq`, or any repository of markdown on the forge — and answers questions about it over the bus, so
|
||||
whoever holds the console sees `records_search` beside every other tool and a symptom can be looked up
|
||||
in the design record without knowing it is there.
|
||||
|
||||
**A checkout, not a copy.** The same bytes the repository holds, at a commit every answer names,
|
||||
brought up to date on every merge the forge announces (`gitea.pull.merged`) and every ten minutes
|
||||
besides. Nothing is indexed, transformed or summarised, so nothing can drift from the source except by
|
||||
lagging behind it, and the lag is in `records_status`.
|
||||
|
||||
## Tools
|
||||
|
||||
| tool | answers |
|
||||
|---|---|
|
||||
| `records_search` `{query, limit?}` | where a phrase appears, as written: document, line, nearest heading, and the commit read |
|
||||
| `records_read` `{path}` | one document, whole |
|
||||
| `records_list` `{folder?}` | what a folder holds |
|
||||
| `records_status` | repository, forge, commit and its date, last sync, document count, last error |
|
||||
| `records_sync` | bring the checkout up to date now |
|
||||
|
||||
## Configuring it
|
||||
|
||||
The module names no mesh (ADR 0112). It requires the `git` provision — the forge — and reads the
|
||||
repository its **settings** name:
|
||||
|
||||
```
|
||||
settings set records repository.json # {"repository": "<owner>/<name>"}
|
||||
```
|
||||
|
||||
Public repositories only: it asks for no credential. Until a repository is set, it serves no tools and
|
||||
says so in its log.
|
||||
|
||||
## The check ADR 0025 names
|
||||
|
||||
Search the mesh, through the console, for a phrase that appears only in one design document here, and
|
||||
get it back. `records_search {"query": "…"}` is that search; its test does the same against a
|
||||
repository it makes.
|
||||
@@ -1,34 +0,0 @@
|
||||
// records' consumer: keep the checkout current (novox/hq ADR 0153).
|
||||
//
|
||||
// Synced when the runtime binds the broker, on every merge the forge announces, and on a timer for
|
||||
// the merges it did not hear about — a restart during a merge, a repository the forge does not emit
|
||||
// for. The timer is unhurried: the record changes when thinking changes, not by the minute.
|
||||
import { on } from "@novox/mesh-sdk/events";
|
||||
import { recordsFromEnv, type Records } from "./records.js";
|
||||
|
||||
let records: Records | null = null;
|
||||
try {
|
||||
records = await recordsFromEnv();
|
||||
} catch (err) {
|
||||
console.log(`[records] not reading — ${err instanceof Error ? err.message : String(err)}`);
|
||||
}
|
||||
|
||||
if (records) {
|
||||
const reader = records;
|
||||
void reader.sync().then(async () => {
|
||||
const s = await reader.standing();
|
||||
console.log(`[records] ${s.repository} at ${s.commit.slice(0, 8) || "(no commit)"}, ${s.documents} document(s)${s.lastError ? ` — ${s.lastError}` : ""}`);
|
||||
});
|
||||
setInterval(() => void reader.sync(), 10 * 60 * 1000).unref();
|
||||
|
||||
// A merge on the forge into the repository this reads: pull now. The event names the repository
|
||||
// by owner and name (gitea's `pull.merged`); anything else is somebody else's merge.
|
||||
await on<{ owner?: string; repo?: string; base?: string }>("gitea.pull.merged", async (event) => {
|
||||
const merged = `${event.body.owner ?? ""}/${event.body.repo ?? ""}`;
|
||||
if (merged !== reader.repository) return;
|
||||
console.log(`[records] ${merged} merged; syncing`);
|
||||
await reader.sync();
|
||||
});
|
||||
}
|
||||
|
||||
export { records };
|
||||
@@ -1,100 +0,0 @@
|
||||
{
|
||||
"module": "records",
|
||||
"version": "1",
|
||||
"slug": "records",
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"requires": [
|
||||
"git"
|
||||
],
|
||||
"binds": {
|
||||
"git": "/var/lib/mesh/records/git.json"
|
||||
},
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/records/broker"
|
||||
},
|
||||
"consumes": [
|
||||
"gitea.pull.merged"
|
||||
],
|
||||
"tools": [
|
||||
"records_search",
|
||||
"records_read",
|
||||
"records_list",
|
||||
"records_status",
|
||||
"records_sync"
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "mesh-state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh/records",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "checkout",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/records",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/records/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
"id": "origin",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/records/origin",
|
||||
"mode": "0600",
|
||||
"content": "${bound:git:scheme}://${bound:git:at}:${bound:git:port}\n"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "records",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/records/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/records/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/mesh/records/origin:/run/config/origin:ro",
|
||||
"/var/lib/records:/var/lib/records"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECORDS_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_RECORDS_ORIGIN_FILE": "/run/config/origin",
|
||||
"MESH_RECORDS_DIR": "/var/lib/records"
|
||||
},
|
||||
"artifact": "runtime",
|
||||
"restart-on": [
|
||||
"config",
|
||||
"origin"
|
||||
]
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
"arg": "BUILD_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "build"
|
||||
},
|
||||
{
|
||||
"arg": "RUNTIME_BASE",
|
||||
"module": "mesh-tools",
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "runtime",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -1,18 +0,0 @@
|
||||
{
|
||||
"name": "@novox/module-records",
|
||||
"version": "0.1.0",
|
||||
"description": "records — reads a repository of decisions, designs and issues where it is written, and answers questions about it (novox/hq ADR 0025, ADR 0153).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc records.ts index.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.1"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/node": "^22.0.0",
|
||||
"typescript": "^5.6.0"
|
||||
}
|
||||
}
|
||||
@@ -1,277 +0,0 @@
|
||||
/**
|
||||
* The record, read where it is written (novox/hq ADR 0025, ADR 0153).
|
||||
*
|
||||
* A repository of decisions, designs and issues — markdown, nothing else — cloned from the mesh's own
|
||||
* forge and kept current. **A checkout, not a copy**: the same bytes the repository holds, at a commit
|
||||
* every answer names, refreshed on every merge the forge announces and on a timer besides. Nothing is
|
||||
* transformed, indexed or summarised on the way, so there is nothing that can drift from the source
|
||||
* except by lagging behind it, and the lag is a number in every answer.
|
||||
*
|
||||
* What it answers: a search for a phrase, a document by path, what a folder holds, and where the
|
||||
* checkout stands. The reasoning is in the documents; this only finds them.
|
||||
*/
|
||||
import { execFile } from "node:child_process";
|
||||
import { promises as fs } from "node:fs";
|
||||
import { join, normalize, relative, sep } from "node:path";
|
||||
import { promisify } from "node:util";
|
||||
|
||||
const run = promisify(execFile);
|
||||
|
||||
/** One place a phrase was found. */
|
||||
export interface Hit {
|
||||
/** The document, relative to the repository's root. */
|
||||
path: string;
|
||||
/** The line it was found on, from 1. */
|
||||
line: number;
|
||||
/** The nearest heading above it, so a hit reads as where in the document it is. */
|
||||
heading: string;
|
||||
/** The line itself, trimmed. */
|
||||
text: string;
|
||||
}
|
||||
|
||||
export interface Standing {
|
||||
repository: string;
|
||||
origin: string;
|
||||
/** The commit the checkout is at, or empty before the first clone. */
|
||||
commit: string;
|
||||
/** When that commit was made, as the repository says. */
|
||||
committed: string;
|
||||
/** When this reader last brought the checkout up to date. */
|
||||
fetched: string;
|
||||
/** How many markdown documents the checkout holds. */
|
||||
documents: number;
|
||||
/** Why the last sync failed, if it did; the checkout stands where it was. */
|
||||
lastError?: string;
|
||||
}
|
||||
|
||||
/** Search answers at most this many places; a phrase found more often is a phrase to narrow. */
|
||||
export const MOST_HITS = 50;
|
||||
/** A document longer than this is answered in part, and says so. */
|
||||
export const MOST_BYTES = 200_000;
|
||||
|
||||
export class Records {
|
||||
/** Where the checkout lives; the mesh gives the module the directory. */
|
||||
readonly dir: string;
|
||||
/** The forge's address, `scheme://host:port`, from the git provision's binding. */
|
||||
readonly origin: string;
|
||||
/** The repository's path on it, `owner/name`, from this module's settings. */
|
||||
readonly repository: string;
|
||||
|
||||
private syncing: Promise<void> | undefined;
|
||||
private fetched = "";
|
||||
private lastError: string | undefined;
|
||||
|
||||
constructor(dir: string, origin: string, repository: string) {
|
||||
this.dir = dir;
|
||||
this.origin = origin;
|
||||
this.repository = repository;
|
||||
}
|
||||
|
||||
/** The clone URL: the forge, the repository. Public repositories only; a credential would be a
|
||||
* secret this module has not asked for. */
|
||||
get url(): string {
|
||||
return `${this.origin.replace(/\/$/, "")}/${this.repository}.git`;
|
||||
}
|
||||
|
||||
/** Bring the checkout up to date, cloning it if it does not exist. One at a time: a second call
|
||||
* while one runs joins it rather than racing it. Never throws — a failed sync is recorded in
|
||||
* `standing()` and the checkout stands where it was, which is still an answer. */
|
||||
sync(): Promise<void> {
|
||||
if (!this.syncing) {
|
||||
this.syncing = this.doSync().finally(() => {
|
||||
this.syncing = undefined;
|
||||
});
|
||||
}
|
||||
return this.syncing;
|
||||
}
|
||||
|
||||
private async doSync(): Promise<void> {
|
||||
try {
|
||||
const cloned = await exists(join(this.dir, ".git"));
|
||||
if (!cloned) {
|
||||
await fs.mkdir(this.dir, { recursive: true });
|
||||
await run("git", ["clone", "--quiet", "--depth", "50", this.url, this.dir]);
|
||||
} else {
|
||||
// The checkout is the mesh's, so a local change is nobody's: reset to what the forge has,
|
||||
// rather than merging into something a hand may have touched.
|
||||
await run("git", ["-C", this.dir, "fetch", "--quiet", "--depth", "50", "origin"]);
|
||||
await run("git", ["-C", this.dir, "reset", "--quiet", "--hard", "origin/HEAD"]);
|
||||
}
|
||||
this.fetched = new Date().toISOString();
|
||||
this.lastError = undefined;
|
||||
} catch (e) {
|
||||
this.lastError = e instanceof Error ? e.message : String(e);
|
||||
console.error(`[records] could not sync ${this.url}: ${this.lastError}`);
|
||||
}
|
||||
}
|
||||
|
||||
async standing(): Promise<Standing> {
|
||||
let commit = "";
|
||||
let committed = "";
|
||||
if (await exists(join(this.dir, ".git"))) {
|
||||
try {
|
||||
commit = (await run("git", ["-C", this.dir, "rev-parse", "HEAD"])).stdout.trim();
|
||||
committed = (await run("git", ["-C", this.dir, "log", "-1", "--format=%cI"])).stdout.trim();
|
||||
} catch {
|
||||
// A checkout without a commit yet: said as empty rather than thrown.
|
||||
}
|
||||
}
|
||||
const documents = commit ? (await this.documents()).length : 0;
|
||||
return {
|
||||
repository: this.repository,
|
||||
origin: this.origin,
|
||||
commit,
|
||||
committed,
|
||||
fetched: this.fetched,
|
||||
documents,
|
||||
...(this.lastError ? { lastError: this.lastError } : {}),
|
||||
};
|
||||
}
|
||||
|
||||
/** Every markdown document, relative to the root, in a stable order. */
|
||||
async documents(): Promise<string[]> {
|
||||
const out: string[] = [];
|
||||
const walk = async (at: string): Promise<void> => {
|
||||
let entries: import("node:fs").Dirent[];
|
||||
try {
|
||||
entries = await fs.readdir(at, { withFileTypes: true });
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
for (const e of entries) {
|
||||
if (e.name === ".git" || e.name === "node_modules") continue;
|
||||
const full = join(at, e.name);
|
||||
if (e.isDirectory()) await walk(full);
|
||||
else if (e.isFile() && e.name.endsWith(".md")) out.push(relative(this.dir, full).split(sep).join("/"));
|
||||
}
|
||||
};
|
||||
await walk(this.dir);
|
||||
return out.sort();
|
||||
}
|
||||
|
||||
/**
|
||||
* Where a phrase appears, case-insensitively, as written — no stemming, no ranking, because a
|
||||
* design record is found by its own words and a reader deciding which words matter would be a
|
||||
* second opinion about somebody else's document. Bounded, and says when it was.
|
||||
*
|
||||
* **The record is wrapped prose, and a phrase does not know where the line ends.** Every document
|
||||
* here wraps at a hundred columns, so a phrase of six words is as likely to straddle a line break
|
||||
* as not; matched line by line, the first live search for a sentence of ADR 0025 found nothing.
|
||||
* So a line is matched together with the one after it, joined by a space, and emphasis marks
|
||||
* are ignored — `**reachable**` is the word reachable. A hit still names the line it starts on.
|
||||
*/
|
||||
async search(query: string, limit = MOST_HITS): Promise<{ hits: Hit[]; more: boolean; commit: string }> {
|
||||
const needle = plain(query).toLowerCase().replace(/\s+/g, " ").trim();
|
||||
if (!needle) throw new Error("search for a phrase; an empty one matches every line of every document");
|
||||
const cap = Math.max(1, Math.min(limit, MOST_HITS));
|
||||
const hits: Hit[] = [];
|
||||
let more = false;
|
||||
for (const path of await this.documents()) {
|
||||
const text = await fs.readFile(join(this.dir, path), "utf8");
|
||||
let heading = "";
|
||||
const lines = text.split("\n");
|
||||
const flat = lines.map((l) => plain(l).toLowerCase().replace(/\s+/g, " ").trim());
|
||||
for (let i = 0; i < lines.length; i++) {
|
||||
const line = lines[i]!;
|
||||
if (/^#{1,6}\s/.test(line)) heading = line.replace(/^#+\s*/, "").trim();
|
||||
const here = flat[i]!;
|
||||
const next = i + 1 < flat.length ? flat[i + 1]! : "";
|
||||
// On this line, or across the break into the next — but not a phrase that begins on the
|
||||
// next line alone, which is that line's hit.
