Compare commits

..
Author SHA1 Message Date
jschoubben 4991c09c1f Convert the resolver from the module it replaces: forward, answer at 127.0.0.1, point the runtime at it
Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity).
On the machines it runs, the predecessor's dnsmasq answers every name: the mesh's own
itself, the rest forwarded to 1.1.1.1 and 8.8.8.8, its module's defaults; resolv.conf
names it alone at 127.0.0.1, and the container runtime's dns is the machine's tunnel
address, so the host and every container resolve the world through it. The nox module
forwarded nothing, listened on 127.0.0.55 — a convention of its own beside the one every
machine already followed — and read a machines file that the module's `facts` already
asks the mesh for, so taking it would have left an adopted machine with a resolv.conf
pointing at an address nothing answered on, and no upstream for anything else.

Now the resolver keeps `no-resolv` (the documented loop — finding its own address in
resolv.conf and becoming its own upstream — stays impossible) and forwards to the same
two explicit upstreams; listens on mesh0 and 127.0.0.1, which systemd-resolved does not
hold; requires `mesh-addressing`, since its data is the mesh's addresses; and writes the
runtime's `dns` into daemon.json beside whatever the machine had (ADR 0102), at this
machine's own address — `${machine:address}`, new in the controller. The runtime is not
restarted for it: it reads the key at start, not on reload, and a restart stops every
container; on the machine this replaces the value is already there.

resolv-conf names the resolver alone, as the predecessor's file did; its placeholder second
line was a fallback nothing ever reached. resolved-split-dns follows the address. The
mesh's suffix as a local domain comes with the machines file, so a mesh name the resolver
does not know is refused here rather than asked upstream. mDNS is not carried: no module
does it and the design says mesh names are not multicast names.
2026-09-23 23:53:51 +02:00
151 changed files with 937 additions and 2960 deletions
+1 -1
View File
@@ -18,7 +18,7 @@
"broker": "/var/lib/mesh/anthropic-consumer/broker" "broker": "/var/lib/mesh/anthropic-consumer/broker"
}, },
"emits": [ "emits": [
"usage.session" "module.anthropic-consumer.usage.session"
], ],
"resources": [ "resources": [
{ {
+1 -1
View File
@@ -123,7 +123,7 @@ async function emitUsage(body: Record<string, unknown>): Promise<void> {
await new Promise<void>((resolve) => { await new Promise<void>((resolve) => {
const child = spawn( const child = spawn(
process.execPath, process.execPath,
[main, "emit", "usage.session", JSON.stringify(body)], [main, "emit", "module.anthropic-consumer.usage.session", JSON.stringify(body)],
{ stdio: "inherit" }, { stdio: "inherit" },
); );
child.on("exit", () => resolve()); child.on("exit", () => resolve());
+1 -1
View File
@@ -18,7 +18,7 @@
"broker": "/var/lib/mesh/anthropic-manager/broker" "broker": "/var/lib/mesh/anthropic-manager/broker"
}, },
"emits": [ "emits": [
"usage.read" "module.anthropic-manager.usage.read"
], ],
"resources": [ "resources": [
{ {
+1 -1
View File
@@ -143,7 +143,7 @@ async function emitUsage(body: Record<string, unknown>): Promise<void> {
const main = process.env.MESH_TOOLS_MAIN ?? "/app/dist/main.js"; const main = process.env.MESH_TOOLS_MAIN ?? "/app/dist/main.js";
const { spawn } = await import("node:child_process"); const { spawn } = await import("node:child_process");
await new Promise<void>((resolve) => { await new Promise<void>((resolve) => {
const child = spawn(process.execPath, [main, "emit", "usage.read", JSON.stringify(body)], { const child = spawn(process.execPath, [main, "emit", "module.anthropic-manager.usage.read", JSON.stringify(body)], {
stdio: "inherit", stdio: "inherit",
}); });
child.on("exit", () => resolve()); child.on("exit", () => resolve());
+1 -1
View File
@@ -3,7 +3,7 @@
"version": "1", "version": "1",
"slug": "audit", "slug": "audit",
"consumes": [ "consumes": [
"**" "#"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/audit-logger/broker" "broker": "/var/lib/audit-logger/broker"
+3 -3
View File
@@ -15,16 +15,16 @@ test("audit-logger records every event to the trail as one line each", async ()
const path = join(dir, "audit.log"); const path = join(dir, "audit.log");
// The audit-logger's whole behaviour: consume everything, record it. // The audit-logger's whole behaviour: consume everything, record it.
await on("**", async (event) => record(event, path)); await on("#", async (event) => record(event, path));
process.env.MESH_MODULE = "umami"; process.env.MESH_MODULE = "umami";
process.env.MESH_NODE = "anchor"; process.env.MESH_NODE = "anchor";
await emit("site.created", { domain: "my-app" }); await emit("module.umami.site.created", { domain: "my-app" });
await emit("node.anchor.joined", { role: "worker" }); // a node event, not a module one await emit("node.anchor.joined", { role: "worker" }); // a node event, not a module one
const lines = (await readFile(path, "utf8")).trim().split("\n").map((l) => JSON.parse(l)); const lines = (await readFile(path, "utf8")).trim().split("\n").map((l) => JSON.parse(l));
assert.equal(lines.length, 2); assert.equal(lines.length, 2);
assert.deepEqual(lines.map((l) => l.type), ["umami.site.created", "node.anchor.joined"]); assert.deepEqual(lines.map((l) => l.type), ["module.umami.site.created", "node.anchor.joined"]);
assert.equal(lines[0].source, "umami"); assert.equal(lines[0].source, "umami");
assert.equal(lines[0].node, "anchor"); assert.equal(lines[0].node, "anchor");
assert.equal(lines[0].body.domain, "my-app"); assert.equal(lines[0].body.domain, "my-app");
+1 -1
View File
@@ -24,7 +24,7 @@ async function pollHistory(): Promise<void> {
for (const entry of entries) { for (const entry of entries) {
if (seen.has(entry.id)) continue; if (seen.has(entry.id)) continue;
if (primed) { if (primed) {
await emit("subtitle.downloaded", { await emit("module.bazarr.subtitle.downloaded", {
kind: entry.kind, kind: entry.kind,
title: entry.title, title: entry.title,
language: entry.language, language: entry.language,
+1 -1
View File
@@ -5,7 +5,7 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"subtitle.downloaded" "module.bazarr.subtitle.downloaded"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/bazarr/broker", "broker": "/var/lib/mesh/bazarr/broker",
+2 -2
View File
@@ -45,12 +45,12 @@ async function pollQueue(bookshelf: BookshelfClient): Promise<void> {
if (primed) { if (primed) {
// Entered the queue since last look — Bookshelf grabbed a release. // Entered the queue since last look — Bookshelf grabbed a release.
for (const [id, item] of now) { for (const [id, item] of now) {
if (!inQueue.has(id)) await emit("book.grabbed", { title: item.title, status: item.status }); if (!inQueue.has(id)) await emit("module.bookshelf.book.grabbed", { title: item.title, status: item.status });
} }
// Left the queue — imported and done, unless it was last seen failing. // Left the queue — imported and done, unless it was last seen failing.
for (const [id, item] of inQueue) { for (const [id, item] of inQueue) {
if (!now.has(id) && !FAILED_STATUSES.has(item.status)) { if (!now.has(id) && !FAILED_STATUSES.has(item.status)) {
await emit("download.completed", { title: item.title }); await emit("module.bookshelf.download.completed", { title: item.title });
} }
} }
} }
+2 -2
View File
@@ -6,8 +6,8 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"book.grabbed", "module.bookshelf.book.grabbed",
"download.completed" "module.bookshelf.download.completed"
], ],
"consumes": [], "consumes": [],
"own-secrets": { "own-secrets": {
-25
View File
@@ -1,25 +0,0 @@
ARG GO_BASE
ARG ALPINE_BASE
# builder's own image: the build machine itself, compiled into a container.
#
# **The source is not vendored here.** builder's actual code — cmd/mesh-builder, internal/builder,
# internal/catalogue — lives in the mesh-controller repository, the same control plane it is one
# half of. This module ships the packaging, not a second copy of the source, so the build context
# is the mesh-controller repository root (declared under build.artifacts[].context), and this
# Dockerfile compiles ./cmd/mesh-builder from it — the same shape route-proxy already uses for the
# same reason.
FROM ${GO_BASE} AS build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-builder ./cmd/mesh-builder
# Unlike mesh-controller's own FROM scratch (ADR 0006: nothing to audit but one binary), the build
# machine's whole job is shelling out to git and docker — it needs a real userland to do that in,
# not a second copy of either tool vendored into this image. apk installs both from the base's own
# packages, not fetched on its own at build time.
FROM ${ALPINE_BASE}
RUN apk add --no-cache docker-cli git
COPY --from=build /mesh-builder /usr/local/bin/mesh-builder
ENTRYPOINT ["/usr/local/bin/mesh-builder"]
+28 -38
View File
@@ -6,22 +6,19 @@
], ],
"claims": [ "claims": [
{ {
"name": "mesh-build-machine", "name": "the-build-machine",
"scope": "mesh" "scope": "node"
} }
], ],
"requires": [ "requires": [
"artifact-store", "artifact-store"
"npm-package-registry" ],
"emits": [
"module.builder.built"
], ],
"binds": {
"npm-package-registry": "/var/lib/mesh/builder/package-registry.json"
},
"secrets": {
"npm-package-registry": "/var/lib/mesh/builder/package-registry.secret"
},
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/builder/broker" "broker": "/var/lib/mesh/builder/broker",
"npm-password": "/var/lib/mesh/builder/npm-password"
}, },
"resources": [ "resources": [
{ {
@@ -41,13 +38,27 @@
"type": "file", "type": "file",
"path": "/var/lib/mesh/builder/builder.env", "path": "/var/lib/mesh/builder/builder.env",
"mode": "0600", "mode": "0600",
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n" "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
},
{
"id": "package-binding",
"type": "file",
"path": "/var/lib/mesh/builder/package-registry.json",
"mode": "0600",
"merge": "json",
"protected": [
"provision",
"from",
"at",
"as"
],
"content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n"
}, },
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "mesh-builder", "name": "mesh-builder",
"artifact": "server", "image": "mesh-builder@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"env-file": [ "env-file": [
"/var/lib/mesh/builder/builder.env" "/var/lib/mesh/builder/builder.env"
], ],
@@ -57,32 +68,11 @@
"/var/run/docker.sock:/var/run/docker.sock" "/var/run/docker.sock:/var/run/docker.sock"
], ],
"restart-on": [ "restart-on": [
"builder-env" "builder-env",
"package-binding",
"needs-npm-password"
], ],
"network": "host" "network": "host"
} }
], ]
"build": {
"artifacts": [
{
"name": "server",
"kind": "image",
"from": "Dockerfile",
"context": {
"repository": "https://git.novox.be/novox/mesh-controller.git",
"ref": "main"
}
}
],
"on": [
{
"arg": "GO_BASE",
"image": "golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
},
{
"arg": "ALPINE_BASE",
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
}
]
}
} }
+2 -2
View File
@@ -22,8 +22,8 @@
"broker": "/var/lib/mesh/cloudflare-dns/broker" "broker": "/var/lib/mesh/cloudflare-dns/broker"
}, },
"emits": [ "emits": [
"record.created", "module.cloudflare-dns.record.created",
"record.removed" "module.cloudflare-dns.record.removed"
], ],
"resources": [ "resources": [
{ {
+2 -2
View File
@@ -20,7 +20,7 @@ runProvisioner("public-dns", {
async create(p: Provision): Promise<void> { async create(p: Provision): Promise<void> {
const fqdn = cloudflare.nameFor(p.as); const fqdn = cloudflare.nameFor(p.as);
await cloudflare.upsert(fqdn); await cloudflare.upsert(fqdn);
await announce("record.created", { await announce("module.cloudflare-dns.record.created", {
name: fqdn, name: fqdn,
target: cloudflare.ingress, target: cloudflare.ingress,
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
@@ -30,7 +30,7 @@ runProvisioner("public-dns", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
const fqdn = cloudflare.nameFor(p.as); const fqdn = cloudflare.nameFor(p.as);
await cloudflare.remove(fqdn); await cloudflare.remove(fqdn);
await announce("record.removed", { name: fqdn, consumer: p.as }); await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: p.as });
}, },
}); });
+1 -1
View File
@@ -58,7 +58,7 @@
"/var/lib/de-spiegel/server.env" "/var/lib/de-spiegel/server.env"
], ],
"ports": [ "ports": [
"35621" "35621:35621"
], ],
"secrets-in-environment": "the application's own code reads SMTP_AUTH_USER/PASS from the environment (de-spiegel server/index.js); converting is that repository's change" "secrets-in-environment": "the application's own code reads SMTP_AUTH_USER/PASS from the environment (de-spiegel server/index.js); converting is that repository's change"
} }
-43
View File
@@ -1,43 +0,0 @@
# dhcpcd
The uplink seat's module for a machine whose own network is dhcpcd's (novox/hq ADR 0117). It
asks two things of dhcpcd, and nothing else: leave the resolver file to the mesh, and leave the
private network's interface alone. It never declares an interface, an address, a route, a
wireless network or its credentials — the link dhcpcd keeps is the only channel the mesh reaches
the machine over.
## What it writes
Two lines into `/etc/dhcpcd.conf`, as the mesh's marked region (`into: block`) — dhcpcd reads no
drop-in directory, so the mesh writes into its one file rather than over it (ADR 0102):
- `nohook resolv.conf` — dhcpcd's resolv.conf hook rewrites `/etc/resolv.conf` on every lease it
takes or renews, which would silently replace the resolver `resolv-conf` names.
- `denyinterfaces mesh0` — dhcpcd never asks for a lease on the private network's interface, and
never takes it down. dhcpcd leaves a point-to-point interface alone by default; this says so
rather than relying on it.
**At the start of the file** (`at: start`). Both are global options, and dhcpcd reads every line
after an `interface` or `ssid` line as that interface's own. A configured machine's file ends in
exactly such a block (the interface, its static address), so appended at the end these two would
quietly apply to one interface only.
## Why it declares no service
dhcpcd is the machine's, not the mesh's. The mesh never starts, stops or enables it: stopping it
drops the address the machine is reached at, and a module unassigned by mistake must not be able
to do that. And there is nothing to reload it with — `dhcpcd.service` reports `CanReload=no`, and
a restart drops the lease. So the two lines take effect at **dhcpcd's next start**.
On an adopted machine that is normally no gap: the predecessor wrote the same `nohook` line, and
it is already in force. **On a machine that was not adopted, it is one:** until dhcpcd next
starts (a reboot, or the operator restarting it in a window of their choosing), a lease renewal
still rewrites `/etc/resolv.conf`, and `resolv-conf` puts it back at the next push. Assign this
module before `resolv-conf` on such a machine, and restart dhcpcd once, by hand, when losing the
link for a moment is acceptable.
## One manager per machine
It claims `the-uplink`: a machine runs one network manager, and assigning a second module that
claims the seat is refused. Assigning this one to a machine whose network is NetworkManager's
installs the package and writes the two lines, and starts nothing.
-30
View File
@@ -1,30 +0,0 @@
{
"module": "dhcpcd",
"version": "1",
"capabilities": [
"package-manager",
"service-manager"
],
"claims": [
{
"name": "node-uplink",
"scope": "node"
}
],
"resources": [
{
"id": "package",
"type": "package",
"package": "dhcpcd"
},
{
"id": "config",
"type": "file",
"path": "/etc/dhcpcd.conf",
"mode": "0644",
"into": "block",
"at": "start",
"content": "# The mesh's two lines (module dhcpcd, novox/hq ADR 0117). Global options, so\n# kept above any interface line; read at dhcpcd's next start.\nnohook resolv.conf\ndenyinterfaces mesh0\n"
}
]
}
+1 -1
View File
@@ -33,7 +33,7 @@ async function pollCatalog(): Promise<void> {
for (const tag of tags) { for (const tag of tags) {
const id = `${repo}:${tag}`; const id = `${repo}:${tag}`;
if (!seen.has(id)) { if (!seen.has(id)) {
if (primed) await emit("image.pushed", { repo, tag }); if (primed) await emit("module.registry.image.pushed", { repo, tag });
seen.add(id); seen.add(id);
} }
} }
+3 -9
View File
@@ -10,14 +10,14 @@
"claims": [ "claims": [
{ {
"name": "the-artifact-store", "name": "the-artifact-store",
"scope": "mesh" "scope": "node"
} }
], ],
"capabilities": [ "capabilities": [
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"image.pushed" "module.registry.image.pushed"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/registry/broker" "broker": "/var/lib/mesh/registry/broker"
@@ -42,12 +42,6 @@
"path": "/var/lib/mesh/registry", "path": "/var/lib/mesh/registry",
"mode": "0700" "mode": "0700"
}, },
{
"id": "registry-data",
"type": "directory",
"path": "/var/lib/mesh-registry",
"mode": "0700"
},
{ {
"id": "store", "id": "store",
"type": "container", "type": "container",
@@ -57,7 +51,7 @@
"5000:5000" "5000:5000"
], ],
"volumes": [ "volumes": [
"/var/lib/mesh-registry:/var/lib/registry" "mesh-registry-data:/var/lib/registry"
] ]
} }
] ]
+2 -2
View File
@@ -20,10 +20,10 @@ async function poll(): Promise<void> {
const now = new Map((await dnsmasq.answeredNames()).map((a) => [a.name, a.address])); const now = new Map((await dnsmasq.answeredNames()).map((a) => [a.name, a.address]));
if (primed) { if (primed) {
for (const [name, address] of now) { for (const [name, address] of now) {
if (!known.has(name)) await emit("name.added", { name, address }); if (!known.has(name)) await emit("module.dnsmasq.name.added", { name, address });
} }
for (const [name] of known) { for (const [name] of known) {
if (!now.has(name)) await emit("name.removed", { name }); if (!now.has(name)) await emit("module.dnsmasq.name.removed", { name });
} }
} }
known.clear(); known.clear();
File diff suppressed because one or more lines are too long
+2 -2
View File
@@ -6,7 +6,7 @@
], ],
"claims": [ "claims": [
{ {
"name": "node-intrusion-prevention", "name": "the-intrusion-prevention",
"scope": "node" "scope": "node"
} }
], ],
@@ -33,7 +33,7 @@
"type": "file", "type": "file",
"path": "/etc/fail2ban/jail.local", "path": "/etc/fail2ban/jail.local",
"mode": "0644", "mode": "0644",
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n" "content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
}, },
{ {
"id": "jail-sshd", "id": "jail-sshd",
+1 -1
View File
@@ -23,7 +23,7 @@ COPY . .
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are # The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
# symlinks to a launcher that requires its library relatively — resolved away when the base image # symlinks to a launcher that requires its library relatively — resolved away when the base image
# was assembled. # was assembled.
RUN node /app/node_modules/typescript/bin/tsc client.ts token.ts index.ts provisioner/index.ts tools/index.ts \ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE} FROM ${RUNTIME_BASE}
+43 -102
View File
@@ -4,7 +4,6 @@
// does. // does.
import { readFileSync } from "node:fs"; import { readFileSync } from "node:fs";
import { ConfiguredToken, MintedToken, type TokenSource } from "./token.js";
/** A repository, trimmed to what the mesh cares about. */ /** A repository, trimmed to what the mesh cares about. */
export interface GiteaRepo { export interface GiteaRepo {
@@ -54,60 +53,44 @@ function meshConfig(file?: string): Record<string, string> {
export class GiteaClient { export class GiteaClient {
readonly baseUrl: string; readonly baseUrl: string;
private readonly tokens: TokenSource; private cachedUsername: string | null = null;
/** A token given as a string is one somebody configured; a source decides for itself (token.ts). */ constructor(
constructor(url: string, token: string | TokenSource) { url: string,
private readonly token: string,
) {
this.baseUrl = url.replace(/\/+$/, ""); this.baseUrl = url.replace(/\/+$/, "");
this.tokens = typeof token === "string" ? new ConfiguredToken(token) : token;
} }
/** /**
* Build from the module's resolved environment. The URL comes from MESH_GITEA_URL (the mesh's own * Build from the module's resolved environment. URL and token come from MESH_GITEA_URL /
* name), falling back to the bare GITEA_URL and to the forge's loopback port. The token, in order: * MESH_GITEA_TOKEN (the mesh's own names), falling back to the bare GITEA_* names and, for the
* one configured in settings or the environment (MESH_GITEA_TOKEN / GITEA_TOKEN), which wins; else * URL, to the forge's loopback port. A token is required — without one there is no authenticated
* one the module mints for itself with the admin account the vault delivered and keeps in its own * call to make, so this throws rather than hand back a client that fails on first use.
* state (token.ts; hq issue 100). Throws only when neither is possible, naming what is missing,
* rather than hand back a client that fails on first use.