|
||||
const onThis = here.includes(needle);
|
||||
const acrossTheBreak = !onThis && next !== "" && `${here} ${next}`.includes(needle) && !next.includes(needle);
|
||||
if (onThis || acrossTheBreak) {
|
||||
if (hits.length >= cap) {
|
||||
more = true;
|
||||
break;
|
||||
}
|
||||
hits.push({ path, line: i + 1, heading, text: acrossTheBreak ? `${line.trim()} ${lines[i + 1]!.trim()}` : line.trim() });
|
||||
}
|
||||
}
|
||||
if (more) break;
|
||||
}
|
||||
const commit = (await this.standing()).commit;
|
||||
return { hits, more, commit };
|
||||
}
|
||||
|
||||
/** One document, whole, or its first part with a note when it is very long. The path is kept
|
||||
* inside the checkout: `..` and absolute paths are refused, not resolved. */
|
||||
async read(path: string): Promise<{ path: string; content: string; truncated: boolean; commit: string }> {
|
||||
const clean = normalize(path).split(sep).join("/");
|
||||
if (!clean || clean.startsWith("..") || clean.startsWith("/") || clean.includes("/../")) {
|
||||
throw new Error(`"${path}" is not a path inside the repository`);
|
||||
}
|
||||
let content: string;
|
||||
try {
|
||||
content = await fs.readFile(join(this.dir, clean), "utf8");
|
||||
} catch {
|
||||
throw new Error(`the repository holds no ${clean} — \`records_list\` says what it holds`);
|
||||
}
|
||||
const truncated = content.length > MOST_BYTES;
|
||||
return {
|
||||
path: clean,
|
||||
content: truncated ? content.slice(0, MOST_BYTES) + "\n\n[… truncated; the document is longer than this answer carries]" : content,
|
||||
truncated,
|
||||
commit: (await this.standing()).commit,
|
||||
};
|
||||
}
|
||||
|
||||
/** What a folder holds: its sub-folders and its documents, one level. */
|
||||
async list(folder = ""): Promise<{ folder: string; folders: string[]; documents: string[] }> {
|
||||
const clean = normalize(folder || ".").split(sep).join("/").replace(/^\.\/?/, "");
|
||||
if (clean.startsWith("..") || clean.startsWith("/")) {
|
||||
throw new Error(`"${folder}" is not a folder inside the repository`);
|
||||
}
|
||||
const at = clean ? join(this.dir, clean) : this.dir;
|
||||
let entries: import("node:fs").Dirent[];
|
||||
try {
|
||||
entries = await fs.readdir(at, { withFileTypes: true });
|
||||
} catch {
|
||||
throw new Error(`the repository holds no folder ${clean || "/"}`);
|
||||
}
|
||||
const folders = entries.filter((e) => e.isDirectory() && e.name !== ".git" && e.name !== "node_modules").map((e) => e.name).sort();
|
||||
const documents = entries.filter((e) => e.isFile() && e.name.endsWith(".md")).map((e) => e.name).sort();
|
||||
return { folder: clean, folders, documents };
|
||||
}
|
||||
}
|
||||
|
||||
/** The reader as the mesh configures it: the directory it was given, the forge it was bound to, and
|
||||
* the repository its settings name. Refuses to guess any of the three (novox/hq ADR 0112). */
|
||||
export async function recordsFromEnv(env: NodeJS.ProcessEnv = process.env): Promise<Records> {
|
||||
const dir = env.MESH_RECORDS_DIR;
|
||||
if (!dir) throw new Error("MESH_RECORDS_DIR is unset: the mesh gives this module the directory its checkout lives in");
|
||||
const originFile = env.MESH_RECORDS_ORIGIN_FILE;
|
||||
if (!originFile) throw new Error("MESH_RECORDS_ORIGIN_FILE is unset: the forge's address comes from the git provision's binding");
|
||||
const origin = (await fs.readFile(originFile, "utf8")).trim();
|
||||
if (!origin) throw new Error(`${originFile} is empty: the git provision has not been bound yet`);
|
||||
const configFile = env.MESH_RECORDS_CONFIG_FILE;
|
||||
if (!configFile) throw new Error("MESH_RECORDS_CONFIG_FILE is unset");
|
||||
let config: { repository?: unknown } = {};
|
||||
try {
|
||||
config = JSON.parse(await fs.readFile(configFile, "utf8")) as { repository?: unknown };
|
||||
} catch (e) {
|
||||
throw new Error(`${configFile} is not JSON: ${e instanceof Error ? e.message : String(e)}`);
|
||||
}
|
||||
const repository = typeof config.repository === "string" ? config.repository.trim() : "";
|
||||
if (!/^[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+$/.test(repository)) {
|
||||
throw new Error(
|
||||
"this module reads the repository its settings name, and none is set: " +
|
||||
'`settings set records <file>` with {"repository": "<owner>/<name>"} — a module names no mesh (novox/hq ADR 0112)',
|
||||
);
|
||||
}
|
||||
return new Records(dir, origin, repository);
|
||||
}
|
||||
|
||||
/** A line without its markdown emphasis, so a phrase matches the words and not the marks. */
|
||||
function plain(line: string): string {
|
||||
return line.replace(/[*_`]/g, "");
|
||||
}
|
||||
|
||||
async function exists(path: string): Promise<boolean> {
|
||||
try {
|
||||
await fs.stat(path);
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -1,87 +0,0 @@
|
||||
/**
|
||||
* The reader against a real repository: a checkout, a phrase found where it is written, a document
|
||||
* read whole, a merge pulled — and the check novox/hq ADR 0025 names: search for a phrase that appears
|
||||
* only in one design document, and get it back.
|
||||
*/
|
||||
import assert from "node:assert/strict";
|
||||
import { test } from "node:test";
|
||||
import { execFileSync } from "node:child_process";
|
||||
import { mkdtempSync, mkdirSync, writeFileSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
|
||||
import { Records } from "../records.ts";
|
||||
|
||||
function aRepository(): string {
|
||||
const dir = mkdtempSync("/tmp/records-origin-");
|
||||
const git = (...args: string[]) => execFileSync("git", ["-C", dir, ...args], { stdio: "pipe" });
|
||||
git("init", "--quiet", "--initial-branch=main");
|
||||
git("config", "user.email", "t@example.invalid");
|
||||
git("config", "user.name", "t");
|
||||
mkdirSync(join(dir, "02-DECISIONS"));
|
||||
mkdirSync(join(dir, "03-DESIGN"));
|
||||
writeFileSync(join(dir, "README.md"), "# A repository\n\nWhat this is.\n");
|
||||
writeFileSync(join(dir, "02-DECISIONS/0001-a-decision.md"), "# 1. A decision\n\n## Context\n\nThe context.\n\n## Decision\n\nWe decided the thing.\n");
|
||||
writeFileSync(join(dir, "03-DESIGN/07-knowledge.md"), "# Knowledge\n\n## The stores\n\nSilence and success must never look alike.\n\nA phrase that is wrapped at the\ncolumn where every document wraps, and **reachable is not the same as\nsurfacing** under emphasis.\n");
|
||||
git("add", "-A");
|
||||
git("commit", "--quiet", "-m", "first");
|
||||
return dir;
|
||||
}
|
||||
|
||||
test("a phrase that appears in one design document comes back from where it is written", async () => {
|
||||
const origin = aRepository();
|
||||
const records = new Records(mkdtempSync("/tmp/records-checkout-"), "file://" + origin.replace(/\/[^/]+$/, ""), origin.split("/").pop()!);
|
||||
// A file:// origin has no `.git` suffix; point the clone at the directory itself.
|
||||
Object.defineProperty(records, "url", { get: () => origin });
|
||||
await records.sync();
|
||||
const found = await records.search("never look alike");
|
||||
assert.equal(found.hits.length, 1);
|
||||
assert.equal(found.hits[0]!.path, "03-DESIGN/07-knowledge.md");
|
||||
assert.equal(found.hits[0]!.heading, "The stores");
|
||||
assert.match(found.commit, /^[0-9a-f]{40}$/, "the answer names the commit it was read at");
|
||||
|
||||
// Wrapped prose: a phrase across the line break is found, once, at the line it starts on; and
|
||||
// emphasis marks are not part of the words.
|
||||
const wrapped = await records.search("wrapped at the column where");
|
||||
assert.deepEqual(wrapped.hits.map((h) => [h.path, h.line]), [["03-DESIGN/07-knowledge.md", 7]]);
|
||||
const emphasised = await records.search("reachable is not the same as surfacing");
|
||||
assert.deepEqual(emphasised.hits.map((h) => [h.path, h.line]), [["03-DESIGN/07-knowledge.md", 8]]);
|
||||
const alsoOnOneLine = await records.search("under emphasis");
|
||||
assert.equal(alsoOnOneLine.hits.length, 1, "a phrase on one line is not also counted from the line before it");
|
||||
|
||||
const doc = await records.read("02-DECISIONS/0001-a-decision.md");
|
||||
assert.match(doc.content, /We decided the thing/);
|
||||
assert.equal(doc.truncated, false);
|
||||
|
||||
const root = await records.list();
|
||||
assert.deepEqual(root.folders, ["02-DECISIONS", "03-DESIGN"]);
|
||||
assert.deepEqual(root.documents, ["README.md"]);
|
||||
|
||||
const standing = await records.standing();
|
||||
assert.equal(standing.documents, 3);
|
||||
assert.equal(standing.lastError, undefined);
|
||||
|
||||
// A merge on the origin, pulled: the checkout follows the source and names the new commit.
|
||||
writeFileSync(join(origin, "02-DECISIONS/0002-another.md"), "# 2. Another\n\nA phrase nobody wrote before.\n");
|
||||
execFileSync("git", ["-C", origin, "add", "-A"], { stdio: "pipe" });
|
||||
execFileSync("git", ["-C", origin, "commit", "--quiet", "-m", "second"], { stdio: "pipe" });
|
||||
await records.sync();
|
||||
const after = await records.search("nobody wrote before");
|
||||
assert.equal(after.hits.length, 1);
|
||||
assert.notEqual(after.commit, found.commit);
|
||||
});
|
||||
|
||||
test("a path outside the repository is refused, and an empty search is too", async () => {
|
||||
const records = new Records(mkdtempSync("/tmp/records-checkout-"), "http://forge.invalid:3000", "novox/hq");
|
||||
await assert.rejects(() => records.read("../etc/passwd"), /not a path inside/);
|
||||
await assert.rejects(() => records.read("/etc/passwd"), /not a path inside/);
|
||||
await assert.rejects(() => records.search(" "), /empty one/);
|
||||
assert.equal(records.url, "http://forge.invalid:3000/novox/hq.git");
|
||||
});
|
||||
|
||||
test("a sync that fails leaves the checkout standing and says why", async () => {
|
||||
const records = new Records(mkdtempSync("/tmp/records-checkout-"), "http://127.0.0.1:1", "novox/hq");
|
||||
await records.sync();
|
||||
const standing = await records.standing();
|
||||
assert.equal(standing.commit, "");
|
||||
assert.ok(standing.lastError, "a failed sync is said, not swallowed");
|
||||
});
|
||||
@@ -1,62 +0,0 @@
|
||||
// records' tools — how the record is asked (novox/hq ADR 0025, ADR 0153).
|
||||
//
|
||||
// Five questions, each answered from the checkout at the commit it names: where does a phrase
|
||||
// appear, what does one document say, what does a folder hold, where does the checkout stand, and
|
||||
// bring it up to date now. The reasoning stays in the documents; the tools only find them.
|
||||
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
||||
import { recordsFromEnv, type Records } from "../records.js";
|
||||
|
||||
export function getRecordsTools(records: Records): ToolDefinition[] {
|
||||
return [
|
||||
{
|
||||
name: "records_search",
|
||||
description:
|
||||
"Where a phrase appears in the decisions, designs and issues, as written: document, line, nearest heading. " +
|
||||
"Search the literal words of a symptom or a term before forming a hypothesis; the answer names the commit it was read at.",
|
||||
input: {
|
||||
query: { type: "string", description: "the phrase, matched case-insensitively as written" },
|
||||
limit: { type: "number", description: "at most this many places (default 50)" },
|
||||
},
|
||||
run: async (args) => records.search(String(args.query ?? ""), args.limit ? Number(args.limit) : undefined),
|
||||
},
|
||||
{
|
||||
name: "records_read",
|
||||
description: "One document, whole, by its path in the repository — a decision record, a design document, an issue report.",
|
||||
input: { path: { type: "string", description: "the document's path, e.g. 02-DECISIONS/0025-....md" } },
|
||||
run: async (args) => records.read(String(args.path ?? "")),
|
||||
},
|
||||
{
|
||||
name: "records_list",
|
||||
description: "What a folder of the repository holds: its sub-folders and its documents. The root when no folder is named.",
|
||||
input: { folder: { type: "string", description: "a folder inside the repository (optional)" } },
|
||||
run: async (args) => records.list(args.folder ? String(args.folder) : ""),
|
||||
},
|
||||
{
|
||||
name: "records_status",
|
||||
description: "Where the checkout stands: the repository, the forge it is read from, the commit and its date, when it was last brought up to date.",
|
||||
input: {},
|
||||
run: async () => records.standing(),
|
||||
},
|
||||
{
|
||||
name: "records_sync",
|
||||
description: "Bring the checkout up to date now, and say where it stands.",
|
||||
input: {},
|
||||
run: async () => {
|
||||
await records.sync();
|
||||
return records.standing();
|
||||
},
|
||||
},
|
||||
];
|
||||
}
|
||||
|
||||
// The reader is made once, at load, from the environment the runtime resolves; the contributor is
|
||||
// synchronous and is called at every collection. Without a repository to read there is nothing to
|
||||
// answer, and the module exposes no tools rather than five that fail — the sdk's contract: a
|
||||
// contributor returning [] is normal.