*/ */
static fromEnv(env: NodeJS.ProcessEnv = process.env): GiteaClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): GiteaClient {
const cfg = meshConfig(env.MESH_GITEA_CONFIG_FILE); const cfg = meshConfig(env.MESH_GITEA_CONFIG_FILE);
const url = cfg.url ?? env.MESH_GITEA_URL ?? env.GITEA_URL ?? `http://127.0.0.1:${env.GITEA_PORT ?? "3000"}`; const url = cfg.url ?? env.MESH_GITEA_URL ?? env.GITEA_URL ?? `http://127.0.0.1:${env.GITEA_PORT ?? "3000"}`;
const configured = cfg.token ?? env.MESH_GITEA_TOKEN ?? env.GITEA_TOKEN; const token = cfg.token ?? env.MESH_GITEA_TOKEN ?? env.GITEA_TOKEN;
if (configured) return new GiteaClient(url, new ConfiguredToken(configured)); if (!token) throw new Error("no Gitea token — set MESH_GITEA_TOKEN");
return new GiteaClient(url, MintedToken.fromEnv(url, env)); return new GiteaClient(url, token);
} }
/**
* One authenticated call. A 401 is the forge saying the token is not one it knows — the case
* after the forge's data was restored, or after somebody revoked it — so the source is asked to
* renew once and the call is repeated with the new token. A configured token has nothing to renew
* with, and its source says so.
*/
private async request<T = unknown>(path: string, options: RequestInit = {}): Promise<T> { private async request<T = unknown>(path: string, options: RequestInit = {}): Promise<T> {
let token = await this.tokens.current(); const res = await fetch(`${this.baseUrl}/api/v1${path}`, {
let res = await this.send(path, options, token); ...options,
if (res.status === 401) { headers: {
token = await this.tokens.renew(token); "Content-Type": "application/json",
res = await this.send(path, options, token); Authorization: `token ${this.token}`,
} ...(options.headers as Record<string, string> | undefined),
},
});
if (!res.ok) throw new Error(`Gitea API ${path}: ${res.status} ${await res.text()}`); if (!res.ok) throw new Error(`Gitea API ${path}: ${res.status} ${await res.text()}`);
if (res.status === 204) return null as T; if (res.status === 204) return null as T;
const text = await res.text(); const text = await res.text();
return (text ? JSON.parse(text) : null) as T; return (text ? JSON.parse(text) : null) as T;
} }
private send(path: string, options: RequestInit, token: string): Promise<Response> {
return fetch(`${this.baseUrl}/api/v1${path}`, {
...options,
headers: {
"Content-Type": "application/json",
Authorization: `token ${token}`,
...(options.headers as Record<string, string> | undefined),
},
});
}
/** Generic authenticated API call — the escape hatch for endpoints without a dedicated method. /** Generic authenticated API call — the escape hatch for endpoints without a dedicated method.
* Path is relative to /api/v1. */ * Path is relative to /api/v1. */
async api<T = unknown>(path: string, options: RequestInit = {}): Promise<T> { async api<T = unknown>(path: string, options: RequestInit = {}): Promise<T> {
@@ -352,34 +335,24 @@ export class GiteaAdmin {
GiteaAdmin.fail("/orgs", res); GiteaAdmin.fail("/orgs", res);
} }
/** Ensure the org's package team exists with exactly these units, and return its id. Found or /** Ensure the org's package team exists, granting read+write on packages, and return its id. The
* created, the units are applied either way — a team is configuration the reconcile loop owns, * team is found by name if it is already there, created otherwise; a lost create race is resolved
* the same as a user's password, so a unit this code gains reaches a team that already exists * by re-listing. */
* rather than only the next mesh raised from scratch. A lost create race is resolved by
* re-listing. */
async ensureTeam(org: string, team: string, packageWrite: boolean): Promise<number> { async ensureTeam(org: string, team: string, packageWrite: boolean): Promise<number> {
// The units a consumer needs, and no more. `units_map` is exhaustive — a unit not named is a
// unit the team does not have — so code read must be said here: without it gitea answers a
// member's clone of a private repository with "not found", which is how the builder's first
// credentialed clone failed against a team that named only packages.
const units = {
permission: "read",
units_map: { "repo.code": "read", "repo.packages": packageWrite ? "write" : "read" },
includes_all_repositories: true,
can_create_org_repo: false,
};
const found = await this.findTeam(org, team); const found = await this.findTeam(org, team);
if (found !== null) { if (found !== null) return found;
const patch = await this.request(`/teams/${found}`, {
method: "PATCH",
body: JSON.stringify({ name: team, ...units }),
});
if (patch.status === 200) return found;
GiteaAdmin.fail(`/teams/${found}`, patch);
}
const res = await this.request(`/orgs/${encodeURIComponent(org)}/teams`, { const res = await this.request(`/orgs/${encodeURIComponent(org)}/teams`, {
method: "POST", method: "POST",
body: JSON.stringify({ name: team, ...units }), body: JSON.stringify({
name: team,
permission: "read",
// Package access is a per-unit grant; the team needs write on the packages unit and nothing
// else. includes_all_repositories keeps the team's repo view whole without widening its
// repo permission beyond read.
units_map: { "repo.packages": packageWrite ? "write" : "read" },
includes_all_repositories: true,
can_create_org_repo: false,
}),
}); });
if (res.status === 201) return Number(res.body?.id); if (res.status === 201) return Number(res.body?.id);
if (res.status === 422 || res.status === 409) { if (res.status === 422 || res.status === 409) {
@@ -390,18 +363,14 @@ export class GiteaAdmin {
} }
private async findTeam(org: string, team: string): Promise<number | null> { private async findTeam(org: string, team: string): Promise<number | null> {
const res = await this.request(`/orgs/${encodeURIComponent(org)}/teams?limit=50`); const res = await this.request(`/orgs/${encodeURIComponent(org)}/teams`);
if (res.status !== 200) return null; if (res.status !== 200) return null;
const match = (res.body as any[] | null)?.find((t) => t?.name === team); const match = (res.body as any[] | null)?.find((t) => t?.name === team);
return match ? Number(match.id) : null; return match ? Number(match.id) : null;
} }
/** Ensure a user exists with exactly this password. Created if absent; if already there, its /** Ensure a user exists with exactly this password. Created if absent; if already there, its
* password is patched — so the mesh minting a new secret takes on the next reconcile. * password is patched — so the mesh minting a new secret takes on the next reconcile. */
*
* The edit path is taken only when the user actually exists. A 422 from the create is also what
* a plain validation failure returns, and reading it as "already there" made the follow-up edit
* 404 — burying the create's own message, which is the one that says what is actually wrong. */
async ensureUser(username: string, password: string, email: string): Promise<void> { async ensureUser(username: string, password: string, email: string): Promise<void> {
const res = await this.request("/admin/users", { const res = await this.request("/admin/users", {
method: "POST", method: "POST",
@@ -409,18 +378,13 @@ export class GiteaAdmin {
}); });
if (res.status === 201) return; if (res.status === 201) return;
if (res.status === 422 || res.status === 409) { if (res.status === 422 || res.status === 409) {
const seen = await this.request(`/users/${encodeURIComponent(username)}`); const patch = await this.request(`/admin/users/${encodeURIComponent(username)}`, {
if (seen.status === 200) { method: "PATCH",
const patch = await this.request(`/admin/users/${encodeURIComponent(username)}`, { // login_name is required by the admin edit endpoint; for a local user it is the username.
method: "PATCH", body: JSON.stringify({ login_name: username, password, must_change_password: false }),
// login_name is required by the admin edit endpoint; for a local user it is the username. });
// active and prohibit_login: a deactivated or login-prohibited user is refused like a wrong if (patch.status === 200) return;
// password, so the provisioner's check reports it lost; applying again must undo both. GiteaAdmin.fail(`/admin/users/${username}`, patch);
body: JSON.stringify({ login_name: username, password, must_change_password: false, active: true, prohibit_login: false }),
});
if (patch.status === 200) return;
GiteaAdmin.fail(`/admin/users/${username}`, patch);
}
} }
GiteaAdmin.fail("/admin/users", res); GiteaAdmin.fail("/admin/users", res);
} }
@@ -435,29 +399,6 @@ export class GiteaAdmin {
GiteaAdmin.fail(`/teams/${teamId}/members/${username}`, res); GiteaAdmin.fail(`/teams/${teamId}/members/${username}`, res);
} }
/**
* Whether a consumer's user logs in with exactly this password and is still a member of the
* package team. Read-only: the password is checked as the consumer presents it, basic auth on the
* API, and membership through the admin API. `false` for a refused login or a missing member; any
* other answer rejects (novox/hq issue 120).
*/
async holdsTeamMember(org: string, team: string, username: string, password: string): Promise<boolean> {
const me = await fetch(`${this.baseUrl}/api/v1/user`, {
headers: { Authorization: "Basic " + Buffer.from(`${username}:${password}`).toString("base64") },
});
if (me.status === 401 || me.status === 403) return false;
if (me.status !== 200) throw new Error(`Gitea GET /user as ${username}: ${me.status}`);
const teams = await this.request(`/orgs/${encodeURIComponent(org)}/teams?limit=50`);
if (teams.status === 404) return false;
if (teams.status !== 200) GiteaAdmin.fail(`/orgs/${org}/teams`, teams);
const found = (teams.body as { id: number; name: string }[]).find((t) => t.name === team);
if (!found) return false;
const member = await this.request(`/teams/${found.id}/members/${encodeURIComponent(username)}`);
if (member.status === 200 || member.status === 204) return true;
if (member.status === 404) return false;
GiteaAdmin.fail(`/teams/${found.id}/members/${username}`, member);
}
/** Delete a user, purging what they own. A 404 means the mesh already withdrew them — success, not /** Delete a user, purging what they own. A 404 means the mesh already withdrew them — success, not
* an error, so a re-run of remove is safe. */ * an error, so a re-run of remove is safe. */
async deleteUser(username: string): Promise<void> { async deleteUser(username: string): Promise<void> {
+3 -18
View File
@@ -16,9 +16,7 @@
import { emit } from "@novox/mesh-sdk/events"; import { emit } from "@novox/mesh-sdk/events";
import { GiteaClient } from "./client.js"; import { GiteaClient } from "./client.js";
// Without a way to a token — configured, or mintable with the admin account (token.ts) — there is // Without a token there is nothing to watch; log and stay quiet rather than crash the runtime.
// nothing to watch; log and stay quiet rather than crash the runtime. With one, the first poll mints
// or reuses the token, so the runtime's start also shows what it did about it.
let gitea: GiteaClient | null = null; let gitea: GiteaClient | null = null;
try { try {
gitea = GiteaClient.fromEnv(); gitea = GiteaClient.fromEnv();
@@ -35,7 +33,7 @@ async function pollRepos(client: GiteaClient): Promise<void> {
for (const repo of repos) { for (const repo of repos) {
if (!seen.has(repo.full_name)) { if (!seen.has(repo.full_name)) {
if (primed) { if (primed) {
await emit("repo.created", { await emit("module.gitea.repo.created", {
full_name: repo.full_name, full_name: repo.full_name,
owner: repo.owner, owner: repo.owner,
name: repo.name, name: repo.name,
@@ -51,21 +49,8 @@ async function pollRepos(client: GiteaClient): Promise<void> {
if (gitea) { if (gitea) {
const client = gitea; const client = gitea;
// A poll that fails says so once, not once a minute: the same reason repeating (the forge not up
// yet, the admin account refused on a restored forge) is one fact, and a recovery is worth a line.
let failing: string | null = null;
const tick = (fn: () => Promise<void>, everyMs: number): void => { const tick = (fn: () => Promise<void>, everyMs: number): void => {
const run = (): void => const run = (): void => void fn().catch((err) => console.error(`[gitea] ${err}`));
void fn()
.then(() => {
if (failing !== null) console.log("[gitea] watching again");
failing = null;
})
.catch((err) => {
const why = err instanceof Error ? err.message : String(err);
if (why !== failing) console.error(`[gitea] not watching until this clears — ${why}`);
failing = why;
});
setInterval(run, everyMs); setInterval(run, everyMs);
run(); run();
}; };
+30 -62
View File
@@ -11,36 +11,28 @@
"name": "gitea" "name": "gitea"
}, },
"route": { "route": {
"web": { "label": "git",
"label": "git", "port": 3000
"port": 3000
},
"internal-api-refused": {
"label": "git",
"path": "/api/internal",
"deny": true,
"priority": 100000
}
} }
}, },
"binds": { "binds": {
"postgres-database": "${dir:state}/database.json", "postgres-database": "/var/lib/gitea/database.json",
"route": "${dir:state}/route.json" "route": "/var/lib/gitea/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "${dir:state}/database.secret", "postgres-database": "/var/lib/gitea/database.secret",
"secret": { "secret": {
"internal-token": "${dir:state}/internal-token.secret", "internal-token": "/var/lib/gitea/internal-token.secret",
"admin": "${dir:state}/admin.secret" "admin": "/var/lib/gitea/admin.secret"
} }
}, },
"capabilities": [ "capabilities": [
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"repo.created", "module.gitea.repo.created",
"issue.opened", "module.gitea.issue.opened",
"pull.merged" "module.gitea.pull.merged"
], ],
"listens": [ "listens": [
{ {
@@ -50,39 +42,25 @@
"why": "the forge, over http" "why": "the forge, over http"
}, },
{ {
"port": 22, "port": 2222,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "git over ssh, gitea's own unmodified sshd. Published on the machine's own side at 222, the mesh's fixed public convention \u2014 not 22, which the machine's own daemon holds and a module does not take" "why": "git over ssh. Not 22: the machine's own daemon holds that, and a module does not take it"
} }
], ],
"serves": { "serves": {
"npm-package-registry": { "package-registry": {
"scheme": "http", "scheme": "http",
"port": 3000, "port": 3000,
"npm-path": "/api/packages/novox/npm/" "npm-path": "/api/packages/novox/npm/"
},
"git": {
"scheme": "http",
"port": 3000
} }
}, },
"receives": { "receives": {
"npm-package-registry": "${dir:grants}/npm.json" "package-registry": "/var/lib/gitea/grants/mesh.json"
}, },
"grants": { "grants": {
"npm-package-registry": "${dir:grants}" "package-registry": "/var/lib/gitea/grants"
}, },
"claims": [
{
"name": "npm-package-registry",
"scope": "mesh"
},
{
"name": "git",
"scope": "mesh"
}
],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/gitea/broker" "broker": "/var/lib/mesh/gitea/broker"
}, },
@@ -93,33 +71,29 @@
"path": "/var/lib/mesh/gitea", "path": "/var/lib/mesh/gitea",
"mode": "0700" "mode": "0700"
}, },
{
"id": "runtime-state",
"type": "directory",
"path": "/var/lib/mesh/gitea/state",
"mode": "0700"
},
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",
"mode": "0700", "path": "/var/lib/gitea",
"place": "." "mode": "0700"
}, },
{ {
"id": "grants", "id": "grants",
"type": "directory", "type": "directory",
"path": "/var/lib/gitea/grants",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "server-env", "id": "server-env",
"type": "file", "type": "file",
"path": "${dir:state}/server.env", "path": "/var/lib/gitea/server.env",
"mode": "0600", "mode": "0600",
"content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n" "content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n"
}, },
{ {
"id": "data", "id": "data",
"type": "directory", "type": "directory",
"path": "/services/gitea/gitea",
"mode": "0700", "mode": "0700",
"owner": "1000:1000" "owner": "1000:1000"
}, },
@@ -134,14 +108,14 @@
"USER_GID": "1000" "USER_GID": "1000"
}, },
"env-file": [ "env-file": [
"${dir:state}/server.env" "/var/lib/gitea/server.env"
], ],
"ports": [ "ports": [
"3000", "3000",
"222:22" "2222:22"
], ],
"volumes": [ "volumes": [
"${dir:data}:/data" "/services/gitea/gitea:/data"
], ],
"secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it" "secrets-in-environment": "gitea honours GITEA__database__PASSWD__FILE and GITEA__security__INTERNAL_TOKEN__FILE; convertible, awaiting a bed that proves it"
}, },
@@ -157,11 +131,11 @@
"MESH_GITEA_ADMIN_USER": "mesh-admin" "MESH_GITEA_ADMIN_USER": "mesh-admin"
}, },
"env-file": [ "env-file": [
"${dir:state}/server.env" "/var/lib/gitea/server.env"
], ],
"volumes": [ "volumes": [
"${dir:data}:/data", "/services/gitea/gitea:/data",
"${dir:state}/admin.secret:/run/secrets/admin:ro" "/var/lib/gitea/admin.secret:/run/secrets/admin:ro"
], ],
"args": [ "args": [
"/bin/sh", "/bin/sh",
@@ -186,9 +160,8 @@
"volumes": [ "volumes": [
"/var/lib/mesh/gitea/broker:/run/secrets/broker:ro", "/var/lib/mesh/gitea/broker:/run/secrets/broker:ro",
"/var/lib/mesh/gitea/config.json:/run/config/config.json:ro", "/var/lib/mesh/gitea/config.json:/run/config/config.json:ro",
"${dir:grants}:${dir:grants}:ro", "/var/lib/gitea/grants:/var/lib/gitea/grants:ro",
"${dir:state}/admin.secret:/run/secrets/admin:ro", "/var/lib/gitea/admin.secret:/run/secrets/admin:ro"
"/var/lib/mesh/gitea/state:/run/state"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
@@ -196,8 +169,7 @@
"MESH_GITEA_CONFIG_FILE": "/run/config/config.json", "MESH_GITEA_CONFIG_FILE": "/run/config/config.json",
"MESH_GITEA_ADMIN_USER": "mesh-admin", "MESH_GITEA_ADMIN_USER": "mesh-admin",
"MESH_GITEA_ADMIN_PASSWORD_FILE": "/run/secrets/admin", "MESH_GITEA_ADMIN_PASSWORD_FILE": "/run/secrets/admin",
"MESH_GITEA_STATE_DIR": "/run/state", "MESH_RECEIVES": "/var/lib/gitea/grants/mesh.json"
"MESH_RECEIVES": "${dir:grants}/npm.json"
}, },
"artifact": "runtime", "artifact": "runtime",
"restart-on": [ "restart-on": [
@@ -207,11 +179,7 @@
], ],
"provides": [ "provides": [
{ {
"name": "npm-package-registry", "name": "package-registry",
"scope": "mesh"
},
{
"name": "git",
"scope": "mesh" "scope": "mesh"
} }
], ],
+1 -5
View File
@@ -4,12 +4,8 @@
"description": "gitea — git hosting. Its API client, tools and events live here (novox/hq ADR 0039).", "description": "gitea — git hosting. Its API client, tools and events live here (novox/hq ADR 0039).",
"type": "module", "type": "module",
"private": true, "private": true,
"scripts": {
"build": "tsc client.ts token.ts index.ts provisioner/index.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
"test": "npm run build && node --test --experimental-strip-types 'test/*.test.ts'"
},
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+7 -27
View File
@@ -1,15 +1,9 @@
// gitea's provisioner — the adapter that makes gitea a provider of the mesh // gitea's provisioner — the adapter that makes gitea a provider of the mesh `package-registry`
// `npm-package-registry` interface. The reconcile loop, the contributions file, and reading the // interface. The reconcile loop, the contributions file, and reading the mesh's minted password are
// mesh's minted password are the sdk harness's; this writes only the per-service half: how gitea // the sdk harness's; this writes only the per-service half: how gitea creates and removes a
// creates and removes a consumer's npm credential (novox/hq ADR 0048/0076). // consumer's npm credential (novox/hq ADR 0048/0076).
// //
// **A package registry seat is one per ecosystem (novox/hq ADR 0109).** gitea holds the npm seat // The `package-registry` interface: a consumer authenticates to the npm registry at
// (ADR 0110). Adding cargo or PyPI is adding a provision — another `provides` entry, another
// `receives` path and another registration below — not widening this one. `git`, which gitea also
// provides, mints nothing and so registers nothing here: the mesh's own repositories are public,
// and a clone credential is not yet decided (ADR 0111).
//
// The `npm-package-registry` interface: a consumer authenticates to the npm registry at
// `/api/packages/novox/npm/` with basic auth, as `as` with the password the mesh minted, and can // `/api/packages/novox/npm/` with basic auth, as `as` with the password the mesh minted, and can
// read and write packages under the `@novox` scope. The registry's npm owner is the gitea org // read and write packages under the `@novox` scope. The registry's npm owner is the gitea org
// `novox`; a consumer is a gitea *user* placed on that org's package team. // `novox`; a consumer is a gitea *user* placed on that org's package team.
@@ -32,11 +26,7 @@ const PACKAGE_TEAM = "packages";
const gitea = GiteaAdmin.fromEnv(); const gitea = GiteaAdmin.fromEnv();
// Where this registration's contributions land comes from $MESH_RECEIVES, never a path written runProvisioner("package-registry", {
// here: the mesh writes the file where the manifest's `receives` says, and a second copy of that
// path in code would drift from it. One variable carries one path, so a second registration in this
// module needs the mesh to say where each provision's file is — not yet possible, and not faked.
runProvisioner("npm-package-registry", {
async create(p: Provision): Promise<void> { async create(p: Provision): Promise<void> {
// The org and its package team are the same for every consumer; ensuring them per-create is // The org and its package team are the same for every consumer; ensuring them per-create is
// idempotent and needs no separate bootstrap step. // idempotent and needs no separate bootstrap step.
@@ -44,21 +34,11 @@ runProvisioner("npm-package-registry", {
const teamId = await gitea.ensureTeam(ORG, PACKAGE_TEAM, true); const teamId = await gitea.ensureTeam(ORG, PACKAGE_TEAM, true);
// The user carries the consumer's login and the mesh's minted password, set every run so a // The user carries the consumer's login and the mesh's minted password, set every run so a
// rotation takes. Membership of the package team is what grants read+write on packages. // rotation takes. Membership of the package team is what grants read+write on packages.
// await gitea.ensureUser(p.as, p.password, `${p.as}@localhost`);
// The address is gitea's own convention for one that is not real: its email validation
// requires a dotted domain, so `@localhost` was refused at create — the fault that had this
// grant retrying for a day — while `@noreply.localhost` is the shape gitea itself gives
// hidden addresses.
await gitea.ensureUser(p.as, p.password, `${p.as}@noreply.localhost`);
await gitea.addUserToTeam(teamId, p.as); await gitea.addUserToTeam(teamId, p.as);
}, },
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
await gitea.deleteUser(p.as); await gitea.deleteUser(p.as);
}, },
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return gitea.holdsTeamMember(ORG, PACKAGE_TEAM, p.as, p.password);
},
}); });
-313
View File
@@ -1,313 +0,0 @@
// What holds the module to its own token (token.ts; hq issue 100, the forge's tools): minted with
// the delivered admin account on the first call and kept at 0600, reused on the next start, minted
// afresh when the forge rejects it or the kept file is gone, and a refused admin account reported in
// plain words rather than crash-looped. A configured token still wins. And the tools register once
// there is a way to a token at all — before one exists.
//
// The forge is a fake: the four routes the module touches, with the same status codes gitea gives.
// Run against the compiled module (npm test builds first), the way the runtime loads it.
import { test, after } from "node:test";
import assert from "node:assert/strict";
import { createServer, type IncomingMessage, type ServerResponse } from "node:http";
import { mkdtemp, readFile, rm, stat, writeFile } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { collectTools } from "@novox/mesh-sdk/tools";
import { AdminRefused, MintedToken, TOKEN_SCOPES } from "../dist/token.js";
import { GiteaClient } from "../dist/client.js";
import "../dist/tools/index.js";
const ADMIN = "mesh-admin";
const PASSWORD = "the-vault-minted-this";
// ---- A fake forge: what the module sends, and what gitea would answer. ----
interface Forge {
url: string;
mints: number;
lastScopes: string[] | null;
tokens: Map<string, string>;
admins: Map<string, string>;
close(): Promise<void>;
}
function fakeForge(): Promise<Forge> {
const forge = {
mints: 0,
lastScopes: null as string[] | null,
tokens: new Map<string, string>(), // name -> value
scopesOf: new Map<string, string[]>(), // value -> scopes, so a route can enforce them like gitea does
admins: new Map([[ADMIN, PASSWORD]]),
};
// write:X implies read:X — gitea's own rule (models/auth/access_token_scope.go).
const covers = (scopes: string[], required: string): boolean =>
scopes.includes(required) || scopes.includes(`write:${required.split(":")[1]}`);
const json = (res: ServerResponse, status: number, body: unknown): void => {
res.writeHead(status, { "Content-Type": "application/json" });
res.end(body === null ? "" : JSON.stringify(body));
};
const body = (req: IncomingMessage): Promise<any> =>
new Promise((resolve) => {
let text = "";
req.on("data", (c) => (text += c));
req.on("end", () => resolve(text ? JSON.parse(text) : null));
});
const basic = (req: IncomingMessage): string | null => {
const h = req.headers.authorization ?? "";
if (!h.startsWith("Basic ")) return null;
const [user, pass] = Buffer.from(h.slice(6), "base64").toString().split(":");
return forge.admins.get(user) === pass ? user : null;
};
const server = createServer(async (req, res) => {
const url = new URL(req.url ?? "/", "http://fake");
const tokens = url.pathname.match(/^\/api\/v1\/users\/([^/]+)\/tokens(?:\/([^/]+))?$/);
if (tokens) {
const user = basic(req);
if (user === null || user !== decodeURIComponent(tokens[1])) return json(res, 401, { message: "auth required" });
if (req.method === "POST") {
const { name, scopes } = await body(req);
if (forge.tokens.has(name)) return json(res, 400, { message: "token name has already been used" });
forge.mints++;
forge.lastScopes = scopes;
const sha1 = `minted-${forge.mints}-${Math.random().toString(36).slice(2)}`;
forge.tokens.set(name, sha1);
forge.scopesOf.set(sha1, scopes);
return json(res, 201, { id: forge.mints, name, sha1, scopes, token_last_eight: sha1.slice(-8) });
}
if (req.method === "DELETE" && tokens[2]) {
const name = decodeURIComponent(tokens[2]);
if (!forge.tokens.has(name)) return json(res, 404, { message: "token not found" });
forge.tokens.delete(name);
return json(res, 204, null);
}
return json(res, 405, { message: "method not allowed" });
}
if (url.pathname === "/api/v1/user/repos") {
const h = req.headers.authorization ?? "";
const value = h.startsWith("token ") ? h.slice(6) : "";
if (![...forge.tokens.values()].includes(value)) return json(res, 401, { message: "token is required" });
// gitea 1.27.3: GET /user/repos sits under the `user` scope category, not `repository` —
// confirmed against the live forge. A token without read:user (or write:user) is refused here.
const scopes = forge.scopesOf.get(value) ?? [];
if (!covers(scopes, "read:user")) {
return json(res, 403, {
message: `token does not have at least one of required scope(s), required=[read:user]`,
});
}
return json(res, 200, [
{ full_name: "novox/hq", name: "hq", owner: { login: "novox" }, private: true, html_url: "http://fake/novox/hq" },
]);
}
return json(res, 404, { message: "no such route in the fake" });
});
return new Promise((resolve) => {
server.listen(0, "127.0.0.1", () => {
const { port } = server.address() as { port: number };
resolve({
url: `http://127.0.0.1:${port}`,
get mints() { return forge.mints; },
get lastScopes() { return forge.lastScopes; },
tokens: forge.tokens,
admins: forge.admins,
close: () => new Promise((r) => server.close(() => r())),
});
});
});
}
// ---- What the runtime's environment gives the module. ----
async function delivered(forge: Forge): Promise<{ env: NodeJS.ProcessEnv; file: string; logs: string[] }> {
const dir = await mkdtemp(join(tmpdir(), "gitea-"));
const passwordFile = join(dir, "admin.secret");
await writeFile(passwordFile, PASSWORD + "\n", { mode: 0o600 });
const state = join(dir, "state");
return {
env: {
MESH_GITEA_URL: forge.url,
MESH_GITEA_ADMIN_USER: ADMIN,
MESH_GITEA_ADMIN_PASSWORD_FILE: passwordFile,
MESH_GITEA_STATE_DIR: state,
},
file: join(state, "token"),
logs: [],
};
}
/** A client as a fresh process would build it: a new source over the kept file, its log captured. */
function minted(env: NodeJS.ProcessEnv, logs: string[]): GiteaClient {
const source = new MintedToken({
url: env.MESH_GITEA_URL!,
admin: env.MESH_GITEA_ADMIN_USER!,
passwordFile: env.MESH_GITEA_ADMIN_PASSWORD_FILE!,
file: join(env.MESH_GITEA_STATE_DIR!, "token"),
log: (l) => logs.push(l),
});
return new GiteaClient(env.MESH_GITEA_URL!, source);
}
const forge = await fakeForge();
after(() => forge.close());
test("first start: mints with the admin account, keeps the token at 0600, asks for two scopes only", async () => {
const { env, file, logs } = await delivered(forge);
const repos = await minted(env, logs).listRepos();
assert.equal(repos[0]?.full_name, "novox/hq");
assert.equal(forge.mints, 1);
assert.deepEqual(forge.lastScopes, ["write:repository", "write:issue", "read:user"]);
assert.deepEqual(forge.lastScopes, [...TOKEN_SCOPES]);
const token = forge.tokens.get("mesh-tools")!;
assert.equal(await readFile(file, "utf8"), token + "\n");
assert.equal((await stat(file)).mode & 0o777, 0o600);
// Said that it minted, and where it keeps it — never what it is.
assert.ok(logs.some((l) => l.startsWith("minted a token")), logs.join("\n"));
assert.ok(logs.every((l) => !l.includes(token) && !l.includes(PASSWORD)), logs.join("\n"));
});
test("second start: reuses the kept token, mints nothing", async () => {
const { env, logs } = await delivered(forge);
await minted(env, logs).listRepos();
const before = forge.mints;
const again: string[] = [];
await minted(env, again).listRepos();
assert.equal(forge.mints, before);
assert.ok(again.some((l) => l.startsWith("reusing the token kept at")), again.join("\n"));
assert.ok(again.every((l) => !l.includes(forge.tokens.get("mesh-tools")!)), again.join("\n"));
});
test("the forge rejects the kept token (its data was restored): minted afresh, once, and the call goes through", async () => {
const { env, file, logs } = await delivered(forge);
const client = minted(env, logs);
await client.listRepos();
const before = forge.mints;
forge.tokens.clear(); // the forge no longer knows any token — a restore from the predecessor
const repos = await client.listRepos();
assert.equal(repos.length, 1);
assert.equal(forge.mints, before + 1);
assert.equal(await readFile(file, "utf8"), forge.tokens.get("mesh-tools") + "\n");
assert.ok(logs.some((l) => l.startsWith("the forge rejected the kept token")), logs.join("\n"));
});
test("the kept file is gone but the forge still holds a token by that name: replaced, not refused", async () => {
const { env, file, logs } = await delivered(forge);
await minted(env, logs).listRepos();
const before = forge.mints;
await rm(file);
const repos = await minted(env, logs).listRepos();
assert.equal(repos.length, 1);
assert.equal(forge.mints, before + 1);
assert.equal([...forge.tokens.keys()].filter((n) => n === "mesh-tools").length, 1);
assert.ok(logs.some((l) => l.includes('already holds a token named "mesh-tools"')), logs.join("\n"));
});
test("concurrent first calls share one mint", async () => {
const { env, logs } = await delivered(forge);
const client = minted(env, logs);
const before = forge.mints;
await Promise.all([client.listRepos(), client.listRepos(), client.listRepos()]);
assert.equal(forge.mints, before + 1);
});
test("the admin account is refused: said plainly, nothing kept, and the next call fails the same way rather than crashing", async () => {
const { env, file, logs } = await delivered(forge);
forge.admins.delete(ADMIN); // the forge's data came from a predecessor; mesh-admin was never created there
try {
const client = minted(env, logs);
const before = forge.mints;
await assert.rejects(client.listRepos(), (err: unknown) => {
assert.ok(err instanceof AdminRefused, String(err));
assert.match(err.message, /refused the admin account "mesh-admin" \(401\)/);
assert.match(err.message, /admin-bootstrap step creates it/);
assert.match(err.message, /came from a predecessor/);
assert.ok(!err.message.includes(PASSWORD));
return true;
});
await assert.rejects(client.listRepos(), AdminRefused);
assert.equal(forge.mints, before);
await assert.rejects(stat(file), /ENOENT/);
// The account appears (the operator created it): the very next call mints and works.
forge.admins.set(ADMIN, PASSWORD);
assert.equal((await client.listRepos()).length, 1);
assert.equal(forge.mints, before + 1);
} finally {
forge.admins.set(ADMIN, PASSWORD);
}
});
test("one process shares one source per kept file — the watcher and the tools never renew against each other", async () => {
const { env } = await delivered(forge);
assert.equal(MintedToken.fromEnv(env.MESH_GITEA_URL!, env), MintedToken.fromEnv(env.MESH_GITEA_URL!, env));
});
test("a second process finds the token the first renewed, and reuses it instead of minting over it", async () => {
const { env, logs } = await delivered(forge);
const first = minted(env, logs);
const second = minted(env, logs);
await first.listRepos();
await second.listRepos(); // both hold the same kept token
const before = forge.mints;
forge.tokens.clear();
await first.listRepos(); // renews: one mint
await second.listRepos(); // rejected too — but the kept file already carries the renewed one
assert.equal(forge.mints, before + 1);
assert.ok(logs.some((l) => l.includes("is newer — reusing it")), logs.join("\n"));
});
test("a configured token wins, and is reported rather than minted over when the forge rejects it", async () => {
const { env } = await delivered(forge);
const before = forge.mints;
const client = GiteaClient.fromEnv({ ...env, MESH_GITEA_TOKEN: "one-somebody-pasted-in" });
await assert.rejects(client.listRepos(), /rejected the configured Gitea token \(401\)/);
assert.equal(forge.mints, before);
});
test("nothing to mint with and no token: the client says what is missing", async () => {
assert.throws(
() => GiteaClient.fromEnv({ MESH_GITEA_URL: forge.url, MESH_GITEA_ADMIN_USER: ADMIN }),
/set MESH_GITEA_TOKEN, or MESH_GITEA_ADMIN_PASSWORD_FILE, MESH_GITEA_STATE_DIR/,
);
});
test("the tools register once there is a way to a token, and the first call mints it", async () => {
const { env } = await delivered(forge);
const before = forge.mints;
const withAdmin = collectTools(env).find((c) => c.module === "gitea")!;
const withNothing = collectTools({}).find((c) => c.module === "gitea")!;
assert.equal(withNothing.tools.length, 0);
assert.deepEqual(
withAdmin.tools.map((t) => t.name),
[
"gitea_list_repos", "gitea_create_repo", "gitea_delete_repo",
"gitea_list_issues", "gitea_get_issue", "gitea_create_issue", "gitea_close_issue", "gitea_add_comment",
"gitea_list_pull_requests", "gitea_get_pull_request", "gitea_create_pull_request", "gitea_merge_pull_request",
"gitea_list_labels", "gitea_create_label",
"gitea_api",
],
);
assert.equal(forge.mints, before, "registering must not mint — the forge may not be up yet");
const result = (await withAdmin.tools.find((t) => t.name === "gitea_list_repos")!.run({})) as { repos: unknown[] };
assert.equal(result.repos.length, 1);
assert.equal(forge.mints, before + 1);
});
-253
View File
@@ -1,253 +0,0 @@
// The token the forge's tools and watcher authenticate with — and where it comes from.
//
// Nobody configures it. The forge is raised by the mesh, so there is no operator holding a token to
// paste in, and pasting one into settings would put a secret in the inventory in plaintext. What
// the mesh does deliver is the admin account: a login the manifest names and a password the vault
// minted and the host unsealed into a file (novox/hq ADR 0086). That account is enough to mint a
// token, so the module mints its own (hq issue 100, the forge's tools):
//
// - at first use, when none is kept: POST /users/{admin}/tokens over basic auth, with the two
// scopes the tools and the watcher need, and no more;
// - kept in the module's own state, a 0600 file, and read back on the next start — the forge
// hands a token's value out exactly once, so a token not kept is a token lost;
// - re-minted when the forge rejects it (401) or the kept file is gone. The one case that is not
// a fault: the forge's data was restored from a predecessor and the token the file names never
// existed there.
//
// An explicitly configured token still wins, and is never minted over: if it is rejected, that is
// reported, not repaired — somebody chose it.
//
// The token is never logged. Lines say that one was minted, reused or renewed, and where it is
// kept; never what it is.
import { chmodSync, mkdirSync, readFileSync, renameSync, writeFileSync } from "node:fs";
import { dirname, join } from "node:path";
/** The name the token carries in the forge's own list — one per mesh runtime, found by name. */
export const TOKEN_NAME = "mesh-tools";
/**
* The least the fifteen tools and the watcher need (gitea's route groups, 1.20+ scoped tokens):
* write:repository — create/delete repositories, pull requests (list/get/open/merge);
* write:issue — issues, comments, labels;
* read:user — GET /user/repos, which the watcher's poll and gitea_list_repos both call.
* It sits under the `user` category despite listing repositories, not `repository`
* — confirmed against the running forge (1.27.3), which answered
* `required=[read:user]` to a token carrying only the other two.
* Nothing under /admin, /orgs or write:user — the escape-hatch tool reaches only what these three cover.
*/
export const TOKEN_SCOPES: readonly string[] = ["write:repository", "write:issue", "read:user"];
/** Where a client's token comes from, and what to do when the forge says it is wrong. */
export interface TokenSource {
/** The token to authenticate with now; minted, read or configured. */
current(): Promise<string>;
/** The forge answered 401 to `rejected`. A fresh token, or a plain error when there is nothing to renew with. */
renew(rejected: string): Promise<string>;
}
/** A token somebody set — in settings or the environment. Never minted over. */
export class ConfiguredToken implements TokenSource {
constructor(private readonly token: string) {}
async current(): Promise<string> {
return this.token;
}
async renew(): Promise<string> {
throw new Error(
"the forge rejected the configured Gitea token (401). It was set explicitly (settings or MESH_GITEA_TOKEN), " +
"so the module does not mint over it — fix it, or unset it and the module mints its own",
);
}
}
/** The forge would not take the admin account: it is missing, or its password is not the one the mesh holds. */
export class AdminRefused extends Error {
constructor(admin: string, status: number) {
super(
`the forge refused the admin account "${admin}" (${status}) — it does not exist there, or its password is not ` +
`the one the vault delivered. The admin-bootstrap step creates it on a forge the mesh raised; a forge whose data ` +
`came from a predecessor does not have it. Create "${admin}" on the forge with the delivered password and the ` +
`token is minted on the next call — the tools stay registered and the watcher keeps trying`,
);
this.name = "AdminRefused";
}
}
export interface MintedTokenOptions {
/** The forge, e.g. http://127.0.0.1:3000. */
readonly url: string;
/** The admin login the manifest names. */
readonly admin: string;
/** The file the host unsealed the admin password into (ADR 0086). Read at mint time, so a rotation takes. */
readonly passwordFile: string;
/** Where the token is kept: a 0600 file in the module's own state. */
readonly file: string;
readonly name?: string;
readonly scopes?: readonly string[];
readonly log?: (line: string) => void;
readonly fetch?: typeof fetch;
}
/** The token the module mints for itself, kept in its state and renewed when the forge rejects it. */
export class MintedToken implements TokenSource {
private held: string | null = null;
private readFile = false;
private inflight: Promise<string> | null = null;
private readonly name: string;
private readonly scopes: readonly string[];
private readonly log: (line: string) => void;
private readonly fetchImpl: typeof fetch;
constructor(private readonly opts: MintedTokenOptions) {
this.name = opts.name ?? TOKEN_NAME;
this.scopes = opts.scopes ?? TOKEN_SCOPES;
this.log = opts.log ?? ((line) => console.log(`[gitea] ${line}`));
this.fetchImpl = opts.fetch ?? fetch;
}
/**
* Build from the runtime's environment: the forge's URL, the admin login and password file the
* manifest hands the runtime, and the module's state directory (MESH_GITEA_STATE_DIR, a directory
* the runtime mounts writable). Throws, naming what is missing, rather than hand back a source
* that cannot mint.