|
||||
let reader: Records | null = null;
|
||||
try {
|
||||
reader = await recordsFromEnv();
|
||||
} catch (err) {
|
||||
console.log(`[records] no tools — ${err instanceof Error ? err.message : String(err)}`);
|
||||
}
|
||||
registerModuleTools("records", () => (reader ? getRecordsTools(reader) : []));
|
||||
@@ -1,12 +0,0 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
"target": "ES2022",
|
||||
"module": "NodeNext",
|
||||
"moduleResolution": "NodeNext",
|
||||
"strict": true,
|
||||
"esModuleInterop": true,
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": ["records.ts", "index.ts", "tools/index.ts"]
|
||||
}
|
||||
+16
-14
@@ -27,13 +27,13 @@
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"redis-cache": "${dir:grants}/mesh.json"
|
||||
"redis-cache": "/var/lib/redis-module/grants/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"redis-cache": "${dir:grants}"
|
||||
"redis-cache": "/var/lib/redis-module/grants"
|
||||
},
|
||||
"secrets": {
|
||||
"secret": "${dir:state}/default.secret"
|
||||
"secret": "/var/lib/redis-module/default.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/redis/broker"
|
||||
@@ -57,27 +57,29 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/redis-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"id": "grants-dir",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/redis-module/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/redis/data",
|
||||
"mode": "0700",
|
||||
"owner": "999:1000"
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "server-conf",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/redis.conf",
|
||||
"path": "/var/lib/redis-module/redis.conf",
|
||||
"mode": "0600",
|
||||
"content": "requirepass ${secret:secret}\nappendonly yes\ndir /data\n",
|
||||
"owner": "999:1000"
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
@@ -88,14 +90,14 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "redis",
|
||||
"image": "redis@sha256:520775a41a63e77e06c73e35d2fd9cc15921a609516818796b4ecbb813078bc7",
|
||||
"image": "redis@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf",
|
||||
"network": "redis",
|
||||
"ports": [
|
||||
"6379"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/data",
|
||||
"${dir:state}/redis.conf:/etc/redis/redis.conf:ro"
|
||||
"/services/redis/data:/data",
|
||||
"/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro"
|
||||
],
|
||||
"args": [
|
||||
"/etc/redis/redis.conf"
|
||||
@@ -111,8 +113,8 @@
|
||||
"network": "redis",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/redis/broker:/run/secrets/broker:ro",
|
||||
"${dir:grants}:/var/lib/redis-module/grants:ro",
|
||||
"${dir:state}/default.secret:/run/secrets/default:ro"
|
||||
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
|
||||
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
|
||||
@@ -162,8 +162,7 @@
|
||||
"kind": "image",
|
||||
"from": "Dockerfile",
|
||||
"context": {
|
||||
"seat": "git",
|
||||
"repository": "novox/mesh-controller",
|
||||
"repository": "https://git.novox.be/novox/mesh-controller.git",
|
||||
"ref": "main"
|
||||
}
|
||||
},
|
||||
|
||||
@@ -100,7 +100,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_SEARXNG_URL": "http://127.0.0.1:8080",
|
||||
"MESH_SEARXNG_URL": "http://127.0.0.1:${port:8080}",
|
||||
"MESH_SEARXNG_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
|
||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/sonarr
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts downloads/settings.ts downloads/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
@@ -22,3 +22,6 @@ COPY --from=build /app/modules/sonarr/dist /app/modules/sonarr/dist
|
||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||
# the convention novox/hq issues 060/061 settled.
|
||||
ENV MESH_TOOL_MODULES=/app/modules/sonarr/dist/index.js,/app/modules/sonarr/dist/tools/index.js
|
||||
# NOT dist/downloads/index.js: that is a step the host runs to completion, named by the `downloads`
|
||||
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
||||
# serving sidecar too, and exit it.
|
||||
|
||||
@@ -0,0 +1,188 @@
|
||||
// The downloads step — run once by the host after the app's server starts, and again whenever a
|
||||
// binding, a pair credential or the step's settings change (the container's `restart-on`,
|
||||
// novox/hq ADR 0099). Byte-identical in sonarr, radarr, lidarr and bookshelf; see settings.ts.
|
||||
//
|
||||
// **A step, not a loop**: everything it does is a function of files the mesh writes, and the host
|
||||
// already knows when they change. It connects to no broker.
|
||||
//
|
||||
// Exits non-zero when anything could not be put right — a refused credential, an unreachable
|
||||
// provider, an entry the app would not save — so the node reports the step failed and the host
|
||||
// runs it again on the next apply. Declared last in the manifest, so its failing gates nothing
|
||||
// else of the module's (novox/hq ADR 0136).
|
||||
//
|
||||
// Reads, in MESH_DOWNLOADS_DIR, `<provision>.json` (the binding), `<provision>.secret` (the pair
|
||||
// credential) and the settings file; remembers in MESH_DOWNLOADS_MEMORY the jackett hosts it has
|
||||
// pointed feeds at, so a jackett that moves takes its feeds with it. Never prints a credential.
|
||||
|
||||
import { mkdir, rename, writeFile } from "node:fs/promises";
|
||||
import { dirname, join } from "node:path";
|
||||
|
||||
import {
|
||||
CLIENTS,
|
||||
JACKETT,
|
||||
acceptRemedy,
|
||||
appConfig,
|
||||
appReady,
|
||||
listEntries,
|
||||
providerTakes,
|
||||
readIfThere,
|
||||
readJson,
|
||||
reconcileClient,
|
||||
reconcileIndexers,
|
||||
scrub,
|
||||
stepSettings,
|
||||
wanted,
|
||||
type App,
|
||||
type Binding,
|
||||
type Http,
|
||||
type Entry,
|
||||
type Outcome,
|
||||
type Took,
|
||||
} from "./settings.js";
|
||||
|
||||
const module = process.env.MESH_DOWNLOADS_APP ?? "app";
|
||||
const dir = process.env.MESH_DOWNLOADS_DIR ?? "/run/downloads";
|
||||
const settingsFile = process.env.MESH_DOWNLOADS_SETTINGS ?? join(dir, "downloads.json");
|
||||
const memoryFile = process.env.MESH_DOWNLOADS_MEMORY ?? "/var/lib/downloads/memory.json";
|
||||
const waitSeconds = Number(process.env.MESH_DOWNLOADS_WAIT_SECONDS ?? "180");
|
||||
const tag = `[${module}-downloads]`;
|
||||
|
||||
const http: Http = { fetch: (u, init) => fetch(u, init) };
|
||||
const secrets: string[] = [];
|
||||
const say = (line: string) => console.log(scrub(`${tag} ${line}`, secrets));
|
||||
const fail = (line: string) => console.error(scrub(`${tag} ${line}`, secrets));
|
||||
|
||||
const config = appConfig((await readIfThere(process.env.MESH_DOWNLOADS_APP_CONFIG)) ?? "");
|
||||
if (!config.apiKey) {
|
||||
fail(`no API key in ${module}'s config.xml yet — ${module} writes it on its first start; the step runs again on the next apply`);
|
||||
process.exit(1);
|
||||
}
|
||||
secrets.push(config.apiKey);
|
||||
const app: App = {
|
||||
module,
|
||||
url: `${(process.env.MESH_DOWNLOADS_APP_URL ?? "http://127.0.0.1").replace(/\/$/, "")}${config.urlBase}`,
|
||||
apiKey: config.apiKey,
|
||||
api: process.env.MESH_DOWNLOADS_API ?? "v3",
|
||||
};
|
||||
const settings = stepSettings(await readJson(settingsFile));
|
||||
|
||||
if (!(await appReady(http, app, waitSeconds * 1000))) {
|
||||
fail(`${module} did not answer at ${app.url} within ${waitSeconds}s`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
const outcomes: Outcome[] = [];
|
||||
|
||||
// The download clients.
|
||||
let clients: Entry[];
|
||||
try {
|
||||
clients = await listEntries(http, app, "downloadclient");
|
||||
} catch (err) {
|
||||
fail(err instanceof Error ? err.message : String(err));
|
||||
process.exit(1);
|
||||
}
|
||||
for (const kind of CLIENTS) {
|
||||
const credential = await readIfThere(join(dir, `${kind.provision}.secret`));
|
||||
if (credential) secrets.push(credential.trim());
|
||||
const w = wanted(kind.provision, (await readJson(join(dir, `${kind.provision}.json`))) as Binding | undefined, credential, true);
|
||||
// `in`, not `!w.ok`: the Dockerfile compiles without strict, where a boolean discriminant does not
|
||||
// narrow.
|
||||
if ("problem" in w) {
|
||||
outcomes.push({ what: kind.provision, result: "refused", problem: w.problem });
|
||||
continue;
|
||||
}
|
||||
const ep = w.endpoint;
|
||||
try {
|
||||
if (!(await providerTakes(http, kind.provision, ep)).took) {
|
||||
outcomes.push({
|
||||
what: kind.provision,
|
||||
result: "refused",
|
||||
problem: acceptRemedy(app, settings.node, kind.provision, kind.provider, kind.secretName, ep.from),
|
||||
});
|
||||
continue;
|
||||
}
|
||||
} catch (err) {
|
||||
outcomes.push({
|
||||
what: kind.provision,
|
||||
result: "refused",
|
||||
problem: `${kind.provider} could not be asked whether it takes the credential at ${ep.host}:${ep.port}: ${err instanceof Error ? err.message : String(err)}`,
|
||||
});
|
||||
continue;
|
||||
}
|
||||
outcomes.push(...(await reconcileClient(http, app, kind, settings.names[kind.provision], ep, clients)));
|
||||
}
|
||||
|
||||
// The indexers, through jackett.
|
||||
{
|
||||
const credential = await readIfThere(join(dir, `${JACKETT}.secret`));
|
||||
if (credential) secrets.push(credential.trim());
|
||||
const w = wanted(JACKETT, (await readJson(join(dir, `${JACKETT}.json`))) as Binding | undefined, credential, false);
|
||||
if ("problem" in w) {
|
||||
outcomes.push({ what: JACKETT, result: "refused", problem: w.problem });
|
||||
} else {
|
||||
const ep = w.endpoint;
|
||||
let took: Took | undefined;
|
||||
try {
|
||||
took = await providerTakes(http, JACKETT, ep);
|
||||
} catch (err) {
|
||||
outcomes.push({
|
||||
what: JACKETT,
|
||||
result: "refused",
|
||||
problem: `jackett could not be asked whether it takes the key at ${ep.host}:${ep.port}: ${err instanceof Error ? err.message : String(err)}`,
|
||||
});
|
||||
}
|
||||
if (took && !took.took) {
|
||||
outcomes.push({ what: JACKETT, result: "refused", problem: acceptRemedy(app, settings.node, JACKETT, "jackett", "API key", ep.from) });
|
||||
} else if (took) {
|
||||
const memory = ((await readJson(memoryFile)) ?? {}) as Record<string, { hosts?: string[] } | undefined>;
|
||||
const remembered = Array.isArray(memory[JACKETT]?.hosts) ? (memory[JACKETT]?.hosts as string[]) : [];
|
||||
try {
|
||||
const indexers = await listEntries(http, app, "indexer");
|
||||
outcomes.push(
|
||||
...(await reconcileIndexers(http, app, ep, took.configured ?? new Map(), settings.indexers, remembered, indexers)),
|
||||
);
|
||||
} catch (err) {
|
||||
outcomes.push({ what: JACKETT, result: "refused", problem: err instanceof Error ? err.message : String(err) });
|
||||
}
|
||||
// Remember where the feeds now point, so they are still recognised as the mesh's if jackett
|
||||
// moves. Written whole and renamed, so a crash leaves the old memory, never half of one.
|
||||
const hosts = [...new Set([...remembered, ep.host.toLowerCase()])].sort();
|
||||
if (hosts.join() !== [...remembered].sort().join()) {
|
||||
try {
|
||||
await mkdir(dirname(memoryFile), { recursive: true });
|
||||
await writeFile(`${memoryFile}.tmp`, JSON.stringify({ ...memory, [JACKETT]: { hosts } }, null, 2) + "\n", { mode: 0o600 });
|
||||
await rename(`${memoryFile}.tmp`, memoryFile);
|
||||
} catch (err) {
|
||||
outcomes.push({
|
||||
what: JACKETT,
|
||||
result: "notice",
|
||||
note: `could not remember ${ep.host} as a jackett host (${err instanceof Error ? err.message : String(err)}); if jackett moves, list it in downloads.jackett-api.adopt-hosts`,
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let failed = 0;
|
||||
for (const o of outcomes) {
|
||||
switch (o.result) {
|
||||
case "unchanged":
|
||||
say(`${o.what}: already as the mesh says${o.untested ? "" : "; connection tested"}`);
|
||||
break;
|
||||
case "written":
|
||||
say(`${o.what}: wrote ${o.fields.join(", ")}${o.untested ? "" : "; connection tested"}`);
|
||||
break;
|
||||
case "created":
|
||||
say(`${o.what}: registered; connection tested`);
|
||||
break;
|
||||
case "notice":
|
||||
say(`${o.what}: ${o.note}`);
|
||||
break;
|
||||
case "refused":
|
||||
failed++;
|
||||
fail(`${o.what}: ${o.problem}`);
|
||||
break;
|
||||
}
|
||||
}
|
||||
process.exitCode = failed > 0 ? 1 : 0;
|
||||
@@ -0,0 +1,778 @@
|
||||
// Where a Servarr app reaches its download clients and its indexer proxy — decided by the mesh,
|
||||
// written into the app by the app's own API.
|
||||
//
|
||||
// **One file, four copies.** sonarr, radarr, lidarr and bookshelf (a Readarr fork) keep their
|
||||
// download clients and indexers behind the same API — `/api/v3/…` for the first two, `/api/v1/…`
|
||||
// for the others — so this step is the same code in each. Each module builds from its own
|
||||
// directory (novox/hq ADR 0069), so each carries a byte-identical copy under `downloads/`;
|
||||
// `test/downloads.test.ts` checks the copies agree wherever the siblings are checked out beside
|
||||
// it. Change all four together.
|
||||
//
|
||||
// **Why this exists.** The app keeps its connection to nzbget, qBittorrent and jackett in its own
|
||||
// database, not in a file, so the mesh has nowhere to write `${bound:nzbget-api:at}` for it. The
|
||||
// module requires `nzbget-api`, `qbittorrent-api` and `jackett-api`; the mesh delivers, for each,
|
||||
// a binding (where the provider is — `at` — and what it serves: `port`, `scheme`, `url-base`, and
|
||||
// for a download client the `username`) and a pair credential (nzbget's ControlPassword,
|
||||
// qBittorrent's WebUI password, jackett's API key — each the provider's one and only, accepted by
|
||||
// the operator per pair; the mesh cannot mint them). This step reads those files and makes the
|
||||
// app's entries say the same thing.
|
||||
//
|
||||
// **Which entries are the mesh's.** Never a guess from what an entry looks like:
|
||||
// - a download client is the mesh's when its name is the one the module's settings give for
|
||||
// that provision (`downloads.<provision>.name`) and its kind is that provider's. On a fresh
|
||||
// machine the step registers it under that name; on a migrated one the assignment names the
|
||||
// entry the migration adopts ("NZBGet" on ace).
|
||||
// - a Torznab indexer is the mesh's when it reads a jackett feed
|
||||
// (`…/api/v2.0/indexers/<id>/results/torznab`) on a host the mesh put there — the bound `at`,
|
||||
// one it bound before (remembered by the step), or one the settings adopt
|
||||
// (`downloads.jackett-api.adopt-hosts`, which is how a migration names the entries that pointed
|
||||
// at the old container). `downloads.jackett-api.indexers` lists the jackett indexers the app
|
||||
// should have; one missing is registered.
|
||||
// Everything else — every entry a person made, an nzbget elsewhere, a seedbox's jackett, a Newznab
|
||||
// indexer — is left exactly as it is. **Nothing is ever deleted.**
|
||||
//
|
||||
// **Only the connection, and only when it differs.** Host, port, TLS, base path, user name and
|
||||
// the credential. Categories, priorities, "enabled", seed criteria and every other choice made in
|
||||
// the app are left alone. The stored credential cannot be read back (the app masks it), so the
|
||||
// step asks the app to test the entry with the mesh's host and port and the credential it already
|
||||
// holds: passing, the credential is already the provider's one and only; failing, the delivered
|
||||
// credential is written.
|
||||
//
|
||||
// **A credential the provider refuses is never written.** Until the operator accepts the
|
||||
// provider's secret for this pair, the mesh delivers a value it minted itself, which no provider
|
||||
// will ever accept (novox/hq ADR 0092). Writing it would replace a working password with a dead
|
||||
// one. So it is tried against the provider first; refused, nothing of that provision is written
|
||||
// and the step fails naming the `secret accept` that fixes it.
|
||||
//
|
||||
// Pure logic and a small HTTP seam, so it is tested against fake servers (test/downloads.test.ts).
|
||||
// Never prints a credential, an API key, or a URL carrying one.
|
||||
|
||||
import { readFile } from "node:fs/promises";
|
||||
|
||||
/** A download-client provision and the shape of its entry in the app. */
|
||||
export interface ClientKind {
|
||||
provision: "nzbget-api" | "qbittorrent-api";
|
||||
/** The app's `implementation` for it. */
|
||||
implementation: "Nzbget" | "QBittorrent";
|
||||
/** The provider, as a person calls it. */
|
||||
provider: string;
|
||||
/** What the pair credential is, in the provider's words. */
|
||||
secretName: string;
|
||||
}
|
||||
|
||||
export const CLIENTS: readonly ClientKind[] = [
|
||||
{ provision: "nzbget-api", implementation: "Nzbget", provider: "nzbget", secretName: "ControlPassword" },
|
||||
{ provision: "qbittorrent-api", implementation: "QBittorrent", provider: "qBittorrent", secretName: "WebUI password" },
|
||||
];
|
||||
|
||||
export const JACKETT = "jackett-api";
|
||||
|
||||
/** What the mesh wrote at `binds.<provision>`: the binding document. */
|
||||
export interface Binding {
|
||||
provision?: string;
|
||||
from?: string;
|
||||
at?: string;
|
||||
as?: string;
|
||||
serves?: Record<string, unknown>;
|
||||
}
|
||||
|
||||
/** Where a provider is, as the mesh bound it, and the credential for it. */
|
||||
export interface Endpoint {
|
||||
scheme: "http" | "https";
|
||||
host: string;
|
||||
port: number;
|
||||
/** "" at the root, otherwise "/base" — one leading slash, none trailing. */
|
||||
urlBase: string;
|
||||
/** The user a download client logs in as; "" for jackett, which takes a key. */
|
||||
username: string;
|
||||
credential: string;
|
||||
/** The provider's node, for the `secret accept` remedy. */
|
||||
from: string;
|
||||
}
|
||||
|
||||
export type Wanted = { ok: true; endpoint: Endpoint } | { ok: false; problem: string };
|
||||
|
||||
/**
|
||||
* The endpoint the mesh says to use, from a binding and its pair credential.
|
||||
*
|
||||
* Refused rather than guessed when the binding cannot be dialled from the app's own container: a
|
||||
* loopback `at` — what the mesh hands a machine that is not on the private network — is the app's
|
||||
* container itself.
|
||||
*/
|
||||
export function wanted(
|
||||
provision: string,
|
||||
binding: Binding | undefined,
|
||||
credential: string | undefined,
|
||||
needsUser: boolean,
|
||||
): Wanted {
|
||||
if (!binding) {
|
||||
return { ok: false, problem: `no binding for ${provision} was delivered — the mesh writes it before this step runs` };
|
||||
}
|
||||
const host = typeof binding.at === "string" ? binding.at.trim() : "";
|
||||
const serves = binding.serves ?? {};
|
||||
const port = Number(serves.port);
|
||||
if (!host) return { ok: false, problem: `the ${provision} binding names no host (at)` };
|
||||
if (isLoopback(host)) {
|
||||
return {
|
||||
ok: false,
|
||||
problem:
|
||||
`the ${provision} binding says the provider is at ${host}, which from the app's own container is the ` +
|
||||
`app itself. The mesh hands loopback to a machine that is not on the private network; put it on the ` +
|
||||
`private network so the provider has an address the app can dial`,
|
||||
};
|
||||
}
|
||||
if (!Number.isInteger(port) || port <= 0 || port > 65535) {
|
||||
return { ok: false, problem: `the ${provision} binding serves no usable port (${String(serves.port)})` };
|
||||
}
|
||||
const scheme = typeof serves.scheme === "string" && serves.scheme ? serves.scheme : "http";
|
||||
if (scheme !== "http" && scheme !== "https") {
|
||||
return { ok: false, problem: `the ${provision} binding serves scheme ${scheme}, which the app cannot dial` };
|
||||
}
|
||||
const username = typeof serves.username === "string" ? serves.username.trim() : "";
|
||||
if (needsUser && !username) {
|
||||
return { ok: false, problem: `the ${provision} binding serves no username for the app to log in as` };
|
||||
}
|
||||
const key = (credential ?? "").trim();
|
||||
if (!key) return { ok: false, problem: `the ${provision} credential is empty or was not delivered` };
|
||||
return {
|
||||
ok: true,
|
||||
endpoint: {
|
||||
scheme,
|
||||
host,
|
||||
port,
|
||||
urlBase: normBase(serves["url-base"]),
|
||||
username,
|
||||
credential: key,
|
||||
from: typeof binding.from === "string" ? binding.from : "",
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
/** A URL base as "" or "/x/y": slashes trimmed, one put back in front. */
|
||||
export function normBase(v: unknown): string {
|
||||
const s = typeof v === "string" ? v.trim().replace(/^\/+|\/+$/g, "") : "";
|
||||
return s === "" ? "" : `/${s}`;
|
||||
}
|
||||
|
||||
function isLoopback(host: string): boolean {
|
||||
const h = host.toLowerCase();
|
||||
return h === "localhost" || h === "::1" || h === "[::1]" || /^127\./.test(h);
|
||||
}
|
||||
|
||||
function hostForUrl(host: string): string {
|
||||
return host.includes(":") && !host.startsWith("[") ? `[${host}]` : host;
|
||||
}
|
||||
|
||||
/** The provider's base URL, as the step dials it and as the app is given it. */
|
||||
export function baseUrl(ep: Endpoint): string {
|
||||
return `${ep.scheme}://${hostForUrl(ep.host)}:${ep.port}${ep.urlBase}`;
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// HTTP
|
||||
|
||||
/** The HTTP the step needs, so a test can stand fakes in for the app and the providers. */
|
||||
export interface Http {
|
||||
fetch(
|
||||
url: string,
|
||||
init?: { method?: string; headers?: Record<string, string>; body?: string },
|
||||
): Promise<{ status: number; text(): Promise<string> }>;
|
||||
}
|
||||
|
||||
/** The app, as the step reaches it from the host. */
|
||||
export interface App {
|
||||
/** The module, for messages and the remedy: sonarr, radarr, lidarr, bookshelf. */
|
||||
module: string;
|
||||
/** Its own URL, base path included. */
|
||||
url: string;
|
||||
apiKey: string;
|
||||
/** v3 (sonarr, radarr) or v1 (lidarr, bookshelf). */
|
||||
api: string;
|
||||
}
|
||||
|
||||
interface Answer {
|
||||
status: number;
|
||||
body: unknown;
|
||||
}
|
||||
|
||||
async function appCall(http: Http, app: App, method: string, path: string, body?: unknown): Promise<Answer> {
|
||||
const res = await http.fetch(`${app.url.replace(/\/$/, "")}/api/${app.api}${path}`, {
|
||||
method,
|
||||
headers: {
|
||||
"X-Api-Key": app.apiKey,
|
||||
Accept: "application/json",
|
||||
...(body !== undefined ? { "Content-Type": "application/json" } : {}),
|
||||
},
|
||||
body: body !== undefined ? JSON.stringify(body) : undefined,
|
||||
});
|
||||
const text = await res.text();
|
||||
let parsed: unknown = undefined;
|
||||
if (text) {
|
||||
try {
|
||||
parsed = JSON.parse(text) as unknown;
|
||||
} catch {
|
||||
parsed = text;
|
||||
}
|
||||
}
|
||||
return { status: res.status, body: parsed };
|
||||
}
|
||||
|
||||
async function appGet(http: Http, app: App, path: string): Promise<unknown> {
|
||||
const a = await appCall(http, app, "GET", path);
|
||||
if (a.status < 200 || a.status >= 300) throw new Error(`${app.module} GET ${path} answered ${a.status}`);
|
||||
return a.body;
|
||||
}
|
||||
|
||||
/** One of the app's validation failures: the only parts of an answer the step ever prints. */
|
||||
interface Failure {
|
||||
property: string;
|
||||
message: string;
|
||||
warning: boolean;
|
||||
}
|
||||
|
||||
function failuresOf(body: unknown): Failure[] {
|
||||
const list = Array.isArray(body) ? body : [];
|
||||
return list.map((f) => {
|
||||
const o = (f ?? {}) as Record<string, unknown>;
|
||||
return {
|
||||
property: String(o.propertyName ?? ""),
|
||||
message: String(o.errorMessage ?? ""),
|
||||
warning: o.isWarning === true,
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* One shape rather than a union on `ok`: the Dockerfile compiles without strict, where a boolean
|
||||
* discriminant does not narrow.
|
||||
*/
|
||||
interface Verdict {
|
||||
ok: boolean;
|
||||
/** Warnings the app raised on a pass; errors (and any warnings) on a failure. */
|
||||
failures: Failure[];
|
||||
status: number;
|
||||
saved?: Entry;
|
||||
}
|
||||
|
||||
function verdict(a: Answer): Verdict {
|
||||
if (a.status >= 200 && a.status < 300) return { ok: true, failures: [], status: a.status };
|
||||
const failures = failuresOf(a.body);
|
||||
if (a.status === 400 && failures.length > 0 && failures.every((f) => f.warning)) return { ok: true, failures, status: a.status };
|
||||
return { ok: false, failures, status: a.status };
|
||||
}
|
||||
|
||||
/** The app's own test of an entry, from the app's own container. */
|
||||
async function appTest(http: Http, app: App, resource: string, entry: Entry): Promise<Verdict> {
|
||||
return verdict(await appCall(http, app, "POST", `/${resource}/test`, entry));
|
||||
}
|
||||
|
||||
/**
|
||||
* Save an entry. The app tests an enabled entry before saving it; a test that passes with only
|
||||
* warnings ("a category is recommended") is saved with `forceSave`, the same as pressing "save
|
||||
* anyway" in its screen. An error is never forced.
|
||||
*/
|
||||
async function appSave(http: Http, app: App, resource: string, entry: Entry, create: boolean): Promise<Verdict> {
|
||||
const path = create ? `/${resource}` : `/${resource}/${entry.id}`;
|
||||
const method = create ? "POST" : "PUT";
|
||||
let a = await appCall(http, app, method, path, entry);
|
||||
let v = verdict(a);
|
||||
if (v.ok && (a.status < 200 || a.status >= 300)) {
|
||||
a = await appCall(http, app, method, `${path}?forceSave=true`, entry);
|
||||
v = verdict(a);
|
||||
if (v.ok && (a.status < 200 || a.status >= 300)) {
|
||||
return { ok: false, failures: failuresOf(a.body), status: a.status };
|
||||
}
|
||||
}
|
||||
if (!v.ok) return v;
|
||||
return { ...v, saved: (a.body ?? undefined) as Entry | undefined };
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// Entries
|
||||
|
||||
/** An entry as the app's API gives it: a download client or an indexer. */
|
||||
export interface Entry {
|
||||
id?: number;
|
||||
name?: string;
|
||||
implementation?: string;
|
||||
enable?: boolean;
|
||||
enableRss?: boolean;
|
||||
enableAutomaticSearch?: boolean;
|
||||
enableInteractiveSearch?: boolean;
|
||||
supportsRss?: boolean;
|
||||
supportsSearch?: boolean;
|
||||
fields?: { name: string; value?: unknown; [k: string]: unknown }[];
|
||||
[k: string]: unknown;
|
||||
}
|
||||
|
||||
export function field(e: Entry, name: string): unknown {
|
||||
return e.fields?.find((f) => f.name === name)?.value;
|
||||
}
|
||||
|
||||
/** The entry with these fields' values replaced — added when the app's shape lacks one. */
|
||||
export function withFields(e: Entry, values: Record<string, unknown>): Entry {
|
||||
const fields = (e.fields ?? []).map((f) => (f.name in values ? { ...f, value: values[f.name] } : { ...f }));
|
||||
for (const [name, value] of Object.entries(values)) {
|
||||
if (!fields.some((f) => f.name === name)) fields.push({ name, value });
|
||||
}
|
||||
return { ...e, fields };
|
||||
}
|
||||
|
||||
function enabled(e: Entry): boolean {
|
||||
return e.enable === true || e.enableRss === true || e.enableAutomaticSearch === true || e.enableInteractiveSearch === true;
|
||||
}
|
||||
|
||||
/** What one provision, or one entry of it, came to. */
|
||||
export type Outcome =
|
||||
| { what: string; result: "unchanged"; untested?: boolean }
|
||||
| { what: string; result: "written"; fields: string[]; untested?: boolean }
|
||||
| { what: string; result: "created"; fields: string[] }
|
||||
| { what: string; result: "notice"; note: string }
|
||||
| { what: string; result: "refused"; problem: string };
|
||||
|
||||
function said(fs: Failure[]): string {
|
||||
return fs.length === 0 ? "no reason given" : fs.map((f) => (f.property ? `${f.property}: ${f.message}` : f.message)).join("; ");
|
||||
}
|
||||
|
||||
/**
|
||||
* Bring one of the mesh's entries in line: `connection` is the non-secret fields as the mesh says
|
||||
* them, `differs` which of them the entry does not already say, `secretField` where the credential
|
||||
* goes. Never throws: every failure is an outcome with a reason.