*/
static fromEnv(url: string, env: NodeJS.ProcessEnv = process.env): MintedToken {
const opts = MintedToken.optionsFromEnv(url, env);
// One source per kept file in a process. The watcher and the tools entrypoint both build a
// client in the same runtime; two sources over one file would each renew on a 401 and drop the
// other's token by name, forever. Shared, a renewal is one renewal.
const shared = MintedToken.shared.get(opts.file);
if (shared) return shared;
const source = new MintedToken(opts);
MintedToken.shared.set(opts.file, source);
return source;
}
private static readonly shared = new Map<string, MintedToken>();
private static optionsFromEnv(url: string, env: NodeJS.ProcessEnv): MintedTokenOptions {
const admin = env.MESH_GITEA_ADMIN_USER;
const passwordFile = env.MESH_GITEA_ADMIN_PASSWORD_FILE;
const stateDir = env.MESH_GITEA_STATE_DIR;
const missing = [
admin ? null : "MESH_GITEA_ADMIN_USER",
passwordFile ? null : "MESH_GITEA_ADMIN_PASSWORD_FILE",
stateDir ? null : "MESH_GITEA_STATE_DIR",
].filter((v): v is string => v !== null);
if (missing.length) {
throw new Error(`no Gitea token, and nothing to mint one with — set MESH_GITEA_TOKEN, or ${missing.join(", ")}`);
}
return { url, admin: admin!, passwordFile: passwordFile!, file: join(stateDir!, "token") };
}
async current(): Promise<string> {
if (this.held !== null) return this.held;
if (!this.readFile) {
this.readFile = true;
const kept = this.read();
if (kept !== null) {
this.held = kept;
this.log(`reusing the token kept at ${this.opts.file}`);
return kept;
}
}
return this.mint("no token kept — minting one");
}
async renew(rejected: string): Promise<string> {
// Another caller already renewed while this one was in flight with the old token.
if (this.held !== null && this.held !== rejected) return this.held;
// Or another process did, and kept it: use what is kept before minting over it.
const kept = this.read();
if (kept !== null && kept !== rejected) {
this.held = kept;
this.log(`the forge rejected the token held; the kept one at ${this.opts.file} is newer — reusing it`);
return kept;
}
this.held = null;
return this.mint("the forge rejected the kept token — minting a fresh one");
}
/** One mint at a time: concurrent first calls share it, rather than each minting its own. */
private mint(why: string): Promise<string> {
if (this.inflight === null) {
this.log(why);
this.inflight = this.doMint().finally(() => {
this.inflight = null;
});
}
return this.inflight;
}
private read(): string | null {
try {
const token = readFileSync(this.opts.file, "utf8").replace(/\n$/, "");
return token.length ? token : null;
} catch (err) {
if ((err as NodeJS.ErrnoException).code === "ENOENT") return null;
throw new Error(`cannot read the kept Gitea token at ${this.opts.file}: ${(err as Error).message}`);
}
}
/** Write the token at 0600, whole or not at all: a temp file beside it, then a rename. */
private keep(token: string): void {
mkdirSync(dirname(this.opts.file), { recursive: true, mode: 0o700 });
const tmp = `${this.opts.file}.tmp`;
writeFileSync(tmp, token + "\n", { mode: 0o600 });
chmodSync(tmp, 0o600);
renameSync(tmp, this.opts.file);
}
private async doMint(): Promise<string> {
let password: string;
try {
password = readFileSync(this.opts.passwordFile, "utf8").replace(/\n$/, "");
} catch (err) {
throw new Error(`cannot read the admin password at ${this.opts.passwordFile}: ${(err as Error).message}`);
}
const authorization = "Basic " + Buffer.from(`${this.opts.admin}:${password}`).toString("base64");
const tokens = `${this.opts.url.replace(/\/+$/, "")}/api/v1/users/${encodeURIComponent(this.opts.admin)}/tokens`;
const call = async (method: string, path = "", body?: unknown): Promise<{ status: number; body: any }> => {
const res = await this.fetchImpl(tokens + path, {
method,
headers: { "Content-Type": "application/json", Authorization: authorization },
...(body === undefined ? {} : { body: JSON.stringify(body) }),
});
const text = await res.text();
let parsed: any = null;
if (text) {
try { parsed = JSON.parse(text); } catch { parsed = text; }
}
return { status: res.status, body: parsed };
};
let res = await call("POST", "", { name: this.name, scopes: this.scopes });
if (res.status === 401 || res.status === 403) throw new AdminRefused(this.opts.admin, res.status);
if (res.status === 400 || res.status === 422) {
// The forge still holds a token by this name whose value we no longer have — the kept file
// went while the forge's data stayed. It is ours to replace: drop it by name and mint again.
this.log(`the forge already holds a token named "${this.name}" — replacing it`);
const dropped = await call("DELETE", `/${encodeURIComponent(this.name)}`);
if (dropped.status !== 204 && dropped.status !== 404) {
throw new Error(`Gitea DELETE /users/${this.opts.admin}/tokens/${this.name}: ${dropped.status} ${detail(dropped.body)}`);
}
res = await call("POST", "", { name: this.name, scopes: this.scopes });
}
if (res.status !== 201 && res.status !== 200) {
throw new Error(`Gitea POST /users/${this.opts.admin}/tokens: ${res.status} ${detail(res.body)}`);
}
const token = typeof res.body?.sha1 === "string" ? res.body.sha1 : null;
if (!token) throw new Error(`Gitea POST /users/${this.opts.admin}/tokens: ${res.status} but no token in the reply`);
this.keep(token);
this.held = token;
this.log(`minted a token for "${this.opts.admin}" (${this.scopes.join(", ")}), kept at ${this.opts.file}`);
return token;
}
}
function detail(body: unknown): string {
return typeof body === "string" ? body : JSON.stringify(body);
}
+5 -8
View File
@@ -124,7 +124,7 @@ export function getGiteaTools(gitea: GiteaClient): ToolDefinition[] {
labels: labelIds, labels: labelIds,
}); });
// The mesh just opened an issue — announce it the moment it exists. // The mesh just opened an issue — announce it the moment it exists.
await emit("issue.opened", { await emit("module.gitea.issue.opened", {
owner, owner,
repo, repo,
number: issue.number, number: issue.number,
@@ -231,7 +231,7 @@ export function getGiteaTools(gitea: GiteaClient): ToolDefinition[] {
// Read the PR first, so the merged event carries a title and branches, not just a number. // Read the PR first, so the merged event carries a title and branches, not just a number.
const pull = await gitea.getPullRequest(owner, repo, number); const pull = await gitea.getPullRequest(owner, repo, number);
await gitea.mergePullRequest(owner, repo, number, method, deleteBranch); await gitea.mergePullRequest(owner, repo, number, method, deleteBranch);
await emit("pull.merged", { await emit("module.gitea.pull.merged", {
owner, owner,
repo, repo,
number, number,
@@ -295,15 +295,12 @@ export function getGiteaTools(gitea: GiteaClient): ToolDefinition[] {
]; ];
} }
// The tools exist when the client has a way to a token: one configured, or the admin account to mint // The tools exist only when a token can be found; without one, gitea contributes none rather than
// one with (token.ts). The mint itself happens on the first call, not here — a contributor is // failing the whole runtime.
// synchronous, and a forge not yet answering must not keep the runtime from serving. Without either
// way, gitea contributes none rather than failing the whole runtime, and says why.
registerModuleTools("gitea", (env) => { registerModuleTools("gitea", (env) => {
try { try {
return getGiteaTools(GiteaClient.fromEnv(env)); return getGiteaTools(GiteaClient.fromEnv(env));
} catch (err) { } catch {
console.log(`[gitea] no tools — ${err instanceof Error ? err.message : String(err)}`);
return []; return [];
} }
}); });
+1 -1
View File
@@ -8,5 +8,5 @@
"skipLibCheck": true, "skipLibCheck": true,
"noEmit": true "noEmit": true
}, },
"include": ["client.ts", "token.ts", "index.ts", "provisioner/index.ts", "tools/index.ts"] "include": ["client.ts", "index.ts", "provisioner/index.ts", "tools/index.ts"]
} }
+1 -1
View File
@@ -40,7 +40,7 @@ async function pollAlerts(client: GrafanaClient): Promise<void> {
for (const key of now) { for (const key of now) {
if (!firing.has(key)) { if (!firing.has(key)) {
const a = byKey.get(key)!; const a = byKey.get(key)!;
await emit("alert.firing", { name: a.name, labels: a.labels, activeAt: a.activeAt }); await emit("module.grafana.alert.firing", { name: a.name, labels: a.labels, activeAt: a.activeAt });
} }
} }
} }
+1 -1
View File
@@ -2,7 +2,7 @@
"module": "grafana", "module": "grafana",
"version": "1", "version": "1",
"emits": [ "emits": [
"alert.firing" "module.grafana.alert.firing"
], ],
"own-secrets": { "own-secrets": {
"admin": "/var/lib/grafana-module/admin.secret", "admin": "/var/lib/grafana-module/admin.secret",
+1 -1
View File
@@ -50,7 +50,7 @@
"name": "hello-web", "name": "hello-web",
"network": "hello-web", "network": "hello-web",
"ports": [ "ports": [
"8080" "8080:8080"
], ],
"volumes": [ "volumes": [
"/var/lib/hello-web/index.html:/www/index.html:ro" "/var/lib/hello-web/index.html:/www/index.html:ro"
+1 -1
View File
@@ -44,7 +44,7 @@ async function pollStates(): Promise<void> {
for (const s of states) { for (const s of states) {
const prev = lastState.get(s.entity_id); const prev = lastState.get(s.entity_id);
if (primed && prev !== undefined && prev !== s.state) { if (primed && prev !== undefined && prev !== s.state) {
await emit("state.changed", { await emit("module.home-assistant.state.changed", {
entity: s.entity_id, entity: s.entity_id,
name: nameOf(s), name: nameOf(s),
from: prev, from: prev,
+1 -1
View File
@@ -6,7 +6,7 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"state.changed" "module.home-assistant.state.changed"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/home-assistant/broker", "broker": "/var/lib/mesh/home-assistant/broker",
+2 -2
View File
@@ -23,7 +23,7 @@ async function pollMounts(): Promise<void> {
if (primed) { if (primed) {
for (const [mount, m] of now) { for (const [mount, m] of now) {
if (!live.has(mount)) { if (!live.has(mount)) {
await emit("stream.started", { await emit("module.icecast.stream.started", {
mount, mount,
name: m.name, name: m.name,
description: m.description, description: m.description,
@@ -33,7 +33,7 @@ async function pollMounts(): Promise<void> {
} }
for (const [mount, m] of live) { for (const [mount, m] of live) {
if (!now.has(mount)) { if (!now.has(mount)) {
await emit("stream.stopped", { mount, name: m.name }); await emit("module.icecast.stream.stopped", { mount, name: m.name });
} }
} }
} }
+2 -2
View File
@@ -5,8 +5,8 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"stream.started", "module.icecast.stream.started",
"stream.stopped" "module.icecast.stream.stopped"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/icecast/broker" "broker": "/var/lib/mesh/icecast/broker"
+6 -9
View File
@@ -14,15 +14,12 @@
"mongodb-database": { "mongodb-database": {
"name": "invoicing" "name": "invoicing"
}, },
"s3-bucket": {
"bucket": "invoicing"
},
"route": { "route": {
"site": { "label": "invoicing",
"label": "invoicing", "port": 80
"port": 80
},
"api": {
"label": "invoicing-api",
"port": 9000
}
} }
}, },
"binds": { "binds": {
@@ -66,7 +63,7 @@
"type": "file", "type": "file",
"path": "/var/lib/invoicing/api.env", "path": "/var/lib/invoicing/api.env",
"mode": "0600", "mode": "0600",
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=${bound:mongodb-database:as}\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_BUCKET=mesh-novox-invoice\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n" "content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/invoicing?authSource=admin\nMINIO_BUCKET=invoicing\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n"
}, },
{ {
"id": "net", "id": "net",
+6 -6
View File
@@ -28,17 +28,17 @@ async function announce(type: string, body: Record<string, unknown>): Promise<vo
export const events = { export const events = {
userCreated: (realm: string, username: string, email?: string) => userCreated: (realm: string, username: string, email?: string) =>
announce("user.created", { realm, username, ...(email ? { email } : {}) }), announce("module.keycloak.user.created", { realm, username, ...(email ? { email } : {}) }),
userDeleted: (realm: string, userId: string) => userDeleted: (realm: string, userId: string) =>
announce("user.deleted", { realm, userId }), announce("module.keycloak.user.deleted", { realm, userId }),
passwordReset: (realm: string, userId: string) => passwordReset: (realm: string, userId: string) =>
announce("password.reset", { realm, userId }), announce("module.keycloak.password.reset", { realm, userId }),
clientCreated: (realm: string, clientId: string, name?: string) => clientCreated: (realm: string, clientId: string, name?: string) =>
announce("client.created", { realm, clientId, ...(name ? { name } : {}) }), announce("module.keycloak.client.created", { realm, clientId, ...(name ? { name } : {}) }),
groupCreated: (realm: string, name: string) => groupCreated: (realm: string, name: string) =>
announce("group.created", { realm, name }), announce("module.keycloak.group.created", { realm, name }),
roleCreated: (realm: string, name: string) => roleCreated: (realm: string, name: string) =>
announce("role.created", { realm, name }), announce("module.keycloak.role.created", { realm, name }),
}; };
console.log("[keycloak] event surface ready — identity, client, group and role changes are announced"); console.log("[keycloak] event surface ready — identity, client, group and role changes are announced");
+8 -10
View File
@@ -25,12 +25,12 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"user.created", "module.keycloak.user.created",
"user.deleted", "module.keycloak.user.deleted",
"password.reset", "module.keycloak.password.reset",
"client.created", "module.keycloak.client.created",
"group.created", "module.keycloak.group.created",
"role.created" "module.keycloak.role.created"
], ],
"listens": [ "listens": [
{ {
@@ -88,9 +88,7 @@
"env": { "env": {
"KC_DB": "postgres", "KC_DB": "postgres",
"KC_HTTP_ENABLED": "true", "KC_HTTP_ENABLED": "true",
"KC_HEALTH_ENABLED": "true", "KC_HEALTH_ENABLED": "true"
"KC_HOSTNAME": "https://keycloak.novox.be",
"KC_PROXY_HEADERS": "xforwarded"
}, },
"env-file": [ "env-file": [
"/var/lib/keycloak/admin.env", "/var/lib/keycloak/admin.env",
@@ -120,7 +118,7 @@
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}", "MESH_KEYCLOAK_URL": "http://127.0.0.1:8080",
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json" "MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json"
}, },
"restart-on": [ "restart-on": [
-33
View File
@@ -94,39 +94,6 @@ export class LavinmqClient {
await this.api("PUT", `/permissions/${v}/${u}`, { configure: ".*", write: ".*", read: ".*" }); await this.api("PUT", `/permissions/${v}/${u}`, { configure: ".*", write: ".*", read: ".*" });
} }
/**
* Whether a consumer's user exists with exactly this password and full permissions on its own
* vhost. Read-only: the stored hash is salted SHA-256, the scheme `rabbitHash` writes, so the
* password is checked by hashing it with the stored salt rather than by logging in. `false` when
* the user or its permission is gone or the password differs; an unreachable API rejects
* (novox/hq issue 120).
*/
async holdsConsumer(login: string, password: string): Promise<boolean> {
const v = encodeURIComponent(login);
const u = encodeURIComponent(login);
const user = await this.getOrNull<{ password_hash?: string; hashing_algorithm?: string }>(`/users/${u}`);
if (!user?.password_hash) return false;
if (user.hashing_algorithm && !/sha256/i.test(user.hashing_algorithm)) {
throw new Error(`lavinmq user ${login} is hashed with ${user.hashing_algorithm}, which this check cannot verify`);
}
const stored = Buffer.from(user.password_hash, "base64");
if (stored.length < 5 || rabbitHash(password, stored.subarray(0, 4)) !== user.password_hash) return false;
const perm = await this.getOrNull<{ configure?: string; write?: string; read?: string }>(`/permissions/${v}/${u}`);
return perm?.configure === ".*" && perm?.write === ".*" && perm?.read === ".*";
}
/** A GET that answers null for a 404 and rejects on anything else that is not 2xx. */
private async getOrNull<T>(path: string): Promise<T | null> {
const resp = await fetch(`${this.conn.base}/api${path}`, {
headers: {
Authorization: "Basic " + Buffer.from(`${this.conn.adminUser}:${this.conn.adminPassword}`).toString("base64"),
},
});
if (resp.status === 404) return null;
if (!resp.ok) throw new Error(`lavinmq management API GET ${path} -> ${resp.status}: ${await resp.text()}`);
return (await resp.json()) as T;
}
/** Remove a consumer's vhost and user, idempotently. A DELETE of what is already gone is tolerated. */ /** Remove a consumer's vhost and user, idempotently. A DELETE of what is already gone is tolerated. */
async removeConsumer(login: string): Promise<void> { async removeConsumer(login: string): Promise<void> {
const v = encodeURIComponent(login); const v = encodeURIComponent(login);
+2 -2
View File
@@ -14,11 +14,11 @@ interface AmqpEvent {
vhost?: string; vhost?: string;
} }
await on<AmqpEvent>("amqp.provisioned", async (e) => { await on<AmqpEvent>("module.lavinmq.amqp.provisioned", async (e) => {
console.log(`[lavinmq] broker provisioned for ${e.body.consumer ?? "?"} (user ${e.body.user}, vhost ${e.body.vhost})`); console.log(`[lavinmq] broker provisioned for ${e.body.consumer ?? "?"} (user ${e.body.user}, vhost ${e.body.vhost})`);
}); });
await on<AmqpEvent>("amqp.deprovisioned", async (e) => { await on<AmqpEvent>("module.lavinmq.amqp.deprovisioned", async (e) => {
console.log(`[lavinmq] broker deprovisioned (user ${e.body.user})`); console.log(`[lavinmq] broker deprovisioned (user ${e.body.user})`);
}); });
+7 -19
View File
@@ -17,12 +17,12 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"amqp.provisioned", "module.lavinmq.amqp.provisioned",
"amqp.deprovisioned" "module.lavinmq.amqp.deprovisioned"
], ],
"consumes": [ "consumes": [
"lavinmq.amqp.provisioned", "module.lavinmq.amqp.provisioned",
"lavinmq.amqp.deprovisioned" "module.lavinmq.amqp.deprovisioned"
], ],
"serves": { "serves": {
"amqp": { "amqp": {
@@ -75,12 +75,6 @@
"path": "/var/lib/lavinmq-module/grants", "path": "/var/lib/lavinmq-module/grants",
"mode": "0700" "mode": "0700"
}, },
{
"id": "broker-data",
"type": "directory",
"path": "/var/lib/mesh-broker",
"mode": "0700"
},
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
@@ -92,8 +86,8 @@
"127.0.0.1:15672:15672" "127.0.0.1:15672:15672"
], ],
"volumes": [ "volumes": [
"/var/lib/mesh-broker:/var/lib/lavinmq", "mesh-broker-data:/var/lib/lavinmq",
"/var/lib/mesh-broker-tls:/tls:ro" "mesh-broker-tls:/tls:ro"
], ],
"args": [ "args": [
"--amqps-port=5671", "--amqps-port=5671",
@@ -141,11 +135,5 @@
"from": "Dockerfile" "from": "Dockerfile"
} }
] ]
}, }
"accesses": [
{
"path": "/var/lib/mesh-broker-tls",
"mode": "read"
}
]
} }
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+2 -7
View File
@@ -37,7 +37,7 @@ runProvisioner("amqp", {
// The vhost and the user share the consumer's login, so one cannot reach another's broker. // The vhost and the user share the consumer's login, so one cannot reach another's broker.
await lavinmq.waitReady(); await lavinmq.waitReady();
await lavinmq.createConsumer(p.as, p.password); await lavinmq.createConsumer(p.as, p.password);
await announce("amqp.provisioned", { await announce("module.lavinmq.amqp.provisioned", {
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
user: p.as, user: p.as,
vhost: p.as, vhost: p.as,
@@ -46,11 +46,6 @@ runProvisioner("amqp", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
await lavinmq.removeConsumer(p.as); await lavinmq.removeConsumer(p.as);
await announce("amqp.deprovisioned", { user: p.as, vhost: p.as }); await announce("module.lavinmq.amqp.deprovisioned", { user: p.as, vhost: p.as });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return lavinmq.holdsConsumer(p.as, p.password);
}, },
}); });
+2 -2
View File
@@ -40,12 +40,12 @@ async function pollQueue(lidarr: LidarrClient): Promise<void> {
if (primed) { if (primed) {
// Entered the queue since last look — Lidarr grabbed a release. // Entered the queue since last look — Lidarr grabbed a release.
for (const [id, item] of now) { for (const [id, item] of now) {
if (!inQueue.has(id)) await emit("album.grabbed", { title: item.title, status: item.status }); if (!inQueue.has(id)) await emit("module.lidarr.album.grabbed", { title: item.title, status: item.status });
} }
// Left the queue — imported and done, unless it was last seen failing. // Left the queue — imported and done, unless it was last seen failing.
for (const [id, item] of inQueue) { for (const [id, item] of inQueue) {
if (!now.has(id) && !FAILED_STATUSES.has(item.status)) { if (!now.has(id) && !FAILED_STATUSES.has(item.status)) {
await emit("download.completed", { title: item.title }); await emit("module.lidarr.download.completed", { title: item.title });
} }
} }
} }
+2 -2
View File
@@ -5,8 +5,8 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"album.grabbed", "module.lidarr.album.grabbed",
"download.completed" "module.lidarr.download.completed"
], ],
"consumes": [], "consumes": [],
"own-secrets": { "own-secrets": {
+2 -2
View File
@@ -17,7 +17,7 @@ FROM ${BUILD_BASE} AS build
# resolved away. # resolved away.
WORKDIR /app/modules/mailu WORKDIR /app/modules/mailu
COPY . . COPY . .