|
||||
*/
|
||||
export async function reconcileEntry(
|
||||
http: Http,
|
||||
app: App,
|
||||
resource: "downloadclient" | "indexer",
|
||||
what: string,
|
||||
current: Entry,
|
||||
connection: Record<string, unknown>,
|
||||
differs: string[],
|
||||
secretField: string,
|
||||
credential: string,
|
||||
testable = true,
|
||||
): Promise<Outcome> {
|
||||
try {
|
||||
const base = withFields(current, connection); // the credential as the app holds it — masked
|
||||
if (!testable) {
|
||||
// Nothing to test against (jackett no longer has the indexer it names): the connection is
|
||||
// still the mesh's to state, and the key goes with it when the address changes.
|
||||
if (differs.length === 0) return { what, result: "unchanged", untested: true };
|
||||
const s = await appSave(http, app, resource, withFields(base, { [secretField]: credential }), false);
|
||||
if (!s.ok) return { what, result: "refused", problem: `${app.module} would not save it: ${said(s.failures)}` };
|
||||
return { what, result: "written", fields: [...differs, secretField], untested: true };
|
||||
}
|
||||
const first = await appTest(http, app, resource, base);
|
||||
if (first.ok) {
|
||||
// The credential the app holds already works against the provider at the mesh's address —
|
||||
// and the provider has exactly one, so it is the delivered one.
|
||||
if (differs.length === 0) return { what, result: "unchanged" };
|
||||
const s = await appSave(http, app, resource, base, false);
|
||||
if (!s.ok) return { what, result: "refused", problem: `${app.module} would not save it: ${said(s.failures)}` };
|
||||
return { what, result: "written", fields: differs };
|
||||
}
|
||||
// The app's test failed with what it holds. The delivered credential was already checked
|
||||
// against the provider, so writing it is safe; the app tests an enabled entry again on save.
|
||||
const s = await appSave(http, app, resource, withFields(base, { [secretField]: credential }), false);
|
||||
if (!s.ok) {
|
||||
return {
|
||||
what,
|
||||
result: "refused",
|
||||
problem: `${app.module} tested it at the mesh's address and would not save it (nothing was written): ${said(s.failures)}`,
|
||||
};
|
||||
}
|
||||
const stored = (await appGet(http, app, `/${resource}/${current.id}`)) as Entry;
|
||||
const second = await appTest(http, app, resource, stored);
|
||||
const fields = [...differs, secretField];
|
||||
if (second.ok) return { what, result: "written", fields };
|
||||
const why = `written (${fields.join(", ")}), and ${app.module}'s own test still fails: ${said(second.failures)}`;
|
||||
return enabled(stored) ? { what, result: "refused", problem: why } : { what, result: "notice", note: `${why} — it is disabled, so nothing uses it` };
|
||||
} catch (err) {
|
||||
return { what, result: "refused", problem: message(err) };
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Register a new entry from the app's own template for that kind: its defaults, the name, the
|
||||
* connection and the credential. A category the provider does not have (nzbget refuses one it was
|
||||
* not told about) is left empty rather than failing the registration, and said.
|
||||
*/
|
||||
export async function createEntry(
|
||||
http: Http,
|
||||
app: App,
|
||||
resource: "downloadclient" | "indexer",
|
||||
what: string,
|
||||
implementation: string,
|
||||
name: string,
|
||||
values: Record<string, unknown>,
|
||||
): Promise<Outcome> {
|
||||
try {
|
||||
const schema = (await appGet(http, app, `/${resource}/schema`)) as Entry[];
|
||||
const template = (schema ?? []).find((s) => s.implementation === implementation);
|
||||
if (!template) return { what, result: "refused", problem: `${app.module} has no ${implementation} to register` };
|
||||
let entry: Entry = withFields({ ...template, id: undefined, name }, values);
|
||||
if (resource === "downloadclient") entry.enable = true;
|
||||
else {
|
||||
entry.enableRss = template.supportsRss !== false;
|
||||
entry.enableAutomaticSearch = template.supportsSearch !== false;
|
||||
entry.enableInteractiveSearch = template.supportsSearch !== false;
|
||||
}
|
||||
let s = await appSave(http, app, resource, entry, true);
|
||||
let note = "";
|
||||
if (!s.ok && s.failures.length > 0 && s.failures.every((f) => /category/i.test(f.property))) {
|
||||
const emptied: Record<string, unknown> = {};
|
||||
for (const f of entry.fields ?? []) if (/category$/i.test(f.name) && !/imported/i.test(f.name)) emptied[f.name] = "";
|
||||
entry = withFields(entry, emptied);
|
||||
s = await appSave(http, app, resource, entry, true);
|
||||
note = " with its category left empty — the provider has none by the app's default name; set one in both";
|
||||
}
|
||||
if (!s.ok) return { what, result: "refused", problem: `${app.module} would not register it: ${said(s.failures)}` };
|
||||
const created = s.saved;
|
||||
if (created?.id !== undefined) {
|
||||
const t = await appTest(http, app, resource, (await appGet(http, app, `/${resource}/${created.id}`)) as Entry);
|
||||
if (!t.ok) {
|
||||
return { what, result: "refused", problem: `registered as "${name}"${note}, and ${app.module}'s own test fails: ${said(t.failures)}` };
|
||||
}
|
||||
}
|
||||
return note
|
||||
? { what, result: "notice", note: `registered as "${name}"${note}` }
|
||||
: { what, result: "created", fields: Object.keys(values) };
|
||||
} catch (err) {
|
||||
return { what, result: "refused", problem: message(err) };
|
||||
}
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// Providers: does it take the credential?
|
||||
|
||||
/**
|
||||
* Does the provider take this credential? `took` it does (for jackett, with the ids of the indexers
|
||||
* it has configured); `refused` it said no; a thrown error when it could not be asked.
|
||||
*/
|
||||
export interface Took {
|
||||
took: boolean;
|
||||
configured?: Map<string, string>;
|
||||
}
|
||||
|
||||
export async function providerTakes(http: Http, provision: string, ep: Endpoint): Promise<Took> {
|
||||
const base = baseUrl(ep);
|
||||
if (provision === "nzbget-api") {
|
||||
const auth = Buffer.from(`${ep.username}:${ep.credential}`).toString("base64");
|
||||
const res = await http.fetch(`${base}/jsonrpc/version`, { method: "GET", headers: { Authorization: `Basic ${auth}` } });
|
||||
await res.text();
|
||||
if (res.status === 401 || res.status === 403) return { took: false };
|
||||
if (res.status >= 200 && res.status < 300) return { took: true };
|
||||
throw new Error(`nzbget answered ${res.status}`);
|
||||
}
|
||||
if (provision === "qbittorrent-api") {
|
||||
const form = `username=${encodeURIComponent(ep.username)}&password=${encodeURIComponent(ep.credential)}`;
|
||||
const res = await http.fetch(`${base}/api/v2/auth/login`, {
|
||||
method: "POST",
|
||||
headers: { "Content-Type": "application/x-www-form-urlencoded" },
|
||||
body: form,
|
||||
});
|
||||
const text = (await res.text()).trim();
|
||||
if (res.status === 401 || /^fails\.?$/i.test(text)) return { took: false };
|
||||
if (res.status === 403) {
|
||||
throw new Error(
|
||||
"qBittorrent answered 403: it has banned this address after failed logins (WebUI\\BanDuration); it lifts by itself",
|
||||
);
|
||||
}
|
||||
if (res.status >= 200 && res.status < 300) return { took: true };
|
||||
throw new Error(`qBittorrent answered ${res.status}`);
|
||||
}
|
||||
if (provision === JACKETT) {
|
||||
const url = `${base}/api/v2.0/indexers/all/results/torznab/api?t=indexers&configured=true&apikey=${encodeURIComponent(ep.credential)}`;
|
||||
const res = await http.fetch(url, { method: "GET" });
|
||||
const text = await res.text();
|
||||
if (res.status === 401 || res.status === 403) return { took: false };
|
||||
if (res.status < 200 || res.status >= 300) throw new Error(`jackett answered ${res.status}`);
|
||||
// jackett answers a wrong key 200 with an error document: code 100, "Invalid API Key".
|
||||
if (/<error\b[^>]*\bcode="100"/i.test(text)) return { took: false };
|
||||
if (/<error\b/i.test(text)) throw new Error("jackett answered with an error document");
|
||||
return { took: true, configured: configuredIndexers(text) };
|
||||
}
|
||||
throw new Error(`no check for ${provision}`);
|
||||
}
|
||||
|
||||
/** jackett's configured indexers, id → title, from its `t=indexers` feed. */
|
||||
export function configuredIndexers(xml: string): Map<string, string> {
|
||||
const out = new Map<string, string>();
|
||||
const re = /<indexer\b[^>]*\bid="([^"]+)"[^>]*>([\s\S]*?)<\/indexer>/g;
|
||||
for (let m = re.exec(xml); m; m = re.exec(xml)) {
|
||||
const title = /<title>([\s\S]*?)<\/title>/.exec(m[2])?.[1]?.trim() ?? m[1];
|
||||
out.set(m[1], decodeXml(title));
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
function decodeXml(s: string): string {
|
||||
return s.replace(/</g, "<").replace(/>/g, ">").replace(/"/g, '"').replace(/'/g, "'").replace(/&/g, "&");
|
||||
}
|
||||
|
||||
/** The remedy for a refused credential, in the controller's own words (ADR 0092). */
|
||||
export function acceptRemedy(app: App, node: string, provision: string, provider: string, secretName: string, from: string): string {
|
||||
return (
|
||||
`${provider} refuses the ${provision} credential the mesh delivered, so nothing of ${provision} was written ` +
|
||||
`into ${app.module}. ${provider} has one ${secretName} and the mesh cannot make it: accept it for this pair — ` +
|
||||
`\`secret accept ${node || "<this node>"} ${app.module} ${provision} --provider ${from || "<its node>"} ` +
|
||||
`--from <file holding ${provider}'s ${secretName}>\``
|
||||
);
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// Download clients
|
||||
|
||||
/** The non-secret fields of a download client as the mesh says them. */
|
||||
export function clientConnection(ep: Endpoint): Record<string, unknown> {
|
||||
return { host: ep.host, port: ep.port, useSsl: ep.scheme === "https", urlBase: ep.urlBase === "" ? null : ep.urlBase, username: ep.username };
|
||||
}
|
||||
|
||||
/** Which of them the entry does not already say. Names only. */
|
||||
export function clientDiffers(e: Entry, ep: Endpoint): string[] {
|
||||
const out: string[] = [];
|
||||
if (String(field(e, "host") ?? "").toLowerCase() !== ep.host.toLowerCase()) out.push("host");
|
||||
if (Number(field(e, "port") ?? 0) !== ep.port) out.push("port");
|
||||
if (Boolean(field(e, "useSsl")) !== (ep.scheme === "https")) out.push("useSsl");
|
||||
if (normBase(field(e, "urlBase")) !== ep.urlBase) out.push("urlBase");
|
||||
if (String(field(e, "username") ?? "") !== ep.username) out.push("username");
|
||||
return out;
|
||||
}
|
||||
|
||||
/**
|
||||
* Bring the app's download client for one provision in line: the entry by that name and kind is
|
||||
* the mesh's and is updated; none, it is registered. An entry by that name of another kind, or by
|
||||
* that name in another case, is somebody else's and is refused rather than touched.
|
||||
*/
|
||||
export async function reconcileClient(
|
||||
http: Http,
|
||||
app: App,
|
||||
kind: ClientKind,
|
||||
name: string,
|
||||
ep: Endpoint,
|
||||
entries: Entry[],
|
||||
): Promise<Outcome[]> {
|
||||
const what = `${kind.provision} ("${name}")`;
|
||||
const exact = entries.filter((e) => e.name === name);
|
||||
const alike = entries.filter((e) => e.name !== name && String(e.name ?? "").toLowerCase() === name.toLowerCase());
|
||||
if (exact.length > 0 && exact[0].implementation !== kind.implementation) {
|
||||
return [{
|
||||
what,
|
||||
result: "refused",
|
||||
problem: `the download client named "${name}" is a ${exact[0].implementation}, not ${kind.implementation}; it is not the mesh's and was left alone. Name the mesh's entry otherwise in downloads.${kind.provision}.name`,
|
||||
}];
|
||||
}
|
||||
if (exact.length === 0 && alike.length > 0) {
|
||||
return [{
|
||||
what,
|
||||
result: "refused",
|
||||
problem: `${app.module} already has "${alike[0].name}", which is not the mesh's name ("${name}") and was left alone. To have the mesh manage it, set downloads.${kind.provision}.name to "${alike[0].name}"`,
|
||||
}];
|
||||
}
|
||||
const outcomes: Outcome[] = [];
|
||||
const others = entries.filter((e) => e.implementation === kind.implementation && e.name !== name);
|
||||
if (others.length > 0) {
|
||||
outcomes.push({
|
||||
what,
|
||||
result: "notice",
|
||||
note: `also present and not the mesh's, left alone: ${others.map((o) => `"${o.name}"`).join(", ")}`,
|
||||
});
|
||||
}
|
||||
if (exact.length === 0) {
|
||||
outcomes.push(
|
||||
await createEntry(http, app, "downloadclient", what, kind.implementation, name, {
|
||||
...clientConnection(ep),
|
||||
password: ep.credential,
|
||||
}),
|
||||
);
|
||||
return outcomes;
|
||||
}
|
||||
outcomes.push(
|
||||
await reconcileEntry(http, app, "downloadclient", what, exact[0], clientConnection(ep), clientDiffers(exact[0], ep), "password", ep.credential),
|
||||
);
|
||||
return outcomes;
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// Indexers
|
||||
|
||||
const FEED = /\/api\/v2\.0\/indexers\/([^/]+)\/results\/torznab\/?$/;
|
||||
|
||||
/** A Torznab entry reading a jackett feed: the host it points at and the jackett indexer's id. */
|
||||
export function jackettFeed(e: Entry): { host: string; id: string } | undefined {
|
||||
if (e.implementation !== "Torznab") return undefined;
|
||||
const raw = String(field(e, "baseUrl") ?? "").trim();
|
||||
if (!raw) return undefined;
|
||||
let u: URL;
|
||||
try {
|
||||
u = new URL(raw);
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
const path = `${u.pathname.replace(/\/+$/, "")}/${String(field(e, "apiPath") ?? "").replace(/^\/+/, "")}`;
|
||||
const m = FEED.exec(path);
|
||||
if (!m) return undefined;
|
||||
return { host: u.hostname.replace(/^\[|\]$/g, "").toLowerCase(), id: decodeURIComponent(m[1]) };
|
||||
}
|
||||
|
||||
/** The feed's two fields as the mesh says them. */
|
||||
export function feedConnection(ep: Endpoint, id: string): Record<string, unknown> {
|
||||
return { baseUrl: baseUrl(ep), apiPath: `/api/v2.0/indexers/${id}/results/torznab/` };
|
||||
}
|
||||
|
||||
function sameUrl(a: string, b: string): boolean {
|
||||
try {
|
||||
const x = new URL(a);
|
||||
const y = new URL(b);
|
||||
const port = (u: URL) => u.port || (u.protocol === "https:" ? "443" : "80");
|
||||
return (
|
||||
x.protocol === y.protocol &&
|
||||
x.hostname.toLowerCase() === y.hostname.toLowerCase() &&
|
||||
port(x) === port(y) &&
|
||||
x.pathname.replace(/\/+$/, "") === y.pathname.replace(/\/+$/, "")
|
||||
);
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
export function feedDiffers(e: Entry, ep: Endpoint, id: string): string[] {
|
||||
const want = feedConnection(ep, id);
|
||||
const out: string[] = [];
|
||||
if (!sameUrl(String(field(e, "baseUrl") ?? ""), String(want.baseUrl))) out.push("baseUrl");
|
||||
const path = (v: unknown) => `/${String(v ?? "").replace(/^\/+|\/+$/g, "")}`;
|
||||
if (path(field(e, "apiPath")) !== path(want.apiPath)) out.push("apiPath");
|
||||
return out;
|
||||
}
|
||||
|
||||
export interface IndexerSettings {
|
||||
/** Hosts whose jackett feeds the mesh takes over — a migration's old names. */
|
||||
adoptHosts: string[];
|
||||
/** jackett indexer ids the app should have. */
|
||||
indexers: string[];
|
||||
}
|
||||
|
||||
/**
|
||||
* Bring the app's jackett feeds in line: every one the mesh manages is pointed at the bound jackett
|
||||
* with its key, and every listed jackett indexer the app lacks is registered.
|
||||
*/
|
||||
export async function reconcileIndexers(
|
||||
http: Http,
|
||||
app: App,
|
||||
ep: Endpoint,
|
||||
configured: Map<string, string>,
|
||||
settings: IndexerSettings,
|
||||
remembered: string[],
|
||||
entries: Entry[],
|
||||
): Promise<Outcome[]> {
|
||||
const ours = new Set([ep.host, ...settings.adoptHosts, ...remembered].map((h) => h.trim().toLowerCase()).filter(Boolean));
|
||||
const outcomes: Outcome[] = [];
|
||||
const managed = new Set<string>();
|
||||
for (const e of entries) {
|
||||
const feed = jackettFeed(e);
|
||||
if (!feed || !ours.has(feed.host)) continue;
|
||||
managed.add(feed.id);
|
||||
const what = `jackett-api ("${e.name}", jackett indexer ${feed.id})`;
|
||||
const known = feed.id === "all" || configured.has(feed.id);
|
||||
const outcome = await reconcileEntry(
|
||||
http, app, "indexer", what, e, feedConnection(ep, feed.id), feedDiffers(e, ep, feed.id), "apiKey", ep.credential, known,
|
||||
);
|
||||
outcomes.push(outcome);
|
||||
if (!known && outcome.result !== "refused") {
|
||||
outcomes.push({ what, result: "notice", note: `jackett has no indexer "${feed.id}" configured, so it was not tested; configure it in jackett or remove the entry in ${app.module}` });
|
||||
}
|
||||
}
|
||||
for (const id of settings.indexers) {
|
||||
if (managed.has(id)) continue;
|
||||
const what = `jackett-api (jackett indexer ${id})`;
|
||||
if (id !== "all" && !configured.has(id)) {
|
||||
outcomes.push({ what, result: "refused", problem: `downloads.jackett-api.indexers lists "${id}", and jackett has no indexer by that id configured` });
|
||||
continue;
|
||||
}
|
||||
const name = `Jackett - ${id === "all" ? "all" : configured.get(id)}`;
|
||||
outcomes.push(await createEntry(http, app, "indexer", what, "Torznab", name, { ...feedConnection(ep, id), apiKey: ep.credential }));
|
||||
}
|
||||
if (outcomes.length === 0) {
|
||||
outcomes.push({ what: "jackett-api", result: "notice", note: `${app.module} has no jackett feed the mesh manages, and downloads.jackett-api.indexers lists none to register` });
|
||||
}
|
||||
return outcomes;
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------------------------
|
||||
// Files
|
||||
|
||||
/** The module's settings for this step, from its merged `downloads.json`. */
|
||||
export interface StepSettings {
|
||||
node: string;
|
||||
names: Record<string, string>;
|
||||
indexers: IndexerSettings;
|
||||
}
|
||||
|
||||
export function stepSettings(raw: unknown): StepSettings {
|
||||
const doc = (raw ?? {}) as Record<string, unknown>;
|
||||
const d = (doc.downloads ?? {}) as Record<string, Record<string, unknown> | undefined>;
|
||||
const names: Record<string, string> = {};
|
||||
for (const k of CLIENTS) {
|
||||
const n = d[k.provision]?.name;
|
||||
names[k.provision] = typeof n === "string" && n.trim() ? n.trim() : k.provision.replace(/-api$/, "");
|
||||
}
|
||||
const j = d[JACKETT] ?? {};
|
||||
const strings = (v: unknown) => (Array.isArray(v) ? v.filter((x): x is string => typeof x === "string" && x.trim() !== "").map((x) => x.trim()) : []);
|
||||
return {
|
||||
node: typeof doc.node === "string" ? doc.node : "",
|
||||
names,
|
||||
indexers: { adoptHosts: strings(j["adopt-hosts"]), indexers: strings(j.indexers) },
|
||||
};
|
||||
}
|
||||
|
||||
/** The app's own key and base path, from its config.xml. */
|
||||
export function appConfig(xml: string): { apiKey: string; urlBase: string } {
|
||||
const tag = (t: string) => new RegExp(`<${t}>([^<]*)</${t}>`).exec(xml)?.[1]?.trim() ?? "";
|
||||
return { apiKey: tag("ApiKey"), urlBase: normBase(tag("UrlBase")) };
|
||||
}
|
||||
|
||||
/** A file the mesh wrote, or undefined when it is not there. */
|
||||
export async function readIfThere(path: string | undefined): Promise<string | undefined> {
|
||||
if (!path) return undefined;
|
||||
return readFile(path, "utf8").catch(() => undefined);
|
||||
}
|
||||
|
||||
/** A JSON file parsed, or undefined when absent or not JSON. */
|
||||
export async function readJson(path: string | undefined): Promise<unknown> {
|
||||
const raw = await readIfThere(path);
|
||||
if (raw === undefined) return undefined;
|
||||
try {
|
||||
return JSON.parse(raw) as unknown;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
/** Wait for the app to answer, because the step runs right after its container starts. */
|
||||
export async function appReady(http: Http, app: App, waitMs: number, pauseMs = 2000): Promise<boolean> {
|
||||
const until = Date.now() + waitMs;
|
||||
for (;;) {
|
||||
try {
|
||||
const a = await appCall(http, app, "GET", "/system/status");
|
||||
if (a.status === 200) return true;
|
||||
} catch {
|
||||
// not listening yet
|
||||
}
|
||||
if (Date.now() >= until) return false;
|
||||
await new Promise((r) => setTimeout(r, pauseMs));
|
||||
}
|
||||
}
|
||||
|
||||
export async function listEntries(http: Http, app: App, resource: "downloadclient" | "indexer"): Promise<Entry[]> {
|
||||
return ((await appGet(http, app, `/${resource}`)) as Entry[]) ?? [];
|
||||
}
|
||||
|
||||
/** Anything printed goes through this: the credentials the step holds never reach a log. */
|
||||
export function scrub(text: string, secrets: string[]): string {
|
||||
let out = text;
|
||||
for (const s of secrets) if (s && s.length >= 4) out = out.split(s).join("<redacted>");
|
||||
return out;
|
||||
}
|
||||
|
||||
function message(err: unknown): string {
|
||||
return err instanceof Error ? err.message : String(err);
|
||||
}
|
||||
@@ -1,6 +1,19 @@
|
||||
{
|
||||
"module": "sonarr",
|
||||
"version": "1",
|
||||
"provides": [
|
||||
{
|
||||
"name": "sonarr-api",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"sonarr-api": {
|
||||
"scheme": "http",
|
||||
"port": 8989,
|
||||
"url-base": ""
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -18,7 +31,7 @@
|
||||
"port": 8989,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "managing series"
|
||||
"why": "managing series: its web UI, and the API other modules reach as sonarr-api"
|
||||
}
|
||||
],
|
||||
"accesses": [
|
||||
@@ -42,10 +55,15 @@
|
||||
"path": "/var/lib/mesh/sonarr",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "directory",
|
||||
"path": "/services/sonarr/config",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
@@ -53,7 +71,7 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "sonarr",
|
||||
"image": "lscr.io/linuxserver/sonarr@sha256:c19aa4ecdf03d73e1d5c901da33744cb7eb4d921f89bafed1ca264601d7fa224",
|
||||
"image": "lscr.io/linuxserver/sonarr@sha256:a5c1a5fecbef946927ab90ad68df319ac5fe644057e5fc18cd993f01ac07b2b2",
|
||||
"env": {
|
||||
"PUID": "1000",
|
||||
"PGID": "1000",
|
||||
@@ -63,7 +81,7 @@
|
||||
"8989"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/sonarr/config:/config",
|
||||
"${dir:config}:/config",
|
||||
"/services/media/series:/series",
|
||||
"/services/media/anime:/anime",
|
||||
"/services/media/downloads:/downloads"
|
||||
@@ -76,17 +94,74 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/sonarr/broker:/run/secrets/broker:ro",
|
||||
"/services/sonarr/config:/var/lib/sonarr/config:ro"
|
||||
"${dir:config}:/var/lib/sonarr/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_SONARR_URL": "http://127.0.0.1:8989",
|
||||
"MESH_SONARR_URL": "http://127.0.0.1:${port:8989}",
|
||||
"MESH_SONARR_CONFIG_DIR": "/var/lib/sonarr/config"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
},
|
||||
{
|
||||
"id": "downloads-config",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/downloads.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"node\": \"${machine:name}\",\n \"downloads\": {\n \"nzbget-api\": {\n \"name\": \"nzbget\"\n },\n \"qbittorrent-api\": {\n \"name\": \"qbittorrent\"\n },\n \"jackett-api\": {\n \"adopt-hosts\": [],\n \"indexers\": []\n }\n }\n}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
"id": "downloads-memory",
|
||||
"type": "directory",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "downloads",
|
||||
"type": "container",
|
||||
"name": "mesh-sonarr-downloads",
|
||||
"network": "host",
|
||||
"run-once": true,
|
||||
"volumes": [
|
||||
"${dir:state}/downloads.json:/run/downloads/downloads.json:ro",
|
||||
"${dir:state}/nzbget-api.json:/run/downloads/nzbget-api.json:ro",
|
||||
"${dir:state}/nzbget-api.secret:/run/downloads/nzbget-api.secret:ro",
|
||||
"${dir:state}/qbittorrent-api.json:/run/downloads/qbittorrent-api.json:ro",
|
||||
"${dir:state}/qbittorrent-api.secret:/run/downloads/qbittorrent-api.secret:ro",
|
||||
"${dir:state}/jackett-api.json:/run/downloads/jackett-api.json:ro",
|
||||
"${dir:state}/jackett-api.secret:/run/downloads/jackett-api.secret:ro",
|
||||
"${dir:config}:/var/lib/sonarr/config:ro",
|
||||
"${dir:downloads-memory}:/var/lib/downloads"
|
||||
],
|
||||
"env": {
|
||||
"MESH_DOWNLOADS_APP": "sonarr",
|
||||
"MESH_DOWNLOADS_API": "v3",
|
||||
"MESH_DOWNLOADS_APP_URL": "http://127.0.0.1:${port:8989}",
|
||||
"MESH_DOWNLOADS_APP_CONFIG": "/var/lib/sonarr/config/config.xml",
|
||||
"MESH_DOWNLOADS_DIR": "/run/downloads",
|
||||
"MESH_DOWNLOADS_SETTINGS": "/run/downloads/downloads.json",
|
||||
"MESH_DOWNLOADS_MEMORY": "/var/lib/downloads/memory.json"
|
||||
},
|
||||
"args": [
|
||||
"run",
|
||||
"/app/modules/sonarr/dist/downloads/index.js"
|
||||
],
|
||||
"restart-on": [
|
||||
"downloads-config",
|
||||
"bound-nzbget-api",
|
||||
"secret-nzbget-api",
|
||||
"bound-qbittorrent-api",
|
||||
"secret-qbittorrent-api",
|
||||
"bound-jackett-api",
|
||||
"secret-jackett-api"
|
||||
],
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"jackett-api",
|
||||
"nzbget-api",
|
||||
"qbittorrent-api",
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
@@ -96,7 +171,15 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "/var/lib/mesh/sonarr/route.json"
|
||||
"route": "${dir:state}/route.json",
|
||||
"nzbget-api": "${dir:state}/nzbget-api.json",
|
||||
"qbittorrent-api": "${dir:state}/qbittorrent-api.json",
|
||||
"jackett-api": "${dir:state}/jackett-api.json"
|
||||
},
|
||||
"secrets": {
|
||||
"nzbget-api": "${dir:state}/nzbget-api.secret",
|
||||
"qbittorrent-api": "${dir:state}/qbittorrent-api.secret",
|
||||
"jackett-api": "${dir:state}/jackett-api.secret"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
@@ -4,6 +4,11 @@
|
||||
"description": "sonarr — TV series management. Its API client, tools and events live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "tsc client.ts index.ts tools/index.ts downloads/settings.ts downloads/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||
"typecheck": "tsc -p tsconfig.json",
|
||||
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
||||
},
|
||||
"dependencies": {
|
||||
"@novox/mesh-sdk": "^0.1.0"
|
||||
},
|
||||
|
||||
@@ -0,0 +1,365 @@
|
||||
// What holds the downloads step (downloads/settings.ts): the app's download clients and jackett
|
||||
// feeds are made to say what the mesh bound — host, port, TLS, base path, user, credential — and
|
||||
// nothing else they keep is touched; only the mesh's entries are touched, and nothing is ever
|
||||
// deleted; nothing is written when nothing differs; a missing one is registered; and a credential
|
||||
// the provider refuses (the mesh's own minted value, before the operator accepts the provider's)
|
||||
// is never written, with the `secret accept` that fixes it named.