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE} FROM ${RUNTIME_BASE}
@@ -27,4 +27,4 @@ COPY --from=build /app/modules/mailu/dist /app/modules/mailu/dist
# the convention novox/hq issues 060/061 settled. A container that instead ran only its # the convention novox/hq issues 060/061 settled. A container that instead ran only its
# provisioner (`run`) served no tools and emitted no events; a container that named no command # provisioner (`run`) served no tools and emitted no events; a container that named no command
# ran no provisioner at all. # ran no provisioner at all.
ENV MESH_TOOL_MODULES=/app/modules/mailu/dist/index.js,/app/modules/mailu/dist/tools/index.js,/app/modules/mailu/dist/provisioner/index.js ENV MESH_TOOL_MODULES=/app/modules/mailu/dist/index.js,/app/modules/mailu/dist/tools/index.js
-44
View File
@@ -1,44 +0,0 @@
# automx2 — the autoconfig/autodiscover responder, carried by the mailu module as its own
# artifact: it is a config-baked sidecar of this mail server, not a standalone application
# (novox/hq ADR 0015 draws that line at applications).
#
# The base is named rather than pinned (novox/hq issue 044): declared in module.json's
# `build.on`. The build context is the module's own directory; every ADD says so.
ARG PYTHON_BASE
FROM ${PYTHON_BASE}
RUN apk add --no-cache bash sqlite
WORKDIR /automx2
ADD automx/files/setupvenv.sh /automx2/setupvenv.sh
ADD automx/files/start /automx2/start
ADD automx/files/setup /automx2/setup
ADD automx/files/setup-db /automx2/setup-db
ADD automx/files/add-domains /automx2/add-domains
RUN chmod u+x setupvenv.sh start add-domains setup setup-db
RUN ./setupvenv.sh \
&& . .venv/bin/activate \
&& pip install automx2==2021.6
# The launcher `start` expects. In the predecessor's image this wrapper appeared during a build
# step that never made it into the files this module carries — the image worked and the recipe
# could not reproduce it. Written here explicitly, verbatim from the proven image, so the build
# is the whole truth about the image again.
RUN mkdir -p .venv/scripts && printf '%s\n' \
'#!/usr/bin/env bash' \
'set -euo pipefail' \
'. .venv/bin/activate' \
"export FLASK_ENV='production'" \
"export FLASK_APP='automx2.server:app'" \
'flask "$@"' > .venv/scripts/flask.sh && chmod +x .venv/scripts/flask.sh
ENV AUTOMX2_CONF=/etc/automx2.conf
ADD automx/files/automx2.conf /etc/automx2.conf
# VOLUME deliberately absent: the anonymous /data volume is exactly what lost db.sqlite on
# every recreate (measured on novox 2026-08-10). The manifest binds a real directory instead.
ENTRYPOINT ["/bin/sh"]
CMD ["./start"]
EXPOSE 4243
-49
View File
@@ -1,49 +0,0 @@
#!/usr/bin/env bash
set -e
echo "${MAIL_DOMAINS}"
# Split domains into array
IFS=', ' read -r -a array <<< "${AMX_MAIL_DOMAINS}"
# User configurable section -- START
PROVIDER_ID=001
SQL_CMD="";
# Iterate domains resulting from split on second arg
for element in "${array[@]}"
do
# Set vars
DOMAIN=$element
PROVIDER_NAME=$DOMAIN
PROVIDER_SHORTNAME=$DOMAIN
# Optional LDAP server
#LDAP_SERVER="ldap.${DOMAIN}"
# User configurable section -- END
s1_id=$((PROVIDER_ID + 1))
s2_id=$((PROVIDER_ID + 2))
s3_id=$((PROVIDER_ID + 3))
dom_id=$((PROVIDER_ID + 4))
s3_id='NULL'
SQL_CMD=$(cat <<EOT
$SQL_CMD
INSERT INTO provider(id, name, short_name) VALUES(${PROVIDER_ID}, '${PROVIDER_NAME}', '${PROVIDER_SHORTNAME}');
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
VALUES(${s1_id}, ${AMX_IMAP_PORT}, 'imap', '${AMX_IMAP_SERVER}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
INSERT INTO server(id, port, type, name, socket_type, user_name, authentication)
VALUES(${s2_id}, ${AMX_SMTP_PORT}, 'smtp', '${AMX_SMTP_ADDRESS}', 'STARTTLS', '%EMAILADDRESS%', 'password-cleartext');
INSERT INTO domain(id, name, provider_id, ldapserver_id) VALUES(${dom_id}, '${DOMAIN}', ${PROVIDER_ID}, ${s3_id});
INSERT INTO server_domain(server_id, domain_id) VALUES(${s1_id}, ${dom_id});
INSERT INTO server_domain(server_id, domain_id) VALUES(${s2_id}, ${dom_id});
EOT
)
PROVIDER_ID=$((PROVIDER_ID+10))
done
echo -e ${SQL_CMD}
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
-21
View File
@@ -1,21 +0,0 @@
[automx2]
# A typical production setup would use loglevel = WARNING
loglevel = WARNING
# Echo SQL commands into log? Used for debugging.
db_echo = false
# In-memory SQLite database
# db_uri = sqlite:///:memory:
# SQLite database in a UNIX-like file system
db_uri = sqlite:////data/db.sqlite
# MySQL database on a remote server. This example does not use an encrypted
# connection and is therefore *not* recommended for production use.
#db_uri = mysql://username:password@server.example.com/db
# Number of proxy servers between automx2 and the client (default: 0).
# If your logs only show 127.0.0.1 or ::1 as the source IP for incoming
# connections, proxy_count probably needs to be changed.
proxy_count = 1
-12
View File
@@ -1,12 +0,0 @@
#!/usr/bin/env bash
set -e
if [ ! -e /data/db.sqlite ]; then
# DB SETUP
echo "SETTING UP DB"
./setup-db
echo "ADDING DOMAINS"
# Add the domains
./add-domains
fi
-84
View File
@@ -1,84 +0,0 @@
#!/usr/bin/env bash
set -e
# LDAP-Server
LDAP=$(cat <<EOT
CREATE TABLE ldapserver(
id INT PRIMARY KEY NOT NULL,
name TEXT NOT NULL,
port INT NOT NULL,
use_ssl INT NOT NULL,
search_base TEXT NOT NULL,
search_filter TEXT NOT NULL,
attr_uid TEXT NOT NULL,
attr_cn TEXT NOT NULL,
bind_password TEXT NOT NULL,
bind_user TEXT NOT NULL
);
EOT
)
# Provider
PROVIDER=$(cat <<EOT
CREATE TABLE provider(
id INT PRIMARY KEY NOT NULL,
name TEXT NOT NULL,
short_name TEXT NOT NULL
);
EOT
)
# Server
SERVER=$(cat <<EOT
CREATE TABLE server(
id INT PRIMARY KEY NOT NULL,
prio INT NOT NULL DEFAULT 10,
name TEXT NOT NULL,
port INT NOT NULL,
type TEXT NOT NULL,
socket_type TEXT NOT NULL,
user_name TEXT NOT NULL,
authentication TEXT NOT NULL
);
EOT
)
# Domain
DOMAIN=$(cat <<EOT
CREATE TABLE domain(
id INT PRIMARY KEY NOT NULL,
name TEXT NOT NULL,
provider_id INT NOT NULL,
ldapserver_id INT NULL,
FOREIGN KEY(ldapserver_id) REFERENCES ldapserver(id),
FOREIGN KEY(provider_id) REFERENCES provider(id)
);
CREATE UNIQUE INDEX domain_name ON domain(name);
EOT
)
# Server-Domain
SERVER_DOMAIN=$(cat <<EOT
CREATE TABLE server_domain(
server_id INT NOT NULL,
domain_id INT NOT NULL,
FOREIGN KEY(server_id) REFERENCES server(id),
FOREIGN KEY(domain_id) REFERENCES domain(id)
);
EOT
)
## TODO Foreign keys
SQL_CMD=$(cat <<EOT
$LDAP
$PROVIDER
$SERVER
$DOMAIN
$SERVER_DOMAIN
EOT
)
echo -e ${SQL_CMD}
echo -e ${SQL_CMD} | sqlite3 /data/db.sqlite
-38
View File
@@ -1,38 +0,0 @@
#!/usr/bin/env bash
# vim:ts=4:sw=4:noet
#
# Creates a Python 3 virtual environment. The target directory can be passed
# as a parameter. The default path is '.venv' in the current directory.
dir="${1:-.venv}"
echo "Setup dir $dir"
set -e
if [ -d "${dir}" ]; then
echo >&2 "Directory '${dir}' already exists, exiting."
exit 1
fi
python3 -m venv "${dir}"
source "${dir}/bin/activate"
set +e
pip install -U pip setuptools wheel || true
#set -e
## vim:tabstop=4:noexpandtab
##
## Creates a Python 3 virtual environment. The target directory can be passed
## as a parameter. The default path is 'venv' in the current directory.
#
#dir="${1:-venv}"
#
#set -e
#if [ -d "${dir}" ]; then
# echo "Directory '${dir}' already exists, exiting." >&2
# exit 1
#fi
#python3 -m venv "${dir}"
#. "${dir}/bin/activate"
#
#set +e
#pip install -U pip setuptools || true
-8
View File
@@ -1,8 +0,0 @@
#!/usr/bin/env bash
set -e
# Setup
./setup
# Start
./.venv/scripts/flask.sh run --host=0.0.0.0 --port=4243
-29
View File
@@ -130,39 +130,10 @@ export class MailuClient {
await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password }); await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password });
} }
/**
* Set the mesh's password on a mailbox the mesh provisions, and enable it. A disabled mailbox is
* what the provisioner's check reports as lost, so applying again must enable it, or the two would
* disagree for ever. Separate from changePassword, which an operator's tool uses and which must
* not re-enable a mailbox someone disabled.
*/
async applyProvisioned(email: string, password: string): Promise<void> {
await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password, enabled: true });
}
async deleteUser(email: string): Promise<void> { async deleteUser(email: string): Promise<void> {
await this.api("DELETE", `/user/${encodeURIComponent(email)}`); await this.api("DELETE", `/user/${encodeURIComponent(email)}`);
} }
/**
* Whether a mailbox exists and is enabled. Read-only, through the admin API.
*
* **The password is not checked.** Mailu authenticates in its admin service, behind the front;
* the imap server's own password database accepts any password from Mailu's subnet, so asking it
* (`doveadm auth test`) proves nothing, or refuses everyone. A lost or disabled mailbox is caught;
* a password changed by hand is not (novox/hq issue 120).
*/
async holdsUser(email: string): Promise<boolean> {
const res = await fetch(`${this.baseUrl}/user/${encodeURIComponent(email)}`, {
headers: { Authorization: this.apiKey, Accept: "application/json" },
});
if (res.status === 404) return false;
if (!res.ok) throw new Error(`Mailu API GET /user/${email}: ${res.status} ${await res.text()}`);
const user = (await res.json()) as { enabled?: boolean };
return user.enabled !== false;
}
async listAliases(): Promise<MailuAlias[]> { async listAliases(): Promise<MailuAlias[]> {
const aliases = await this.api<any[]>("GET", "/alias"); const aliases = await this.api<any[]>("GET", "/alias");
return (aliases ?? []).map((a) => ({ return (aliases ?? []).map((a) => ({
+2 -2
View File
@@ -36,8 +36,8 @@ function watcher(created: string, deleted: string): (keys: string[]) => Promise<
}; };
} }
const watchUsers = watcher("user.created", "user.deleted"); const watchUsers = watcher("module.mailu.user.created", "module.mailu.user.deleted");
const watchAliases = watcher("alias.created", "alias.deleted"); const watchAliases = watcher("module.mailu.alias.created", "module.mailu.alias.deleted");
async function pollUsers(): Promise<void> { async function pollUsers(): Promise<void> {
await watchUsers((await mailu.listUsers()).map((u) => u.email)); await watchUsers((await mailu.listUsers()).map((u) => u.email));
+94 -223
View File
@@ -14,49 +14,27 @@
"name": "mailu" "name": "mailu"
}, },
"route": { "route": {
"web": { "label": "mail",
"label": "mail", "port": 7080
"port": 7443,
"scheme": "https",
"insecure": true
},
"acme": {
"label": "mail",
"path": "/.well-known/acme-challenge",
"port": 7080,
"priority": 100
},
"autoconfig": {
"label": "autoconfig",
"port": 4243
},
"autodiscover": {
"label": "autodiscover",
"port": 4243
},
"automx": {
"label": "automx",
"port": 4243
}
} }
}, },
"binds": { "binds": {
"postgres-database": "${dir:state}/database.json", "postgres-database": "/var/lib/mailu/database.json",
"route": "${dir:state}/route.json" "route": "/var/lib/mailu/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "${dir:state}/database.secret", "postgres-database": "/var/lib/mailu/database.secret",
"secret": { "secret": {
"secret-key": "${dir:state}/secret-key.secret", "secret-key": "/var/lib/mailu/secret-key.secret",
"admin": "${dir:state}/admin.secret", "admin": "/var/lib/mailu/admin.secret",
"api-token": "${dir:state}/api-token.secret" "api-token": "/var/lib/mailu/api-token.secret"
} }
}, },
"emits": [ "emits": [
"user.created", "module.mailu.user.created",
"user.deleted", "module.mailu.user.deleted",
"alias.created", "module.mailu.alias.created",
"alias.deleted" "module.mailu.alias.deleted"
], ],
"listens": [ "listens": [
{ {
@@ -66,20 +44,6 @@
"why": "mail from other mail servers", "why": "mail from other mail servers",
"fixed": true "fixed": true
}, },
{
"port": 110,
"protocol": "tcp",
"from": "anywhere",
"why": "POP3, kept at parity with the predecessor; pruning legacy protocols is its own deliberate change",
"fixed": true
},
{
"port": 143,
"protocol": "tcp",
"from": "anywhere",
"why": "IMAP with STARTTLS, kept at parity",
"fixed": true
},
{ {
"port": 465, "port": 465,
"protocol": "tcp", "protocol": "tcp",
@@ -91,7 +55,7 @@
"port": 587, "port": 587,
"protocol": "tcp", "protocol": "tcp",
"from": "anywhere", "from": "anywhere",
"why": "submission; also what the smtp provision serves consumers", "why": "submission",
"fixed": true "fixed": true
}, },
{ {
@@ -101,30 +65,11 @@
"why": "IMAP over TLS", "why": "IMAP over TLS",
"fixed": true "fixed": true
}, },
{
"port": 995,
"protocol": "tcp",
"from": "anywhere",
"why": "POP3 over TLS, kept at parity",
"fixed": true
},
{ {
"port": 7080, "port": 7080,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy" "why": "the web interface (admin, webmail, admin API), behind the route proxy"
},
{
"port": 7443,
"protocol": "tcp",
"from": "mesh",
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
},
{
"port": 4243,
"protocol": "tcp",
"from": "mesh",
"why": "automx: mail client autoconfiguration; autoconfig/autodiscover/automx.novox.be are route grants reaching it here"
} }
], ],
"own-secrets": { "own-secrets": {
@@ -140,125 +85,125 @@
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",
"mode": "0700", "path": "/var/lib/mailu",
"place": "."
},
{
"id": "grants",
"type": "directory",
"mode": "0700"
},
{
"id": "data-automx",
"type": "directory",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "config-env", "id": "config-env",
"type": "file", "type": "file",
"path": "${dir:state}/mailu.env", "path": "/var/lib/mailu/mailu.env",
"mode": "0644", "mode": "0644",
"content": "ADMIN_ADDRESS=mailu-admin\nANTISPAM_ADDRESS=mailu-antispam\nANTIVIRUS_ADDRESS=mailu-antivirus\nIMAP_ADDRESS=mailu-imap\nSMTP_ADDRESS=mailu-smtp\nFRONT_ADDRESS=mailu-front\nWEBMAIL_ADDRESS=mailu-webmail\nWEBDAV_ADDRESS=mailu-webdav\nREDIS_ADDRESS=mailu-redis\nPORTS=25,80,443,465,993,995,4190,110,143,587\nDOMAIN=novox.be\nHOSTNAMES=mail.novox.be\nPOSTMASTER=admin\nSITENAME=Novox\nWEBSITE=https://novox.be\nTLS_FLAVOR=letsencrypt\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=novox.be\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=7080\nHTTPS_PORT=7443\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=mail.novox.be\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=mail.novox.be\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=novox.be\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=142.132.152.141\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\nWELCOME_SUBJECT=Welcome to your new email account\nWELCOME_BODY=Welcome to your new email account, if you can read this, then it is configured properly!\n" "content": "DOMAIN=novox.be\nHOSTNAMES=mail.novox.be\nPOSTMASTER=admin\nSITENAME=Novox\nWEBSITE=https://novox.be\nTLS_FLAVOR=cert\nSUBNET=192.168.203.0/24\nCOMPOSE_PROJECT_NAME=mailu\nHOST_ADMIN=mailu-admin\nHOST_ANTISPAM=mailu-antispam:11332\nHOST_IMAP=mailu-imap\nHOST_SMTP=mailu-smtp\nHOST_WEBMAIL=mailu-webmail\nHOST_WEBDAV=mailu-webdav:5232\nHOST_REDIS=mailu-redis\nHOST_FRONT=mailu-front\nREDIS_ADDRESS=mailu-redis\nANTIVIRUS=clamav\nWEBMAIL=roundcube\nWEBDAV=radicale\nFETCHMAIL_ENABLED=True\nFETCHMAIL_DELAY=600\nADMIN=true\nWEB_ADMIN=/admin\nWEB_WEBMAIL=/webmail\nWEBROOT_REDIRECT=/webmail\nWEBMAIL_ADDRESS=webmail\nAPI=true\nWEB_API=/api\nAUTH_RATELIMIT_IP=6000/hour\nAUTH_RATELIMIT_USER=1000/day\nCREDENTIAL_ROUNDS=12\nPASSWORD_SCHEME=PBKDF2\nDISABLE_STATISTICS=True\nMESSAGE_SIZE_LIMIT=50000000\nMESSAGE_RATELIMIT=200/day\nRECIPIENT_DELIMITER=+\nPOSTFIX_MYNETWORKS=127.0.0.0/8 [::1]/128\nRELAYNETS=\nRELAYHOST=\nREJECT_UNLISTED_RECIPIENT=\nDB_FLAVOR=postgresql\nINITIAL_ADMIN_ACCOUNT=admin\nINITIAL_ADMIN_DOMAIN=novox.be\nINITIAL_ADMIN_MODE=ifmissing\nSMTP_PORT=25\nSMTPS_PORT=465\nSUBMISSION_PORT=587\nPOP3_PORT=110\nPOP3S_PORT=995\nIMAP_PORT=143\nIMAPS_PORT=993\nHTTP_PORT=7080\nHTTPS_PORT=7443\nAUTOMX_PORT=4243\nAMX_SMTP_ADDRESS=mail.novox.be\nAMX_SMTP_PORT=587\nAMX_IMAP_ADDRESS=mail.novox.be\nAMX_IMAP_PORT=143\nAMX_MAIL_DOMAINS=novox.be\nDMARC_RUA=admin\nDMARC_RUF=admin\nLETSENCRYPT_SHORTCHAIN=True\nTZ=Etc/UTC\nLOG_LEVEL=INFO\nWELCOME=false\nREAL_IP_HEADER=X-Real-IP\nREAL_IP_FROM=\nCOMPRESSION=\nCOMPRESS_LEVEL=\nCOMPRESSION_LEVEL=\nBIND_ADDRESS4=127.0.0.1\nBIND_ADDRESS6=::1\nMAILU_VERSION=1.9\nDOCKER_ORG=mailu\nDOCKER_PREFIX=\n"
}, },
{ {
"id": "secret-env", "id": "secret-env",
"type": "file", "type": "file",
"path": "${dir:state}/secret.env", "path": "/var/lib/mailu/secret.env",
"mode": "0600", "mode": "0600",
"content": "SECRET_KEY=${secret:secret-key}\n" "content": "SECRET_KEY=${secret:secret-key}\n"
}, },
{ {
"id": "database-env", "id": "database-env",
"type": "file", "type": "file",
"path": "${dir:state}/database.env", "path": "/var/lib/mailu/database.env",
"mode": "0600", "mode": "0600",
"content": "DB_FLAVOR=postgresql\nDB_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nDB_USER=${bound:postgres-database:as}\nDB_NAME=${bound:postgres-database:as}\nDB_PW=${secret:postgres-database}\n" "content": "DB_FLAVOR=postgresql\nDB_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nDB_USER=${bound:postgres-database:as}\nDB_NAME=${bound:postgres-database:as}\nDB_PW=${secret:postgres-database}\n"
}, },
{ {
"id": "admin-env", "id": "admin-env",
"type": "file", "type": "file",
"path": "${dir:state}/admin.env", "path": "/var/lib/mailu/admin.env",
"mode": "0600", "mode": "0600",
"content": "INITIAL_ADMIN_PW=${secret:admin}\nAPI_TOKEN=${secret:api-token}\n" "content": "INITIAL_ADMIN_PW=${secret:admin}\nAPI_TOKEN=${secret:api-token}\n"
}, },
{ {
"id": "data-certs", "id": "data-certs",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/certs",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-data", "id": "data-data",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/data",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-dkim", "id": "data-dkim",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/dkim",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-mail", "id": "data-mail",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/mail",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-mailqueue", "id": "data-mailqueue",
"type": "directory", "type": "directory",
"mode": "0755" "path": "/services/mailu/data/mailqueue",
"mode": "0700"
}, },
{ {
"id": "data-filter", "id": "data-filter",
"type": "directory", "type": "directory",
"mode": "0700" "path": "/services/mailu/data/filter",
},
{
"id": "data-clamav",
"type": "directory",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-redis", "id": "data-redis",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/redis",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-webmail", "id": "data-webmail",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/webmail",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-dav", "id": "data-dav",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/dav",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-fetchmail", "id": "data-fetchmail",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/data/fetchmail",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-overrides-nginx", "id": "data-overrides-nginx",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/overrides/nginx",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-overrides-dovecot", "id": "data-overrides-dovecot",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/overrides/dovecot",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-overrides-postfix", "id": "data-overrides-postfix",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/overrides/postfix",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-overrides-rspamd", "id": "data-overrides-rspamd",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/overrides/rspamd",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data-overrides-roundcube", "id": "data-overrides-roundcube",
"type": "directory", "type": "directory",
"path": "/services/mailu/data/overrides/roundcube",
"mode": "0700" "mode": "0700"
}, },
{ {