|
||||
//
|
||||
// The app and the providers are fakes: the routes the step touches, answering as the real ones do
|
||||
// (checked against the catalogue's pinned sonarr, radarr, lidarr, bookshelf, nzbget, qBittorrent
|
||||
// and jackett): the app masks a stored password as "********", tests an enabled entry before
|
||||
// saving it, refuses a warning unless forceSave, and jackett answers a wrong key 200 with an error.
|
||||
|
||||
import { test } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import { existsSync, readFileSync } from "node:fs";
|
||||
import { dirname, join } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
|
||||
import {
|
||||
CLIENTS,
|
||||
acceptRemedy,
|
||||
jackettFeed,
|
||||
providerTakes,
|
||||
reconcileClient,
|
||||
reconcileIndexers,
|
||||
stepSettings,
|
||||
wanted,
|
||||
type App,
|
||||
type Binding,
|
||||
type Endpoint,
|
||||
type Entry,
|
||||
type Http,
|
||||
} from "../downloads/settings.ts";
|
||||
|
||||
const NZBGET = CLIENTS.find((c) => c.provision === "nzbget-api")!;
|
||||
const QBIT = CLIENTS.find((c) => c.provision === "qbittorrent-api")!;
|
||||
const APP: App = { module: "sonarr", url: "http://127.0.0.1:8989", apiKey: "app-key", api: "v3" };
|
||||
const MASK = "********";
|
||||
|
||||
interface Provider {
|
||||
host: string;
|
||||
port: number;
|
||||
user?: string;
|
||||
secret: string;
|
||||
configured?: Record<string, string>;
|
||||
}
|
||||
|
||||
const nzbget: Provider = { host: "ace.internal", port: 20201, user: "luffy", secret: "nzb-real" };
|
||||
const qbit: Provider = { host: "ace.internal", port: 8112, user: "luffy", secret: "qbt-real" };
|
||||
const jackett: Provider = { host: "ace.internal", port: 20204, secret: "jackett-real", configured: { rutracker: "RuTracker", torrent9: "Torrent9" } };
|
||||
|
||||
function binding(p: Provider, provision: string, extra: Record<string, unknown> = {}): Binding {
|
||||
return {
|
||||
provision,
|
||||
from: "ace",
|
||||
at: p.host,
|
||||
as: "mesh_ace_sonarr",
|
||||
serves: { scheme: "http", port: p.port, "url-base": "", ...(p.user ? { username: p.user } : {}), ...extra },
|
||||
};
|
||||
}
|
||||
|
||||
function endpoint(p: Provider, provision: string, credential = p.secret): Endpoint {
|
||||
const w = wanted(provision, binding(p, provision), credential, provision !== "jackett-api");
|
||||
if (!w.ok) throw new Error(w.problem);
|
||||
return w.endpoint;
|
||||
}
|
||||
|
||||
const f = (name: string, value: unknown) => ({ name, value });
|
||||
|
||||
function client(id: number, name: string, implementation: string, host: string, port: number, password: string, extra: Record<string, unknown> = {}): Entry {
|
||||
return {
|
||||
id, name, implementation, enable: true, priority: 1, tags: [],
|
||||
fields: [f("host", host), f("port", port), f("useSsl", false), f("urlBase", null), f("username", "luffy"), f("password", password), f("tvCategory", "Series"), ...Object.entries(extra).map(([k, v]) => f(k, v))],
|
||||
};
|
||||
}
|
||||
|
||||
function feed(id: number, name: string, baseUrl: string, jid: string, key: string, on = true): Entry {
|
||||
return {
|
||||
id, name, implementation: "Torznab", enableRss: on, enableAutomaticSearch: on, enableInteractiveSearch: on, priority: 25,
|
||||
fields: [f("baseUrl", baseUrl), f("apiPath", `/api/v2.0/indexers/${jid}/results/torznab/`), f("apiKey", key), f("categories", [5000])],
|
||||
};
|
||||
}
|
||||
|
||||
interface Call {
|
||||
method: string;
|
||||
url: string;
|
||||
body?: unknown;
|
||||
}
|
||||
|
||||
/** A Servarr app and the three providers behind one fetch. */
|
||||
function fakes(start: { clients?: Entry[]; indexers?: Entry[] }) {
|
||||
const calls: Call[] = [];
|
||||
const store: Record<string, Entry[]> = {
|
||||
downloadclient: structuredClone(start.clients ?? []),
|
||||
indexer: structuredClone(start.indexers ?? []),
|
||||
};
|
||||
let next = 100;
|
||||
const secretOf: Record<string, string> = { downloadclient: "password", indexer: "apiKey" };
|
||||
const masked = (e: Entry): Entry => ({ ...e, fields: e.fields!.map((x) => (x.name === "password" || x.name === "apiKey") && x.value ? { ...x, value: MASK } : { ...x }) });
|
||||
const val = (e: Entry, n: string) => e.fields?.find((x) => x.name === n)?.value;
|
||||
|
||||
/** What the app's own test says: dialled from its container, with its stored secret for a mask. */
|
||||
const appTest = (kind: string, e: Entry): { propertyName: string; errorMessage: string; isWarning: boolean }[] => {
|
||||
let secret = val(e, secretOf[kind]);
|
||||
if (secret === MASK) secret = val(store[kind].find((s) => s.id === e.id) ?? {}, secretOf[kind]);
|
||||
if (kind === "downloadclient") {
|
||||
const p = e.implementation === "Nzbget" ? nzbget : qbit;
|
||||
if (val(e, "host") !== p.host || val(e, "port") !== p.port) return [{ propertyName: "Host", errorMessage: "Unable to connect", isWarning: false }];
|
||||
if (secret !== p.secret || val(e, "username") !== p.user) return [{ propertyName: "Username", errorMessage: "Authentication Failure", isWarning: false }];
|
||||
if (val(e, "tvCategory") === "") return [{ propertyName: "TvCategory", errorMessage: "A category is recommended", isWarning: true }];
|
||||
if (e.implementation === "Nzbget" && val(e, "tvCategory") === "tv") return [{ propertyName: "TvCategory", errorMessage: "Category does not exist", isWarning: false }];
|
||||
return [];
|
||||
}
|
||||
const u = new URL(String(val(e, "baseUrl")));
|
||||
if (u.hostname !== jackett.host || Number(u.port) !== jackett.port) return [{ propertyName: "BaseUrl", errorMessage: "Unable to connect", isWarning: false }];
|
||||
if (secret !== jackett.secret) return [{ propertyName: "ApiKey", errorMessage: "Invalid API Key", isWarning: false }];
|
||||
const id = /indexers\/([^/]+)\//.exec(String(val(e, "apiPath")))?.[1] ?? "";
|
||||
if (!(id in jackett.configured!)) return [{ propertyName: "", errorMessage: "Unknown indexer", isWarning: false }];
|
||||
return [];
|
||||
};
|
||||
|
||||
const http: Http = {
|
||||
async fetch(url, init) {
|
||||
const method = init?.method ?? "GET";
|
||||
const body = init?.body && init.headers?.["Content-Type"] === "application/json" ? (JSON.parse(init.body) as Entry) : init?.body;
|
||||
calls.push({ method, url, body });
|
||||
const reply = (status: number, value?: unknown) => ({ status, text: async () => (value === undefined ? "" : typeof value === "string" ? value : JSON.stringify(value)) });
|
||||
const u = new URL(url);
|
||||
// Providers.
|
||||
if (u.pathname === "/jsonrpc/version") {
|
||||
const want = "Basic " + Buffer.from(`${nzbget.user}:${nzbget.secret}`).toString("base64");
|
||||
return init?.headers?.Authorization === want ? reply(200, { result: "26.0" }) : reply(401);
|
||||
}
|
||||
if (u.pathname === "/api/v2/auth/login") {
|
||||
const form = new URLSearchParams(String(init?.body ?? ""));
|
||||
return form.get("username") === qbit.user && form.get("password") === qbit.secret ? reply(204) : reply(401, "Unauthorized");
|
||||
}
|
||||
if (u.pathname.endsWith("/torznab/api")) {
|
||||
if (u.searchParams.get("apikey") !== jackett.secret) return reply(200, '<?xml version="1.0"?><error code="100" description="Invalid API Key" />');
|
||||
const items = Object.entries(jackett.configured!).map(([id, t]) => `<indexer id="${id}" configured="true"><title>${t}</title></indexer>`).join("");
|
||||
return reply(200, `<?xml version="1.0"?><indexers>${items}</indexers>`);
|
||||
}
|
||||
// The app.
|
||||
if (init?.headers?.["X-Api-Key"] !== APP.apiKey) return reply(401);
|
||||
const m = /^\/api\/v3\/(downloadclient|indexer)(?:\/(schema|test|\d+))?$/.exec(u.pathname);
|
||||
if (!m) return reply(404);
|
||||
const [, kind, sub] = m;
|
||||
const force = u.searchParams.get("forceSave") === "true";
|
||||
if (method === "GET" && !sub) return reply(200, store[kind].map(masked));
|
||||
if (method === "GET" && sub === "schema") {
|
||||
return reply(200, kind === "downloadclient"
|
||||
? [client(0, "", "Nzbget", "localhost", 6789, MASK, {}), client(0, "", "QBittorrent", "localhost", 8080, "", {})].map((e) => ({ ...e, fields: e.fields!.map((x) => x.name === "tvCategory" ? { ...x, value: e.implementation === "Nzbget" ? "tv" : "tv-sonarr" } : x.name === "username" ? { ...x, value: null } : x) }))
|
||||
: [{ ...feed(0, "", "", "x", "", false), supportsRss: true, supportsSearch: true, fields: [f("baseUrl", null), f("apiPath", "/api"), f("apiKey", null), f("categories", [5030, 5040])] }]);
|
||||
}
|
||||
if (method === "GET") {
|
||||
const e = store[kind].find((s) => s.id === Number(sub));
|
||||
return e ? reply(200, masked(e)) : reply(404);
|
||||
}
|
||||
if (method === "POST" && sub === "test") {
|
||||
const fails = appTest(kind, body as Entry);
|
||||
return fails.length ? reply(400, fails) : reply(200);
|
||||
}
|
||||
// Save: tested when enabled; a mask keeps what is stored.
|
||||
const e = body as Entry;
|
||||
const on = e.enable === true || e.enableRss === true || e.enableAutomaticSearch === true;
|
||||
if (on) {
|
||||
const fails = appTest(kind, e);
|
||||
if (fails.some((x) => !x.isWarning) || (fails.length && !force)) return reply(400, fails);
|
||||
}
|
||||
if (method === "POST" && !sub) {
|
||||
if (store[kind].some((s) => String(s.name).toLowerCase() === String(e.name).toLowerCase())) {
|
||||
return reply(400, [{ propertyName: "Name", errorMessage: "Should be unique", isWarning: false }]);
|
||||
}
|
||||
const created = { ...e, id: next++ };
|
||||
store[kind].push(created);
|
||||
return reply(201, masked(created));
|
||||
}
|
||||
if (method === "PUT") {
|
||||
const i = store[kind].findIndex((s) => s.id === Number(sub));
|
||||
if (i < 0) return reply(404);
|
||||
const was = store[kind][i];
|
||||
store[kind][i] = { ...e, fields: e.fields!.map((x) => x.value === MASK ? { ...x, value: val(was, x.name) } : x) };
|
||||
return reply(202, masked(store[kind][i]));
|
||||
}
|
||||
return reply(405);
|
||||
},
|
||||
};
|
||||
const saves = () => calls.filter((c) => (c.method === "PUT" || (c.method === "POST" && !c.url.endsWith("/test"))) && c.url.includes("/api/v3/"));
|
||||
return { http, calls, store, saves };
|
||||
}
|
||||
|
||||
const aceClients = () => [
|
||||
client(1, "NZBGet", "Nzbget", "nzbget", 6789, "nzb-real"),
|
||||
client(2, "qBitTorrent", "QBittorrent", "qbittorrent", 8112, "qbt-real"),
|
||||
];
|
||||
|
||||
test("the migration's download client is repointed, its category and everything else kept", async () => {
|
||||
const f = fakes({ clients: aceClients() });
|
||||
const out = await reconcileClient(f.http, APP, NZBGET, "NZBGet", endpoint(nzbget, "nzbget-api"), f.store.downloadclient.map((e) => ({ ...e })));
|
||||
assert.deepEqual(out, [{ what: 'nzbget-api ("NZBGet")', result: "written", fields: ["host", "port"] }]);
|
||||
const saved = f.store.downloadclient.find((e) => e.id === 1)!;
|
||||
const v = (n: string) => saved.fields!.find((x) => x.name === n)?.value;
|
||||
assert.equal(v("host"), "ace.internal");
|
||||
assert.equal(v("port"), 20201);
|
||||
assert.equal(v("tvCategory"), "Series");
|
||||
assert.equal(v("password"), "nzb-real", "the password it held works, so it was kept, not rewritten");
|
||||
assert.equal(saved.priority, 1);
|
||||
});
|
||||
|
||||
test("rerun: already as the mesh says, nothing saved", async () => {
|
||||
const f = fakes({ clients: [client(1, "NZBGet", "Nzbget", "ace.internal", 20201, "nzb-real")] });
|
||||
const out = await reconcileClient(f.http, APP, NZBGET, "NZBGet", endpoint(nzbget, "nzbget-api"), f.store.downloadclient);
|
||||
assert.deepEqual(out, [{ what: 'nzbget-api ("NZBGet")', result: "unchanged" }]);
|
||||
assert.equal(f.saves().length, 0);
|
||||
});
|
||||
|
||||
test("a stale password is replaced by the delivered one, which the provider took first", async () => {
|
||||
const f = fakes({ clients: [client(2, "qBitTorrent", "QBittorrent", "ace.internal", 8112, "old-pass")] });
|
||||
const out = await reconcileClient(f.http, APP, QBIT, "qBitTorrent", endpoint(qbit, "qbittorrent-api"), f.store.downloadclient);
|
||||
assert.deepEqual(out, [{ what: 'qbittorrent-api ("qBitTorrent")', result: "written", fields: ["password"] }]);
|
||||
assert.equal(f.store.downloadclient[0].fields!.find((x) => x.name === "password")?.value, "qbt-real");
|
||||
});
|
||||
|
||||
test("a minted credential is refused by the provider: nothing written, the accept named", async () => {
|
||||
const f = fakes({ clients: aceClients() });
|
||||
const ep = endpoint(nzbget, "nzbget-api", "a-value-the-mesh-minted");
|
||||
assert.deepEqual(await providerTakes(f.http, "nzbget-api", ep), { took: false });
|
||||
const remedy = acceptRemedy(APP, "ace", "nzbget-api", "nzbget", "ControlPassword", ep.from);
|
||||
assert.match(remedy, /`secret accept ace sonarr nzbget-api --provider ace --from <file holding nzbget's ControlPassword>`/);
|
||||
assert.doesNotMatch(remedy, /minted/);
|
||||
assert.equal(f.calls.some((c) => c.url.includes("/api/v3/")), false, "the app was not even asked");
|
||||
const q = endpoint(qbit, "qbittorrent-api", "minted");
|
||||
assert.deepEqual(await providerTakes(f.http, "qbittorrent-api", q), { took: false });
|
||||
const j = endpoint(jackett, "jackett-api", "minted");
|
||||
assert.deepEqual(await providerTakes(f.http, "jackett-api", j), { took: false });
|
||||
assert.equal(f.calls.find((c) => c.url.includes("apikey="))?.url.includes("jackett-real"), false);
|
||||
});
|
||||
|
||||
test("a fresh app gets the mesh's client registered, under the mesh's name", async () => {
|
||||
const f = fakes({});
|
||||
const out = await reconcileClient(f.http, APP, QBIT, "qbittorrent", endpoint(qbit, "qbittorrent-api"), []);
|
||||
assert.equal(out[0].result, "created");
|
||||
const e = f.store.downloadclient[0];
|
||||
assert.equal(e.name, "qbittorrent");
|
||||
assert.equal(e.enable, true);
|
||||
assert.equal(e.fields!.find((x) => x.name === "tvCategory")?.value, "tv-sonarr", "the app's own default category");
|
||||
});
|
||||
|
||||
test("nzbget without the app's default category: registered with none, and said", async () => {
|
||||
const f = fakes({});
|
||||
const out = await reconcileClient(f.http, APP, NZBGET, "nzbget", endpoint(nzbget, "nzbget-api"), []);
|
||||
assert.equal(out[0].result, "notice");
|
||||
assert.match((out[0] as { note: string }).note, /category left empty/);
|
||||
assert.equal(f.store.downloadclient[0].fields!.find((x) => x.name === "tvCategory")?.value, "");
|
||||
});
|
||||
|
||||
test("somebody else's entries are never touched: another name of the same kind, and a clash of names", async () => {
|
||||
const mine = client(7, "My seedbox", "QBittorrent", "seedbox.example", 443, "theirs");
|
||||
const f = fakes({ clients: [mine] });
|
||||
const out = await reconcileClient(f.http, APP, QBIT, "qbittorrent", endpoint(qbit, "qbittorrent-api"), f.store.downloadclient);
|
||||
assert.equal(out[0].result, "notice");
|
||||
assert.deepEqual(f.store.downloadclient.find((e) => e.id === 7), mine);
|
||||
// Same name in another case: refused, and the setting that adopts it named.
|
||||
const g = fakes({ clients: aceClients() });
|
||||
const clash = await reconcileClient(g.http, APP, NZBGET, "nzbget", endpoint(nzbget, "nzbget-api"), g.store.downloadclient);
|
||||
assert.equal(clash[0].result, "refused");
|
||||
assert.match((clash[0] as { problem: string }).problem, /downloads\.nzbget-api\.name to "NZBGet"/);
|
||||
assert.equal(g.saves().length, 0);
|
||||
});
|
||||
|
||||
test("jackett feeds: the migration's are repointed, a person's is left, a listed one is registered", async () => {
|
||||
const personal = feed(9, "Seedbox jackett", "https://jackett.seedbox.example", "rutracker", "their-key");
|
||||
const f = fakes({
|
||||
indexers: [
|
||||
feed(5, "Torznab - RuTracker", "https://indexers.zurag.be", "rutracker-ru", "jackett-real", false),
|
||||
feed(6, "Torznab - Torrent9", "https://indexers.zurag.be", "torrent9", "jackett-real", false),
|
||||
feed(4, "Jackett - RARBG", "http://jackett:9117", "therarbg", "old", false),
|
||||
personal,
|
||||
],
|
||||
});
|
||||
const configured = new Map(Object.entries(jackett.configured!));
|
||||
const out = await reconcileIndexers(
|
||||
f.http, APP, endpoint(jackett, "jackett-api"), configured,
|
||||
{ adoptHosts: ["indexers.zurag.be", "jackett"], indexers: ["rutracker"] }, [], f.store.indexer,
|
||||
);
|
||||
const byWhat = Object.fromEntries(out.map((o) => [o.what + ":" + o.result, o]));
|
||||
// torrent9: jackett has it; repointed, key already right, tested.
|
||||
assert.ok(byWhat['jackett-api ("Torznab - Torrent9", jackett indexer torrent9):written']);
|
||||
// rutracker-ru and therarbg: jackett has neither — repointed with the key, untested, and said.
|
||||
assert.ok(byWhat['jackett-api ("Jackett - RARBG", jackett indexer therarbg):written']);
|
||||
assert.ok(byWhat['jackett-api ("Jackett - RARBG", jackett indexer therarbg):notice']);
|
||||
// rutracker is listed and nothing of the mesh's reads it: registered.
|
||||
assert.ok(byWhat["jackett-api (jackett indexer rutracker):created"]);
|
||||
assert.deepEqual(f.store.indexer.find((e) => e.id === 9), personal, "a person's jackett is not the mesh's");
|
||||
const t9 = f.store.indexer.find((e) => e.id === 6)!;
|
||||
assert.equal(t9.fields!.find((x) => x.name === "baseUrl")?.value, "http://ace.internal:20204");
|
||||
assert.equal(t9.enableRss, false, "disabled stays disabled");
|
||||
const created = f.store.indexer.find((e) => e.name === "Jackett - RuTracker")!;
|
||||
assert.equal(created.enableRss, true);
|
||||
assert.equal(f.calls.some((c) => c.method === "DELETE"), false, "nothing is ever deleted");
|
||||
});
|
||||
|
||||
test("jackett feeds rerun: nothing saved, and a remembered host keeps a moved jackett's feeds", async () => {
|
||||
const f = fakes({ indexers: [feed(6, "Torznab - Torrent9", "http://ace.internal:20204", "torrent9", "jackett-real")] });
|
||||
const configured = new Map(Object.entries(jackett.configured!));
|
||||
const out = await reconcileIndexers(f.http, APP, endpoint(jackett, "jackett-api"), configured, { adoptHosts: [], indexers: ["torrent9"] }, [], f.store.indexer);
|
||||
assert.deepEqual(out.map((o) => o.result), ["unchanged"]);
|
||||
assert.equal(f.saves().length, 0);
|
||||
// jackett moved to novox: the feed on ace.internal is still the mesh's because it was remembered.
|
||||
const moved = { ...jackett, host: "novox.internal" };
|
||||
const g = fakes({ indexers: [feed(6, "Torznab - Torrent9", "http://ace.internal:20204", "torrent9", "jackett-real")] });
|
||||
const saved = jackett.host;
|
||||
jackett.host = moved.host;
|
||||
try {
|
||||
const again = await reconcileIndexers(g.http, APP, endpoint(moved, "jackett-api"), configured, { adoptHosts: [], indexers: [] }, ["ace.internal"], g.store.indexer);
|
||||
assert.equal(again[0].result, "written");
|
||||
assert.equal(g.store.indexer[0].fields!.find((x) => x.name === "baseUrl")?.value, "http://novox.internal:20204");
|
||||
} finally {
|
||||
jackett.host = saved;
|
||||
}
|
||||
});
|
||||
|
||||
test("an enabled entry the app cannot test at the mesh's address is not saved", async () => {
|
||||
const f = fakes({ clients: [client(1, "NZBGet", "Nzbget", "nzbget", 6789, "nzb-real")] });
|
||||
const elsewhere = { ...nzbget, port: 1 };
|
||||
const out = await reconcileClient(f.http, APP, NZBGET, "NZBGet", endpoint(elsewhere, "nzbget-api"), f.store.downloadclient);
|
||||
assert.equal(out[0].result, "refused");
|
||||
assert.equal(f.store.downloadclient[0].fields!.find((x) => x.name === "host")?.value, "nzbget", "left as it was");
|
||||
});
|
||||
|
||||
test("bindings: loopback, no user, no credential are refused; the base path is normalised", () => {
|
||||
assert.equal(wanted("nzbget-api", { ...binding(nzbget, "nzbget-api"), at: "127.0.0.1" }, "x", true).ok, false);
|
||||
assert.equal(wanted("nzbget-api", binding({ ...nzbget, user: undefined }, "nzbget-api"), "x", true).ok, false);
|
||||
assert.equal(wanted("nzbget-api", binding(nzbget, "nzbget-api"), " \n", true).ok, false);
|
||||
const w = wanted("jackett-api", binding(jackett, "jackett-api", { "url-base": "jackett/" }), "k", false);
|
||||
assert.equal(w.ok && w.endpoint.urlBase, "/jackett");
|
||||
});
|
||||
|
||||
test("a feed is read whole: base path in the base URL or in the API path", () => {
|
||||
const e = feed(1, "x", "http://ace.internal:9117/jackett", "rutracker", "k");
|
||||
assert.deepEqual(jackettFeed(e), { host: "ace.internal", id: "rutracker" });
|
||||
assert.equal(jackettFeed({ ...e, implementation: "Newznab" }), undefined);
|
||||
assert.equal(jackettFeed({ ...e, fields: [f("baseUrl", "https://api.nzbgeek.info"), f("apiPath", "/api")] }), undefined);
|
||||
});
|
||||
|
||||
test("settings: names default to the provider's, adoption and registration read from the merged file", () => {
|
||||
assert.deepEqual(stepSettings({ node: "ace" }), { node: "ace", names: { "nzbget-api": "nzbget", "qbittorrent-api": "qbittorrent" }, indexers: { adoptHosts: [], indexers: [] } });
|
||||
const s = stepSettings({ node: "ace", downloads: { "nzbget-api": { name: "NZBGet" }, "jackett-api": { "adopt-hosts": ["jackett"], indexers: ["torrent9", 3] } } });
|
||||
assert.equal(s.names["nzbget-api"], "NZBGet");
|
||||
assert.deepEqual(s.indexers, { adoptHosts: ["jackett"], indexers: ["torrent9"] });
|
||||
});
|
||||
|
||||
// The four copies are one step. Where the siblings are checked out beside this module, they must
|
||||
// be byte-identical — a fix made in one and not the others is a bug in three apps.
|
||||
test("the step is the same in sonarr, radarr, lidarr and bookshelf", () => {
|
||||
const here = dirname(dirname(fileURLToPath(import.meta.url)));
|
||||
const modules = dirname(here);
|
||||
for (const file of ["downloads/settings.ts", "downloads/index.ts", "test/downloads.test.ts"]) {
|
||||
const mine = readFileSync(join(here, file), "utf8");
|
||||
for (const sibling of ["sonarr", "radarr", "lidarr", "bookshelf"]) {
|
||||
const theirs = join(modules, sibling, file);
|
||||
if (existsSync(theirs)) assert.equal(readFileSync(theirs, "utf8"), mine, `${sibling}/${file} differs`);
|
||||
}
|
||||
}
|
||||
});
|
||||
@@ -8,5 +8,5 @@
|
||||
"skipLibCheck": true,
|
||||
"noEmit": true
|
||||
},
|
||||
"include": ["client.ts", "index.ts", "tools/index.ts"]
|
||||
"include": ["client.ts", "index.ts", "tools/index.ts", "downloads/settings.ts", "downloads/index.ts"]
|
||||
}
|
||||
|
||||
File diff suppressed because one or more lines are too long
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user