@@ -270,191 +215,164 @@
"id": "resolver", "id": "resolver",
"type": "container", "type": "container",
"name": "mailu-resolver", "name": "mailu-resolver",
"image": "ghcr.io/mailu/unbound@sha256:3a0fdfb364a63f4f9259526e013c1ef40f5f14de3621ce1560804b3a5909584a", "image": "ghcr.io/mailu/unbound@sha256:142aaad82ad1b0d5b59a5f1303778dba61a3e0a540f5d969c48862bcc99f6f5d",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env", "/var/lib/mailu/mailu.env",
"${dir:state}/secret.env" "/var/lib/mailu/secret.env"
], ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
"ip": "192.168.203.254"
}, },
{ {
"id": "redis", "id": "redis",
"type": "container", "type": "container",
"name": "mailu-redis", "name": "mailu-redis",
"image": "redis@sha256:4bed291aa5efb9f0d77b76ff7d4ab71eee410962965d052552db1fb80576431d", "image": "redis@sha256:1db42ccef14898aa29bae778452d567534b59c107129cbc1163fb552de184d3c",
"network": "mailu", "network": "mailu",
"volumes": [ "volumes": [
"${dir:data-redis}:/data" "/services/mailu/data/redis:/data"
] ]
}, },
{ {
"id": "admin", "id": "admin",
"type": "container", "type": "container",
"name": "mailu-admin", "name": "mailu-admin",
"image": "ghcr.io/mailu/admin@sha256:6dbfdadc4a9590dcb7652357b505200115b689b74008653bbf369e4599a3be5a", "image": "ghcr.io/mailu/admin@sha256:dcac20e9cbdad560faef9653b1b5ac0d9266f4098dc00f0e7f0d35f4e70ed8f1",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env", "/var/lib/mailu/mailu.env",
"${dir:state}/secret.env", "/var/lib/mailu/secret.env",
"${dir:state}/database.env", "/var/lib/mailu/database.env",
"${dir:state}/admin.env" "/var/lib/mailu/admin.env"
], ],
"volumes": [ "volumes": [
"${dir:data-data}:/data", "/services/mailu/data/data:/data",
"${dir:data-dkim}:/dkim" "/services/mailu/data/dkim:/dkim"
], ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
"dns": [
"192.168.203.254"
]
}, },
{ {
"id": "imap", "id": "imap",
"type": "container", "type": "container",
"name": "mailu-imap", "name": "mailu-imap",
"image": "ghcr.io/mailu/dovecot@sha256:7f0ed5db996fbdc00adc5c5e38a08492e04f7eb4a9fbd66a03aa9a28ddf23993", "image": "ghcr.io/mailu/dovecot@sha256:46d18ba51032be8ebd6841aa49c1ef8762c729038c5fd86a081b5b884d478af9",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env" "/var/lib/mailu/mailu.env"
], ],
"volumes": [ "volumes": [
"${dir:data-mail}:/mail", "/services/mailu/data/mail:/mail",
"${dir:data-overrides-dovecot}:/overrides:ro" "/services/mailu/data/overrides/dovecot:/overrides:ro"
],
"dns": [
"192.168.203.254"
] ]
}, },
{ {
"id": "smtp", "id": "smtp",
"type": "container", "type": "container",
"name": "mailu-smtp", "name": "mailu-smtp",
"image": "ghcr.io/mailu/postfix@sha256:e2e49f39e53b80eac9e7a2f18d9df11edeb4914fd62dbba89b3155e8e034f62e", "image": "ghcr.io/mailu/postfix@sha256:bbf882880f68849511710b35237a933f3fe80c4b28bf48ff20205dbd1f1433d7",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env" "/var/lib/mailu/mailu.env"
], ],
"volumes": [ "volumes": [
"${dir:data-mailqueue}:/queue", "/services/mailu/data/mailqueue:/queue",
"${dir:data-overrides-postfix}:/overrides:ro" "/services/mailu/data/overrides/postfix:/overrides:ro"
],
"dns": [
"192.168.203.254"
] ]
}, },
{ {
"id": "antispam", "id": "antispam",
"type": "container", "type": "container",
"name": "mailu-antispam", "name": "mailu-antispam",
"image": "ghcr.io/mailu/rspamd@sha256:ff3666d8a61f17d309c5c6f6bcf4d40470b82299ca706ac650301175bb1a079d", "image": "ghcr.io/mailu/rspamd@sha256:e87ab93dd252cc69499caa5317dd10d445fd4291a7ecf6bca09793c7d475a0c8",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env" "/var/lib/mailu/mailu.env"
], ],
"volumes": [ "volumes": [
"${dir:data-filter}:/var/lib/rspamd", "/services/mailu/data/filter:/var/lib/rspamd",
"${dir:data-overrides-rspamd}:/etc/rspamd/override.d:ro" "/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro"
],
"dns": [
"192.168.203.254"
] ]
}, },
{ {
"id": "antivirus", "id": "antivirus",
"type": "container", "type": "container",
"name": "mailu-antivirus", "name": "mailu-antivirus",
"image": "clamav/clamav-debian@sha256:b12ef8fefddbba7d88de59bea8a32622f365339154adf02d38fd089112e6745a", "image": "ghcr.io/mailu/clamav@sha256:01d30483e4a8a20a54566addb1f9b00ebb51e8a103f9226602379c412cf5fb62",
"network": "mailu", "network": "mailu",
"volumes": [ "env-file": [
"${dir:data-clamav}:/var/lib/clamav" "/var/lib/mailu/mailu.env",
"/var/lib/mailu/secret.env"
], ],
"dns": [ "volumes": [
"192.168.203.254" "/services/mailu/data/filter:/data"
] ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
}, },
{ {
"id": "webmail", "id": "webmail",
"type": "container", "type": "container",
"name": "mailu-webmail", "name": "mailu-webmail",
"image": "ghcr.io/mailu/webmail@sha256:bdbee44cdb05a4658f0e3b62cc448de55ca8f8aea172279fda594826144c04f6", "image": "ghcr.io/mailu/roundcube@sha256:19ccc9c21b2420dabb893ffa707ef90785c785e53dcb6bb9f98da01598412c43",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env", "/var/lib/mailu/mailu.env",
"${dir:state}/secret.env" "/var/lib/mailu/secret.env"
], ],
"volumes": [ "volumes": [
"${dir:data-webmail}:/data", "/services/mailu/data/webmail:/data",
"${dir:data-overrides-roundcube}:/overrides:ro" "/services/mailu/data/overrides/roundcube:/overrides:ro"
], ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
"dns": [
"192.168.203.254"
]
}, },
{ {
"id": "webdav", "id": "webdav",
"type": "container", "type": "container",
"name": "mailu-webdav", "name": "mailu-webdav",
"image": "ghcr.io/mailu/radicale@sha256:690ed6edf189dfef100a5a8b37c195ebf5d9241ac5f23f2f44b8b7b75726e3de", "image": "ghcr.io/mailu/radicale@sha256:e13cbad3791c0a6841b5d387e57e49a117808dcef87b8c9969f671ae9c3b67c0",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env", "/var/lib/mailu/mailu.env",
"${dir:state}/secret.env" "/var/lib/mailu/secret.env"
], ],
"volumes": [ "volumes": [
"${dir:data-dav}:/data" "/services/mailu/data/dav:/data"
], ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
"dns": [
"192.168.203.254"
]
}, },
{ {
"id": "fetchmail", "id": "fetchmail",
"type": "container", "type": "container",
"name": "mailu-fetchmail", "name": "mailu-fetchmail",
"image": "ghcr.io/mailu/fetchmail@sha256:f881c8412d3bbe73d638469b48321558d6403a9d45bfa043c1e52c752103d42d", "image": "ghcr.io/mailu/fetchmail@sha256:7dcd1392882925d612ab2d0230d437f0c660989d572283c48b0d0f2d491adce7",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env", "/var/lib/mailu/mailu.env",
"${dir:state}/secret.env" "/var/lib/mailu/secret.env"
], ],
"volumes": [ "volumes": [
"${dir:data-fetchmail}:/data" "/services/mailu/data/data/fetchmail:/data"
], ],
"secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified", "secrets-in-environment": "mailu-admin honours SECRET_KEY_FILE, DB_PW_FILE and API_TOKEN_FILE (configuration.py) but INITIAL_ADMIN_PW is env-only (start.py); the remaining containers' need for SECRET_KEY is unverified"
"dns": [
"192.168.203.254"
]
}, },
{ {
"id": "front", "id": "front",
"type": "container", "type": "container",
"name": "mailu-front", "name": "mailu-front",
"image": "ghcr.io/mailu/nginx@sha256:36f98897cd1bc9d27628bbb4e04bdf60147af2ec7507d6da77f002c4f256896d", "image": "ghcr.io/mailu/nginx@sha256:09f28ab6d36367fcacc7994f7021f132ac845bdc05f04bf80906102d11aaa057",
"network": "mailu", "network": "mailu",
"env-file": [ "env-file": [
"${dir:state}/mailu.env" "/var/lib/mailu/mailu.env"
], ],
"ports": [ "ports": [
"25", "25",
"110",
"143",
"465", "465",
"587", "587",
"993", "993",
"995", "7080:80"
"7080:80",
"7443:443"
], ],
"volumes": [ "volumes": [
"${dir:data-certs}:/certs", "/services/mailu/data/certs:/certs",
"${dir:data-overrides-nginx}:/overrides:ro" "/services/mailu/data/overrides/nginx:/overrides:ro"
],
"dns": [
"192.168.203.254"
] ]
}, },
{ {
@@ -472,40 +390,21 @@
"network": "mailu", "network": "mailu",
"volumes": [ "volumes": [
"/var/lib/mesh/mailu/broker:/run/secrets/broker:ro", "/var/lib/mesh/mailu/broker:/run/secrets/broker:ro",
"${dir:state}/api-token.secret:/run/secrets/api-token:ro", "/var/lib/mailu/api-token.secret:/run/secrets/api-token:ro",
"${dir:grants}:${dir:grants}:ro",
"/var/lib/mesh/mailu/config.json:/run/config/config.json:ro", "/var/lib/mesh/mailu/config.json:/run/config/config.json:ro",
"/var/run/docker.sock:/var/run/docker.sock" "/var/run/docker.sock:/var/run/docker.sock"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_MAILU_URL": "http://mailu-admin:8080/api/v1", "MESH_MAILU_URL": "http://mailu-admin/api/v1",
"MESH_MAILU_API_KEY_FILE": "/run/secrets/api-token", "MESH_MAILU_API_KEY_FILE": "/run/secrets/api-token",
"MESH_MAILU_IMAP_CONTAINER": "mailu-imap", "MESH_MAILU_IMAP_CONTAINER": "mailu-imap",
"MESH_MAILU_CONFIG_FILE": "/run/config/config.json", "MESH_MAILU_CONFIG_FILE": "/run/config/config.json"
"MESH_MAILU_DOMAIN": "novox.be",
"MESH_RECEIVES": "${dir:grants}/mesh.json"
}, },
"restart-on": [ "restart-on": [
"runtime-config" "runtime-config"
], ],
"artifact": "runtime" "artifact": "runtime"
},
{
"id": "automx",
"type": "container",
"name": "mailu-automx",
"artifact": "automx",
"network": "mailu",
"env-file": [
"${dir:state}/mailu.env"
],
"ports": [
"4243"
],
"volumes": [
"${dir:data-automx}:/data"
]
} }
], ],
"build": { "build": {
@@ -519,10 +418,6 @@
"arg": "RUNTIME_BASE", "arg": "RUNTIME_BASE",
"module": "mesh-tools", "module": "mesh-tools",
"artifact": "runtime" "artifact": "runtime"
},
{
"arg": "PYTHON_BASE",
"image": "python@sha256:25f3cfeaceca14921366af4d1240b56457ef46273bdb508c7b0e8f469f6fd228"
} }
], ],
"artifacts": [ "artifacts": [
@@ -530,31 +425,7 @@
"name": "runtime", "name": "runtime",
"kind": "image", "kind": "image",
"from": "Dockerfile" "from": "Dockerfile"
},
{
"name": "automx",
"kind": "image",
"from": "automx/Dockerfile"
} }
] ]
},
"provides": [
{
"name": "smtp",
"scope": "mesh"
}
],
"serves": {
"smtp": {
"port": 587,
"domain": "novox.be",
"name": "mail.novox.be"
}
},
"receives": {
"smtp": "${dir:grants}/mesh.json"
},
"grants": {
"smtp": "${dir:grants}"
} }
} }
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
-70
View File
@@ -1,70 +0,0 @@
// mailu's provisioner — the adapter that makes mailu a provider of the mesh `smtp` interface.
// The reconcile loop, the contributions file, and reading the mesh's minted password are the sdk
// harness's; this writes only the per-service half: how mailu creates and removes a consumer's
// sending account (novox/hq ADR 0048/0076, gitea's package-registry provisioner is the sibling).
//
// The `smtp` interface: a consumer authenticates to submission (port 587, STARTTLS) as a real
// mailbox this provisioner creates. The address is `<account>@<domain>`: the local part is the
// consumer's `account` contribution — the name it wants to send as — falling back to the mesh's
// own login for a consumer that named none; the domain is the mail server's, which is this
// module's fact, not the consumer's.
//
// **The password is the mesh's, not the provisioner's (ADR 0048).** The mesh mints it and hands
// it to both ends; mailu sets exactly that password every run — so a rotation takes — and seals
// nothing: the consumer already has its copy through the mesh's own channel.
import { runProvisioner, type Provision } from "@novox/mesh-sdk/provisioner";
import { MailuClient } from "../client.js";
const mailu = MailuClient.fromEnv();
// The mail server's own domain. From the environment the manifest composes, because the client's
// config file carries the admin API's coordinates, not the mail domain.
function domain(): string {
const named = (process.env.MESH_MAILU_DOMAIN ?? "").trim();
if (named === "") {
throw new Error("MESH_MAILU_DOMAIN is not set, so a consumer's address cannot be composed");
}
return named;
}
// The address one consumer sends as. The local part is refused rather than sanitised when it is
// not a plain mailbox name — a rewritten name is an address nobody asked for.
function addressOf(p: { as: string; values?: Readonly<Record<string, unknown>> }): string {
const contributed = typeof p.values?.["account"] === "string" ? (p.values["account"] as string).trim() : "";
const local = contributed !== "" ? contributed : p.as;
if (!/^[a-z0-9][a-z0-9._-]*$/.test(local)) {
throw new Error(`${JSON.stringify(local)} is not a usable mailbox name`);
}
return `${local}@${domain()}`;
}
runProvisioner("smtp", {
async create(p: Provision): Promise<void> {
const email = addressOf(p);
// Create if absent, and set exactly the minted password either way so a rotation takes.
// Mailu's create refuses a duplicate address, which is the signal to fall through to the
// password set — the same found-then-apply shape gitea's ensureUser settled on.
try {
await mailu.createUser(email, p.password);
} catch {
await mailu.applyProvisioned(email, p.password);
}
},
async remove(p: { as: string }): Promise<void> {
// The withdrawal only knows the mesh login, never the contributed local part — so accounts
// that contributed one are removed when the address matching the login is absent? No: the
// harness hands remove only `as`, and an address composed from a contribution cannot be
// recomputed from it. The account is therefore removed by its login-shaped address when one
// exists, and left otherwise — a mailbox holding mail is the one thing a background loop
// must not guess about (this module's own events file says the same). Withdrawal of a
// named-account consumer is an operator action until the harness carries values here.
await mailu.deleteUser(`${p.as}@${domain()}`).catch(() => {});
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return mailu.holdsUser(addressOf(p));
},
});
+6 -6
View File
@@ -1,6 +1,6 @@
// mesh-catalog's entrypoint — the module graph's consumer (novox/hq ADR 0070, ADR 0072). // mesh-catalog's entrypoint — the module graph's consumer (novox/hq ADR 0070, ADR 0072).
// //
// The build-machine role announces what it built; this places it in the graph and announces what that means. // The builder announces what it built; this places it in the graph and announces what that means.
// The control plane hooks the *meaning* — a module was upgraded — rather than the build output, so // The control plane hooks the *meaning* — a module was upgraded — rather than the build output, so
// it never has to interpret an artifact or ask this module anything. // it never has to interpret an artifact or ask this module anything.
// //
@@ -47,7 +47,7 @@ interface Built {
replay?: boolean; replay?: boolean;
} }
await on("mesh-build-machine.built", async (event) => { await on("module.builder.built", async (event) => {
const body = event.body as Built; const body = event.body as Built;
if (!body.module || !body.commit) { if (!body.module || !body.commit) {
// Said rather than dropped: a build that announced itself without saying what it built is a // Said rather than dropped: a build that announced itself without saying what it built is a
@@ -69,7 +69,7 @@ await on("mesh-build-machine.built", async (event) => {
// it was missing, and the mesh is told nothing happened, because nothing did. // it was missing, and the mesh is told nothing happened, because nothing did.
if (body.replay) return; if (body.replay) return;
await emit("registered", { await emit("module.mesh-catalog.registered", {
module: body.module, commit: body.commit, upgraded, module: body.module, commit: body.commit, upgraded,
}); });
@@ -77,13 +77,13 @@ await on("mesh-build-machine.built", async (event) => {
// through modules that did not change, forever (ADR 0072). // through modules that did not change, forever (ADR 0072).
if (!upgraded) return; if (!upgraded) return;
await emit("upgraded", { await emit("module.mesh-catalog.upgraded", {
module: body.module, commit: body.commit, previous, module: body.module, commit: body.commit, previous,
}); });
// What can be built now — stale, and waiting on nothing that is itself stale. // What can be built now — stale, and waiting on nothing that is itself stale.
for (const next of await graph.buildable()) { for (const next of await graph.buildable()) {
await emit("rebuild-needed", { await emit("module.mesh-catalog.rebuild-needed", {
module: next.module, module: next.module,
builtAt: next.commit, builtAt: next.commit,
because: next.because, because: next.because,
@@ -101,4 +101,4 @@ await on("mesh-build-machine.built", async (event) => {
// Asked on every start, not only the first. A catalogue cannot tell whether it has a gap, and the // Asked on every start, not only the first. A catalogue cannot tell whether it has a gap, and the
// answer is idempotent: registering a build already held changes nothing and announces nothing. // answer is idempotent: registering a build already held changes nothing and announces nothing.
// Asked AFTER subscribing, so a build arriving during the replay is not lost between the two. // Asked AFTER subscribing, so a build arriving during the replay is not lost between the two.
await emit("catching-up", {}); await emit("module.mesh-catalog.catching-up", {});
+5 -5
View File
@@ -7,7 +7,7 @@
], ],
"claims": [ "claims": [
{ {
"name": "mesh-catalog", "name": "the-catalogue",
"scope": "mesh" "scope": "mesh"
} }
], ],
@@ -29,12 +29,12 @@
"broker": "/var/lib/mesh/mesh-catalog/broker" "broker": "/var/lib/mesh/mesh-catalog/broker"
}, },
"consumes": [ "consumes": [
"mesh-build-machine.built" "module.builder.built"
], ],
"emits": [ "emits": [
"registered", "module.mesh-catalog.registered",
"upgraded", "module.mesh-catalog.upgraded",
"rebuild-needed" "module.mesh-catalog.rebuild-needed"
], ],
"resources": [ "resources": [
{ {
+3 -3
View File
@@ -16,15 +16,15 @@ interface SecretEvent {
rotations?: number; rotations?: number;
} }
await on<SecretEvent>("secret.provisioned", async (e) => { await on<SecretEvent>("module.mesh-vault.secret.provisioned", async (e) => {
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`); console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
}); });
await on<SecretEvent>("secret.rotated", async (e) => { await on<SecretEvent>("module.mesh-vault.secret.rotated", async (e) => {
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`); console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
}); });
await on<SecretEvent>("secret.deprovisioned", async (e) => { await on<SecretEvent>("module.mesh-vault.secret.deprovisioned", async (e) => {
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`); console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
}); });
+6 -6
View File
@@ -11,14 +11,14 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"secret.provisioned", "module.mesh-vault.secret.provisioned",
"secret.rotated", "module.mesh-vault.secret.rotated",
"secret.deprovisioned" "module.mesh-vault.secret.deprovisioned"
], ],
"consumes": [ "consumes": [
"mesh-vault.secret.provisioned", "module.mesh-vault.secret.provisioned",
"mesh-vault.secret.rotated", "module.mesh-vault.secret.rotated",
"mesh-vault.secret.deprovisioned" "module.mesh-vault.secret.deprovisioned"
], ],
"receives": { "receives": {
"secret": "/var/lib/mesh-vault/grants/mesh.json" "secret": "/var/lib/mesh-vault/grants/mesh.json"
+1 -1
View File
@@ -43,6 +43,6 @@ runProvisioner("secret", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
if (!ledger.withdraw(p.as)) return; if (!ledger.withdraw(p.as)) return;
console.log(`[mesh-vault] withdrawn: ${p.as}`); console.log(`[mesh-vault] withdrawn: ${p.as}`);
await announce("secret.deprovisioned", { as: p.as }); await announce("module.mesh-vault.secret.deprovisioned", { as: p.as });
}, },
}); });
+4 -17
View File
@@ -125,18 +125,6 @@ export class MinioClient {
throw new Error(`minio bucketExists ${bucket}: ${status}`); throw new Error(`minio bucketExists ${bucket}: ${status}`);
} }
/**
* Whether a consumer's access key, with exactly this secret, reaches its bucket: a HEAD of the
* bucket signed as the consumer, the way it signs. Read-only. `false` when the key is unknown, the
* secret wrong, access denied or the bucket gone; any other answer rejects (novox/hq issue 120).
*/
async canReachAs(bucket: string, accessKey: string, secretKey: string): Promise<boolean> {
const { status } = await this.request("HEAD", `/${bucket}`, {}, { accessKey, secretKey });
if (status === 200) return true;
if (status === 403 || status === 404) return false;
throw new Error(`minio HEAD ${bucket} as ${accessKey}: ${status}`);
}
async createBucket(bucket: string): Promise<void> { async createBucket(bucket: string): Promise<void> {
const { status, text } = await this.request("PUT", `/${bucket}`); const { status, text } = await this.request("PUT", `/${bucket}`);
// 200 created; 409 BucketAlreadyOwnedByYou — idempotent, a re-provision must not fail. // 200 created; 409 BucketAlreadyOwnedByYou — idempotent, a re-provision must not fail.
@@ -263,7 +251,6 @@ export class MinioClient {
method: string, method: string,
path: string, path: string,
query: Record<string, string> = {}, query: Record<string, string> = {},
as: { accessKey: string; secretKey: string } = { accessKey: this.rootUser, secretKey: this.rootPassword },
): Promise<{ status: number; headers: Headers; text: string }> { ): Promise<{ status: number; headers: Headers; text: string }> {
const { amzDate, dateStamp } = this.stamp(); const { amzDate, dateStamp } = this.stamp();
const host = new URL(this.baseUrl).host; const host = new URL(this.baseUrl).host;
@@ -275,8 +262,8 @@ export class MinioClient {
const canonicalRequest = [method, encodedPath, canonicalQuery, canonicalHeaders, signedHeaders, payloadHash].join("\n"); const canonicalRequest = [method, encodedPath, canonicalQuery, canonicalHeaders, signedHeaders, payloadHash].join("\n");
const scope = `${dateStamp}/${this.region}/s3/aws4_request`; const scope = `${dateStamp}/${this.region}/s3/aws4_request`;
const stringToSign = ["AWS4-HMAC-SHA256", amzDate, scope, sha256hex(canonicalRequest)].join("\n"); const stringToSign = ["AWS4-HMAC-SHA256", amzDate, scope, sha256hex(canonicalRequest)].join("\n");
const signature = hmac(this.signingKey(dateStamp, as.secretKey), stringToSign).toString("hex"); const signature = hmac(this.signingKey(dateStamp), stringToSign).toString("hex");
const authorization = `AWS4-HMAC-SHA256 Credential=${as.accessKey}/${scope}, SignedHeaders=${signedHeaders}, Signature=${signature}`; const authorization = `AWS4-HMAC-SHA256 Credential=${this.rootUser}/${scope}, SignedHeaders=${signedHeaders}, Signature=${signature}`;
const url = `${this.baseUrl}${encodedPath}${canonicalQuery ? `?${canonicalQuery}` : ""}`; const url = `${this.baseUrl}${encodedPath}${canonicalQuery ? `?${canonicalQuery}` : ""}`;
const res = await fetch(url, { const res = await fetch(url, {
@@ -288,8 +275,8 @@ export class MinioClient {
return { status: res.status, headers: res.headers, text }; return { status: res.status, headers: res.headers, text };
} }
private signingKey(dateStamp: string, secretKey: string = this.rootPassword): Buffer { private signingKey(dateStamp: string): Buffer {
const kDate = hmac(`AWS4${secretKey}`, dateStamp); const kDate = hmac(`AWS4${this.rootPassword}`, dateStamp);
const kRegion = hmac(kDate, this.region); const kRegion = hmac(kDate, this.region);
const kService = hmac(kRegion, "s3"); const kService = hmac(kRegion, "s3");
return hmac(kService, "aws4_request"); return hmac(kService, "aws4_request");
+14 -64
View File
@@ -7,27 +7,12 @@
"scope": "mesh" "scope": "mesh"
} }
], ],
"requires": [
"route"
],
"contributes": {
"route": {
"api": {
"label": "files-api",
"port": 9000
},
"console": {
"label": "files",
"port": 9001
}
}
},
"capabilities": [ "capabilities": [
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"bucket.created", "module.minio.bucket.created",
"bucket.removed" "module.minio.bucket.removed"
], ],
"listens": [ "listens": [
{ {
@@ -35,18 +20,12 @@
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the S3 endpoint" "why": "the S3 endpoint"
},
{
"port": 9001,
"protocol": "tcp",
"from": "mesh",
"why": "the admin console"
} }
], ],
"serves": { "serves": {
"s3-bucket": { "s3-bucket": {
"scheme": "http", "scheme": "http",
"region": "eu-west", "region": "us-east-1",
"port": 9000 "port": 9000
} }
}, },
@@ -89,20 +68,20 @@
{ {
"id": "data", "id": "data",
"type": "directory", "type": "directory",
"path": "/var/lib/minio-store", "path": "/services/minio/data/data1-1",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "net", "id": "net",
"type": "network", "type": "network",
"name": "minio-net" "name": "minio"
}, },
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "minio", "name": "minio",
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372", "image": "quay.io/minio/minio@sha256:14cea493d9a34af32f524e538b8346cf79f3321eff8e708c1e2960462bd8936e",
"network": "minio-net", "network": "minio",
"args": [ "args": [
"server", "server",
"/data", "/data",
@@ -113,24 +92,22 @@
"/var/lib/minio/root.env" "/var/lib/minio/root.env"
], ],
"ports": [ "ports": [
"9000", "9000"
"9001"
], ],
"volumes": [ "volumes": [
"/var/lib/minio-store:/data", "/services/minio/data/data1-1:/data",
"/var/lib/minio/root.secret:/run/secrets/root:ro" "/var/lib/minio/root.secret:/run/secrets/root:ro"
], ],
"env": { "env": {
"MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root"
"MINIO_BROWSER_REDIRECT_URL": "https://files.novox.be",
"MINIO_REGION": "eu-west"
} }
}, },
{ {
"id": "runtime", "id": "runtime",
"type": "container", "type": "container",
"name": "mesh-minio", "name": "mesh-minio",
"network": "minio-net", "image": "mesh-runtime-minio@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "minio",
"volumes": [ "volumes": [
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro", "/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
"/var/lib/minio/grants:/var/lib/minio/grants:ro", "/var/lib/minio/grants:/var/lib/minio/grants:ro",
@@ -140,36 +117,9 @@
"MESH_MINIO_ENDPOINT": "http://minio:9000", "MESH_MINIO_ENDPOINT": "http://minio:9000",
"MESH_MINIO_ROOT_USER": "meshroot", "MESH_MINIO_ROOT_USER": "meshroot",
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
"MESH_MINIO_REGION": "eu-west",
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json" "MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
}, }
"artifact": "runtime"
} }
], ]
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
},
{
"arg": "MC_CLI",
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
}
} }
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+2 -8
View File
@@ -30,7 +30,7 @@ runProvisioner("s3-bucket", {
try { await minio.removeAccessKey(accessKeyId); } catch { /* none yet — first provision */ } try { await minio.removeAccessKey(accessKeyId); } catch { /* none yet — first provision */ }
await minio.createAccessKey(bucket, accessKeyId, p.password); await minio.createAccessKey(bucket, accessKeyId, p.password);
await announce("bucket.created", { await announce("module.minio.bucket.created", {
bucket, bucket,
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
accessKey: accessKeyId, accessKey: accessKeyId,
@@ -51,13 +51,7 @@ runProvisioner("s3-bucket", {
console.error(`[minio] bucket ${bucket} not removed (likely non-empty), access revoked: ${err}`); console.error(`[minio] bucket ${bucket} not removed (likely non-empty), access revoked: ${err}`);
} }
await announce("bucket.removed", { bucket, accessKey: p.as }); await announce("module.minio.bucket.removed", { bucket, accessKey: p.as });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return minio.canReachAs(bucketFor(p.as), p.as, p.password);
}, },
}); });
+1 -1
View File
@@ -22,7 +22,7 @@ const store = UsageStore.fromEnv();
// to reach the provider over the overlay would block the very apply that brings the overlay up. // to reach the provider over the overlay would block the very apply that brings the overlay up.
await store.migrate(); await store.migrate();
await on("*.usage.*", async (event) => { await on("module.*.usage.*", async (event) => {
const body = event.body as { rows?: UsageRow[]; raw?: unknown }; const body = event.body as { rows?: UsageRow[]; raw?: unknown };
for (const row of body.rows ?? []) { for (const row of body.rows ?? []) {
try { try {
+1 -1
View File
@@ -20,7 +20,7 @@
"postgres-database": "/var/lib/model-usage/database.secret" "postgres-database": "/var/lib/model-usage/database.secret"
}, },
"consumes": [ "consumes": [
"*.usage.*" "module.*.usage.*"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/model-usage/broker" "broker": "/var/lib/mesh/model-usage/broker"
-28
View File
@@ -109,34 +109,6 @@ print(EJSON.stringify({ ok: 1 }));
await this.evalJs<{ ok: number }>(js); await this.evalJs<{ ok: number }>(js);
} }
/**
* Whether `user` authenticates against `database` with exactly `password` and holds `dbOwner`
* there: checked by connecting as the consumer, the way it connects. Read-only. `false` only on an
* authentication failure or a missing role; an unreachable server rejects (novox/hq issue 120).
*/
async canAuthenticateAs(database: string, user: string, password: string): Promise<boolean> {
// Connected without credentials, then authenticated inside the eval from the environment, so
// the consumer's password is neither on argv nor in the message of a failed command.
const uri = `mongodb://${this.conn.host}:${this.conn.port}/?serverSelectionTimeoutMS=10000`;
const js =
"const t = db.getSiblingDB(process.env.MESH_HOLDS_DB);" +
"t.auth(process.env.MESH_HOLDS_USER, process.env.MESH_HOLDS_PW);" +
"print(EJSON.stringify(t.runCommand({ connectionStatus: 1 }).authInfo.authenticatedUserRoles))";
let stdout: string;
try {
({ stdout } = await run("mongosh", [uri, "--quiet", "--eval", js], {
env: { ...process.env, MESH_HOLDS_DB: database, MESH_HOLDS_USER: user, MESH_HOLDS_PW: password },
timeout: 30_000,
}));
} catch (err) {
const text = `${(err as { stderr?: string }).stderr ?? ""}${(err as { stdout?: string }).stdout ?? ""}`;
if (/Authentication failed|AuthenticationFailed/i.test(text)) return false;
throw new Error(`mongosh could not check ${user}: ${text.trim().slice(0, 500) || String((err as Error).message).split("\n")[0]}`);
}
const roles = JSON.parse(stdout.trim()) as { role: string; db: string }[];
return roles.some((r) => r.role === "dbOwner" && r.db === database);
}
/** Drop a database and its owning user, idempotently. Dropping the database evicts its data; the /** Drop a database and its owning user, idempotently. Dropping the database evicts its data; the
* user is removed first so a re-grant of the same login starts clean. */ * user is removed first so a re-grant of the same login starts clean. */
async dropDatabaseAndUser(database: string, user: string): Promise<void> { async dropDatabaseAndUser(database: string, user: string): Promise<void> {
+2 -2
View File
@@ -14,11 +14,11 @@ interface DatabaseEvent {
user?: string; user?: string;
} }
await on<DatabaseEvent>("database.provisioned", async (e) => { await on<DatabaseEvent>("module.mongodb.database.provisioned", async (e) => {
console.log(`[mongodb] database provisioned for ${e.body.consumer} (db ${e.body.database})`); console.log(`[mongodb] database provisioned for ${e.body.consumer} (db ${e.body.database})`);
}); });
await on<DatabaseEvent>("database.deprovisioned", async (e) => { await on<DatabaseEvent>("module.mongodb.database.deprovisioned", async (e) => {
console.log(`[mongodb] database deprovisioned for ${e.body.consumer} (db ${e.body.database})`); console.log(`[mongodb] database deprovisioned for ${e.body.consumer} (db ${e.body.database})`);
}); });
+18 -16
View File
@@ -11,12 +11,12 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"database.provisioned", "module.mongodb.database.provisioned",
"database.deprovisioned" "module.mongodb.database.deprovisioned"
], ],
"consumes": [ "consumes": [
"mongodb.database.provisioned", "module.mongodb.database.provisioned",
"mongodb.database.deprovisioned" "module.mongodb.database.deprovisioned"
], ],
"listens": [ "listens": [
{ {
@@ -32,13 +32,13 @@
} }
}, },
"receives": { "receives": {
"mongodb-database": "${dir:grants}/mesh.json" "mongodb-database": "/var/lib/mongodb/grants/mesh.json"
}, },
"grants": { "grants": {
"mongodb-database": "${dir:grants}" "mongodb-database": "/var/lib/mongodb/grants"
}, },
"own-secrets": { "own-secrets": {
"root": "${dir:state}/root.secret", "root": "/var/lib/mongodb/root.secret",
"broker": "/var/lib/mesh/mongodb/broker" "broker": "/var/lib/mesh/mongodb/broker"
}, },
"secrets-owner": "999:999", "secrets-owner": "999:999",
@@ -52,17 +52,19 @@
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",
"mode": "0700", "path": "/var/lib/mongodb",
"place": "." "mode": "0700"
}, },
{ {
"id": "grants", "id": "grants",
"type": "directory", "type": "directory",
"path": "/var/lib/mongodb/grants",
"mode": "0700" "mode": "0700"
}, },
{ {
"id": "data", "id": "data",
"type": "directory", "type": "directory",
"path": "/services/mongodb/db-data",
"mode": "0700" "mode": "0700"
}, },
{ {
@@ -73,7 +75,7 @@
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "mongodb-server", "name": "mongo",
"image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3", "image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3",
"network": "mongodb", "network": "mongodb",
"env": { "env": {
@@ -84,8 +86,8 @@
"27017" "27017"
], ],
"volumes": [ "volumes": [
"${dir:data}:/data/db", "/services/mongodb/db-data:/data/db",
"${dir:state}/root.secret:/run/secrets/root:ro" "/var/lib/mongodb/root.secret:/run/secrets/root:ro"
] ]
}, },
{ {
@@ -95,14 +97,14 @@
"network": "mongodb", "network": "mongodb",
"volumes": [ "volumes": [
"/var/lib/mesh/mongodb/broker:/run/secrets/broker:ro", "/var/lib/mesh/mongodb/broker:/run/secrets/broker:ro",
"${dir:grants}:${dir:grants}:ro", "/var/lib/mongodb/grants:/var/lib/mongodb/grants:ro",
"${dir:state}/root.secret:/run/secrets/root:ro" "/var/lib/mongodb/root.secret:/run/secrets/root:ro"
], ],
"env": { "env": {
"MESH_PROVISION_MONGODB": "mongodb://root@mongodb-server:27017/admin?authSource=admin", "MESH_PROVISION_MONGODB": "mongodb://root@mongo:27017/admin?authSource=admin",
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/root", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/root",
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "${dir:grants}/mesh.json" "MESH_RECEIVES": "/var/lib/mongodb/grants/mesh.json"
}, },
"artifact": "runtime" "artifact": "runtime"
} }
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+2 -7
View File
@@ -34,7 +34,7 @@ runProvisioner("mongodb-database", {
// Database and owning user share the consumer's login, so the consumer owns exactly its own. // Database and owning user share the consumer's login, so the consumer owns exactly its own.
const database = p.as; const database = p.as;
await mongo.createDatabaseAndUser(database, p.as, p.password); await mongo.createDatabaseAndUser(database, p.as, p.password);
await announce("database.provisioned", { await announce("module.mongodb.database.provisioned", {
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
database, database,
user: p.as, user: p.as,
@@ -43,11 +43,6 @@ runProvisioner("mongodb-database", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
await mongo.dropDatabaseAndUser(p.as, p.as); await mongo.dropDatabaseAndUser(p.as, p.as);
await announce("database.deprovisioned", { database: p.as }); await announce("module.mongodb.database.deprovisioned", { database: p.as });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return mongo.canAuthenticateAs(p.as, p.as, p.password);
}, },
}); });
+3 -94
View File
@@ -15,7 +15,6 @@
// The one cost dynsec carries is the bootstrap file; see initBootstrapFile() and the module README. // The one cost dynsec carries is the bootstrap file; see initBootstrapFile() and the module README.
import { randomBytes } from "node:crypto"; import { randomBytes } from "node:crypto";
import { connect as tcpConnect } from "node:net";
import { readFileSync } from "node:fs"; import { readFileSync } from "node:fs";
import { execFile } from "node:child_process"; import { execFile } from "node:child_process";
import { promisify } from "node:util"; import { promisify } from "node:util";
@@ -88,20 +87,9 @@ export class MosquittoClient {
"-u", this.conn.adminUser, "-u", this.conn.adminUser,
"-P", this.conn.adminPassword, "-P", this.conn.adminPassword,
]; ];
let stdout: string; const { stdout, stderr } = await run("mosquitto_ctrl", [...base, "dynsec", ...args], {
let stderr: string; maxBuffer: 16 << 20,
try { });
({ stdout, stderr } = await run("mosquitto_ctrl", [...base, "dynsec", ...args], {
maxBuffer: 16 << 20,
timeout: 30_000,
}));
} catch (err) {
// A failed run's message repeats its argv, the admin password (-P) included; say what failed
// without it.
const e = err as { code?: unknown; signal?: unknown; stderr?: string; stdout?: string };
const detail = `${e.stderr ?? ""}${e.stdout ?? ""}`.trim().slice(0, 500);
throw new Error(`mosquitto_ctrl dynsec ${args[0] ?? ""} could not run (${e.code ?? e.signal ?? "error"}): ${detail}`);
}
const failure = ctlError(`${stdout}\n${stderr}`); const failure = ctlError(`${stdout}\n${stderr}`);
if (failure) { if (failure) {
throw new Error(`mosquitto_ctrl dynsec ${args[0] ?? ""} failed: ${failure}`); throw new Error(`mosquitto_ctrl dynsec ${args[0] ?? ""} failed: ${failure}`);
@@ -152,11 +140,6 @@ export class MosquittoClient {
if (await this.clientExists(username)) { if (await this.clientExists(username)) {
await this.ctl("setClientPassword", username, password); await this.ctl("setClientPassword", username, password);
// A disabled client is refused like a wrong password, so the check the provisioner runs
// reports it lost; applying again must enable it, or the two would disagree for ever.
if (/Disabled:\s*true/i.test(await this.ctl("getClient", username))) {
await this.ctl("enableClient", username);
}
} else { } else {
await this.ctl("createClient", username, "-p", password); await this.ctl("createClient", username, "-p", password);
} }
@@ -180,28 +163,6 @@ export class MosquittoClient {
} }
} }
/**
* Whether a consumer's client accepts exactly this password and still carries its own role.
* Read-only. The password is checked the way the consumer is checked, by an MQTT CONNECT as it,
* and the broker's CONNACK code is the answer: 0 accepted, 4 bad credentials, 5 not authorised.
* Nothing rides on argv. An unreachable broker rejects (novox/hq issue 120).
*/
async holdsClient(username: string, password: string): Promise<boolean> {
const code = await mqttConnack(this.conn.host, this.conn.port, username, password);
if (code === 4 || code === 5) return false;
if (code !== 0) throw new Error(`mosquitto refused ${username} with CONNACK ${code}`);
// The role, asked directly: only "not found" means absent. Any other failure to ask rejects,
// unlike clientHasRole, which reads every failure as "no role".
let out: string;
try {
out = await this.ctl("getClient", username);
} catch (err) {
if (/not\s*found|does not exist|no such/i.test(String(err))) return false;
throw err;
}
return new RegExp(`(^|\\s)${escapeRegExp(username)}\\s+\\(priority`, "m").test(out);
}
/** Remove a client and the per-client role created for it, idempotently. */ /** Remove a client and the per-client role created for it, idempotently. */
async deleteScopedClient(username: string): Promise<void> { async deleteScopedClient(username: string): Promise<void> {
await ignoreMissing(this.ctl("deleteClient", username)); await ignoreMissing(this.ctl("deleteClient", username));
@@ -288,55 +249,3 @@ function readSecretFile(path: string | undefined): string | undefined {
return undefined; return undefined;
} }
} }
/**
* Connect once over MQTT 3.1.1 with a username and password, return the broker's CONNACK return code,
* and disconnect. A clean session under a throwaway client id, so no consumer session is taken over.
*/
function mqttConnack(host: string, port: number, username: string, password: string): Promise<number> {
const str = (v: string): Buffer => {
const b = Buffer.from(v, "utf8");
const len = Buffer.alloc(2);
len.writeUInt16BE(b.length);
return Buffer.concat([len, b]);
};
const variable = Buffer.concat([str("MQTT"), Buffer.from([4, 0xc2, 0, 10])]); // level 4; user+pass+clean; keepalive 10s
const payload = Buffer.concat([str(`mesh-holds-${randomBytes(6).toString("hex")}`), str(username), str(password)]);
let remaining = variable.length + payload.length;
const lenBytes: number[] = [];
do {
let byte = remaining % 128;
remaining = Math.floor(remaining / 128);
if (remaining > 0) byte |= 0x80;
lenBytes.push(byte);
} while (remaining > 0);
const packet = Buffer.concat([Buffer.from([0x10, ...lenBytes]), variable, payload]);
return new Promise((resolve, reject) => {
const socket = tcpConnect({ host, port });
let buf = Buffer.alloc(0);
const timer = setTimeout(() => {
socket.destroy();
reject(new Error(`no CONNACK from ${host}:${port} within 10s`));
}, 10_000);
socket.on("connect", () => socket.write(packet));
socket.on("data", (chunk) => {
buf = Buffer.concat([buf, chunk]);
if (buf.length < 4) return;
clearTimeout(timer);
if (buf[0] !== 0x20) {
socket.destroy();
reject(new Error(`unexpected MQTT packet 0x${buf[0].toString(16)} instead of CONNACK`));
return;
}
const code = buf[3];
if (code === 0) socket.end(Buffer.from([0xe0, 0])); // DISCONNECT
else socket.destroy();
resolve(code);
});
socket.on("error", (err) => {
clearTimeout(timer);
reject(err);
});
});
}
+2 -2
View File
@@ -14,11 +14,11 @@ interface TopicEvent {
topicPrefix?: string; topicPrefix?: string;
} }
await on<TopicEvent>("topic.provisioned", async (e) => { await on<TopicEvent>("module.mosquitto.topic.provisioned", async (e) => {
console.log(`[mosquitto] topic provisioned for ${e.body.consumer} (client ${e.body.username})`); console.log(`[mosquitto] topic provisioned for ${e.body.consumer} (client ${e.body.username})`);
}); });
await on<TopicEvent>("topic.deprovisioned", async (e) => { await on<TopicEvent>("module.mosquitto.topic.deprovisioned", async (e) => {
console.log(`[mosquitto] topic deprovisioned for ${e.body.consumer} (client ${e.body.username})`); console.log(`[mosquitto] topic deprovisioned for ${e.body.consumer} (client ${e.body.username})`);
}); });
+4 -4
View File
@@ -12,12 +12,12 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"topic.provisioned", "module.mosquitto.topic.provisioned",
"topic.deprovisioned" "module.mosquitto.topic.deprovisioned"
], ],
"consumes": [ "consumes": [
"mosquitto.topic.provisioned", "module.mosquitto.topic.provisioned",
"mosquitto.topic.deprovisioned" "module.mosquitto.topic.deprovisioned"
], ],
"serves": { "serves": {
"mqtt-topic": {} "mqtt-topic": {}
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+2 -7
View File
@@ -32,7 +32,7 @@ runProvisioner("mqtt-topic", {
// The topic subtree is scoped to the consumer's own login, so one cannot read another's topics. // The topic subtree is scoped to the consumer's own login, so one cannot read another's topics.
const topicPrefix = p.as; const topicPrefix = p.as;
await mosquitto.createScopedClient(p.as, p.password, topicPrefix); await mosquitto.createScopedClient(p.as, p.password, topicPrefix);
await announce("topic.provisioned", { await announce("module.mosquitto.topic.provisioned", {
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
username: p.as, username: p.as,
topicPrefix, topicPrefix,
@@ -41,11 +41,6 @@ runProvisioner("mqtt-topic", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
await mosquitto.deleteScopedClient(p.as); await mosquitto.deleteScopedClient(p.as);
await announce("topic.deprovisioned", { username: p.as }); await announce("module.mosquitto.topic.deprovisioned", { username: p.as });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return mosquitto.holdsClient(p.as, p.password);
}, },
}); });
+4 -54
View File
@@ -75,18 +75,14 @@ export class MssqlClient {
* prints (split across output lines for a large result, and reassembled here) is parsed. An * prints (split across output lines for a large result, and reassembled here) is parsed. An
* empty result yields no output at all — an empty array. * empty result yields no output at all — an empty array.
*/ */
async query( async query(select: string, database = "master"): Promise<Record<string, unknown>[]> {
select: string,
database = "master",
variables: Record<string, string> = {},
): Promise<Record<string, unknown>[]> {
const wrapped = `SET NOCOUNT ON;\n${stripTrailingSemis(select)}\nFOR JSON PATH, INCLUDE_NULL_VALUES;`; const wrapped = `SET NOCOUNT ON;\n${stripTrailingSemis(select)}\nFOR JSON PATH, INCLUDE_NULL_VALUES;`;
const stdout = await this.sqlcmd(wrapped, database, variables); const stdout = await this.sqlcmd(wrapped, database);
return parseJsonRows(stdout); return parseJsonRows(stdout);
} }
/** The one execution boundary: invoke `sqlcmd` and return its concatenated stdout. */ /** The one execution boundary: invoke `sqlcmd` and return its concatenated stdout. */
private async sqlcmd(sql: string, database: string, variables: Record<string, string> = {}): Promise<string> { private async sqlcmd(sql: string, database: string): Promise<string> {
// `-h -1` drops the column-header rule; `-y 0`/`-Y 0` lift the display-width cap so a long // `-h -1` drops the column-header rule; `-y 0`/`-Y 0` lift the display-width cap so a long
// JSON document is not truncated; `-W` trims trailing whitespace so the JSON chunks rejoin // JSON document is not truncated; `-W` trims trailing whitespace so the JSON chunks rejoin
// cleanly. sqlcmd from the mssql-tools ships in the runtime container, the way `psql` ships // cleanly. sqlcmd from the mssql-tools ships in the runtime container, the way `psql` ships
@@ -105,9 +101,7 @@ export class MssqlClient {
"-W", "-W",
"-Q", sql, "-Q", sql,
], ],
// `variables` reach sqlcmd as environment variables, which it substitutes as `$(NAME)` scripting { env: { ...process.env, SQLCMDPASSWORD: this.conn.password }, maxBuffer: 16 << 20 },
// variables: a value that must not appear on argv, or in the message of a failed command.
{ env: { ...process.env, ...variables, SQLCMDPASSWORD: this.conn.password }, maxBuffer: 16 << 20 },
); );
return stdout; return stdout;
} }
@@ -127,9 +121,6 @@ export class MssqlClient {
); );
} else { } else {
await this.exec(`ALTER LOGIN ${ident(login)} WITH PASSWORD = ${literal(password)}`); await this.exec(`ALTER LOGIN ${ident(login)} WITH PASSWORD = ${literal(password)}`);
// A disabled login is refused like a wrong password; the check the provisioner runs reports it
// lost, so applying again must enable it or the two would disagree for ever.
await this.exec(`ALTER LOGIN ${ident(login)} ENABLE`);
} }
const dbs = await this.query( const dbs = await this.query(
@@ -147,51 +138,10 @@ export class MssqlClient {
); );
if (users.length === 0) { if (users.length === 0) {
await this.exec(`CREATE USER ${ident(login)} FOR LOGIN ${ident(login)}`, database); await this.exec(`CREATE USER ${ident(login)} FOR LOGIN ${ident(login)}`, database);
} else {
// Re-point an existing user at the login when its SID is not the login's: a database restored
// from elsewhere keeps its user under the old login's SID, orphaned. Only then, so a user that
// is already mapped is left alone.
const orphaned = await this.query(
`SELECT 1 AS ok FROM sys.database_principals WHERE name = ${literal(login)} ` +
`AND (sid IS NULL OR sid <> SUSER_SID(${literal(login)}))`,
database,
);
if (orphaned.length > 0) {
await this.exec(`ALTER USER ${ident(login)} WITH LOGIN = ${ident(login)}`, database);
}
} }
await this.exec(`ALTER ROLE db_owner ADD MEMBER ${ident(login)}`, database); await this.exec(`ALTER ROLE db_owner ADD MEMBER ${ident(login)}`, database);
} }
/**
* Whether `login` exists, is enabled, has exactly `password`, and is a db_owner user of
* `database`. Read-only: the password is compared with PWDCOMPARE against the stored hash, so
* nothing logs in and no failed-login is recorded (novox/hq issue 120).
*/
async holdsLogin(database: string, login: string, password: string): Promise<boolean> {
// The password reaches sqlcmd as a scripting variable from the environment, never inside the
// query text, so it is neither on argv nor in the message of a failed command. It is the mesh's
// minted value, which carries no quote.
const server = await this.query(
`SELECT CAST(CASE WHEN EXISTS (SELECT 1 FROM sys.sql_logins WHERE name = ${literal(login)} ` +
`AND is_disabled = 0 AND PWDCOMPARE(N'$(MESHHOLDSPW)', password_hash) = 1) ` +
`AND DB_ID(${literal(database)}) IS NOT NULL THEN 1 ELSE 0 END AS int) AS ok`,
"master",
{ MESHHOLDSPW: password },
);
if (Number(server[0]?.ok) !== 1) return false;
// The user must be this login's, by SID, and a db_owner. A user orphaned by a restore has the
// right name and the wrong SID, and cannot be reached through the login.
const owner = await this.query(
`SELECT CAST(CASE WHEN EXISTS (SELECT 1 FROM sys.database_principals dp ` +
`JOIN sys.server_principals sp ON dp.sid = sp.sid ` +
`WHERE dp.name = ${literal(login)} AND sp.name = ${literal(login)}) ` +
`AND IS_ROLEMEMBER('db_owner', ${literal(login)}) = 1 THEN 1 ELSE 0 END AS int) AS ok`,
database,
);
return Number(owner[0]?.ok) === 1;
}
/** Drop a database and its login, idempotently, after evicting live connections. */ /** Drop a database and its login, idempotently, after evicting live connections. */
async dropDatabaseAndLogin(database: string, login: string): Promise<void> { async dropDatabaseAndLogin(database: string, login: string): Promise<void> {
const dbs = await this.query( const dbs = await this.query(
+2 -2
View File
@@ -14,11 +14,11 @@ interface DatabaseEvent {
user?: string; user?: string;
} }
await on<DatabaseEvent>("database.provisioned", async (e) => { await on<DatabaseEvent>("module.mssql.database.provisioned", async (e) => {
console.log(`[mssql] database provisioned for ${e.body.consumer} (db ${e.body.database})`); console.log(`[mssql] database provisioned for ${e.body.consumer} (db ${e.body.database})`);
}); });
await on<DatabaseEvent>("database.deprovisioned", async (e) => { await on<DatabaseEvent>("module.mssql.database.deprovisioned", async (e) => {
console.log(`[mssql] database deprovisioned for ${e.body.consumer} (db ${e.body.database})`); console.log(`[mssql] database deprovisioned for ${e.body.consumer} (db ${e.body.database})`);
}); });
+7 -6
View File
@@ -11,12 +11,12 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"database.provisioned", "module.mssql.database.provisioned",
"database.deprovisioned" "module.mssql.database.deprovisioned"
], ],
"consumes": [ "consumes": [
"mssql.database.provisioned", "module.mssql.database.provisioned",
"mssql.database.deprovisioned" "module.mssql.database.deprovisioned"
], ],
"listens": [ "listens": [
{ {
@@ -68,6 +68,7 @@
{ {
"id": "data", "id": "data",
"type": "directory", "type": "directory",
"path": "/services/mssql/data",
"mode": "0700", "mode": "0700",
"owner": "10001:0" "owner": "10001:0"
}, },
@@ -86,10 +87,10 @@
"/var/lib/mssql/sa.env" "/var/lib/mssql/sa.env"
], ],
"ports": [ "ports": [
"1433" "4848:1433"
], ],
"volumes": [ "volumes": [
"${dir:data}:/var/opt/mssql" "/services/mssql/data:/var/opt/mssql"
], ],
"secrets-in-environment": "the image documents only MSSQL_SA_PASSWORD, no _FILE and no configuration field; not convertible without a wrapper entrypoint" "secrets-in-environment": "the image documents only MSSQL_SA_PASSWORD, no _FILE and no configuration field; not convertible without a wrapper entrypoint"
}, },
+1 -1
View File
@@ -5,7 +5,7 @@
"type": "module", "type": "module",
"private": true, "private": true,
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.1" "@novox/mesh-sdk": "^0.1.0"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.0.0", "@types/node": "^22.0.0",
+2 -7
View File
@@ -33,7 +33,7 @@ runProvisioner("mssql-database", {
// Database, login and user share the consumer's name, so the consumer owns exactly its own. // Database, login and user share the consumer's name, so the consumer owns exactly its own.
const database = p.as; const database = p.as;
await mssql.createDatabaseAndLogin(database, p.as, p.password); await mssql.createDatabaseAndLogin(database, p.as, p.password);
await announce("database.provisioned", { await announce("module.mssql.database.provisioned", {
consumer: p.consumer ?? "", consumer: p.consumer ?? "",
database, database,
user: p.as, user: p.as,
@@ -42,11 +42,6 @@ runProvisioner("mssql-database", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
await mssql.dropDatabaseAndLogin(p.as, p.as); await mssql.dropDatabaseAndLogin(p.as, p.as);
await announce("database.deprovisioned", { database: p.as }); await announce("module.mssql.database.deprovisioned", { database: p.as });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return mssql.holdsLogin(p.as, p.as, p.password);
}, },
}); });
+1 -1
View File
@@ -71,7 +71,7 @@
"/var/lib/n8n/server.env" "/var/lib/n8n/server.env"
], ],
"ports": [ "ports": [
"5678" "5682:5678"
], ],
"volumes": [ "volumes": [
"/services/n8n/n8n-data:/home/node/.n8n" "/services/n8n/n8n-data:/home/node/.n8n"
-18
View File
@@ -1,18 +0,0 @@
# nats's server image: the upstream server, plus an entrypoint that reloads it in place when the
# mesh rewrites its configuration. See entrypoint.sh for why that belongs here and not in the host.
#
# **Pinned to the multi-architecture index digest, not a platform's.** `docker manifest inspect`
# reports a platform manifest per architecture and the index that lists them; pinning a platform's
# digest builds on this workstation and fails on any node of another architecture, with an error
# that names a manifest rather than the mistake. This is the index — `docker pull` reports the same
# one, and `RepoDigests` confirms it.
#
# Unlike every other module's Dockerfile, this builds no TypeScript and uses no mesh base image:
# the module's code is the server, which upstream already built. There is no BUILD_BASE here on
# purpose — nothing is compiled.
FROM nats@sha256:b83efabe3e7def1e0a4a31ec6e078999bb17c80363f881df35edc70fcb6bb927
COPY entrypoint.sh /usr/local/bin/mesh-nats-entrypoint
RUN chmod 0755 /usr/local/bin/mesh-nats-entrypoint
ENTRYPOINT ["/usr/local/bin/mesh-nats-entrypoint"]
-69
View File
@@ -1,69 +0,0 @@
#!/bin/sh
# nats's entrypoint: run the server, and reload it in place when the mesh rewrites its
# configuration.
#
# **Why this exists inside the module** (novox/hq design 25 §5). The controller composes every
# account and permission into one file, and that file changes whenever a module is added,
# reassigned, or a person's access is granted or revoked — which is often, and on the one server
# everything else depends on. The host has no way to say "reload this container": a
# container resource has `restart-on` and nothing else, and a container's `restart-on` means
# *recreate* — every connection dropped and every in-flight JetStream ack lost, mid-flight, for a
# permission change. `reload-on` is real but it is a *service* field, not a container's.
#
# nats-server already reloads its own configuration on SIGHUP — accounts, permissions, everything
# the mesh composes — without dropping a connection. That is the server's own documented
# capability, not something built for the mesh. So the configuration is mounted as a directory
# (a directory's contents are not digest-tracked the way a directly-mounted file's are, novox/hq
# issue 103), and this watches the one file inside it and signals the server itself. The host's
# only job is what it already does for any directory: keep the file's content current. Nothing
# here is declared `restart-on` or `reload-on`.
set -eu
# **Two files, and only one of them is the mesh's** (novox/hq design 25 §4, task 1.7). CONF is this
# module's own — ports, TLS, JetStream — declared in its manifest, because those are properties of
# the container this module raises. USERS is every account and permission, composed by the
# controller, and CONF includes it. So what is watched here is the mesh's half: the module's own
# does not change without a new declaration, and that recreates the container anyway.
CONF="${MESH_NATS_CONF:-/etc/nats/nats.conf}"
USERS="${MESH_NATS_USERS:-/etc/nats/accounts.conf}"
POLL="${MESH_NATS_CONF_POLL_SECONDS:-5}"
# Both are written as part of the same declaration that creates this container, but none of the
# three are ordered against each other. Waiting is correct and starting without them is not:
# nats-server given a configuration whose include is missing refuses to start, and one given no
# configuration at all comes up with its compiled-in defaults — no TLS, no accounts, every subject
# open to anyone who can reach the port. A bus that is briefly open to everything is not a bus that
# is briefly wrong; it is an open bus.
for needed in "$CONF" "$USERS"; do
while [ ! -s "$needed" ]; do
echo "[nats] waiting for the mesh to write $needed"
sleep 1
done
done
digest() { sha256sum "$USERS" 2>/dev/null | cut -d' ' -f1; }
nats-server --config "$CONF" "$@" &
server=$!
# Forward a stop to the server and let it drain, rather than dying and leaving it orphaned as
# PID 1's child.
stop() { kill -TERM "$server" 2>/dev/null || true; }
trap stop TERM INT
last=$(digest)
while kill -0 "$server" 2>/dev/null; do
sleep "$POLL"
now=$(digest)
# An empty digest means the file is mid-write or briefly gone. Reloading on that would hand the
# server a truncated configuration; the next tick sees the finished one.
[ -n "$now" ] || continue
if [ "$now" != "$last" ]; then
last=$now
echo "[nats] the mesh's user list changed; reloading in place"
kill -HUP "$server" || true
fi
done
# `wait` on an already-exited child still yields its status, which becomes this container's.
wait "$server"
-84
View File
@@ -1,84 +0,0 @@
{
"module": "nats",
"version": "1",
"provides": [
{
"name": "mesh-bus",
"scope": "mesh"
}
],
"claims": [
{
"name": "mesh-broker",
"scope": "mesh"
}
],
"bus-users": "/var/lib/nats-module/conf/accounts.conf",
"capabilities": [
"container-runtime"
],
"emits": [],
"consumes": [],
"listens": [
{
"port": 4222,
"protocol": "tcp",
"from": "mesh",
"why": "the mesh bus \u2014 every link the mesh has, over TLS, reached across the overlay"
}
],
"guards": [
8222
],
"resources": [
{
"id": "jetstream-data",
"type": "directory",
"path": "/var/lib/mesh-broker-nats",
"mode": "0700"
},
{
"id": "conf-dir",
"type": "directory",
"path": "/var/lib/nats-module/conf",
"mode": "0700"
},
{
"id": "server-conf",
"type": "file",
"path": "/var/lib/nats-module/conf/nats.conf",
"content": "# The nats module's own server settings. Declared by the module, because a port, a TLS path\n# and a store directory are properties of the container this module raises: they live in its\n# image and its mounts and change when it does.\n#\n# The mesh writes accounts.conf beside this one and nothing else. A controller that wrote the\n# whole file would have to be kept in step with a Dockerfile it never sees.\n\nport: 4222\nhttp: 127.0.0.1:8222\n\ntls {\n cert_file: \"/tls/tls.crt\"\n key_file: \"/tls/tls.key\"\n ca_file: \"/tls/ca.crt\"\n}\n\n# **No `verify`, deliberately, and it was `verify: true` until a probe ran this image.** That\n# setting makes the server demand a *client* certificate, and nothing in the mesh presents one: a\n# host pins this server's exact certificate and authenticates with the password the mesh minted\n# (novox/hq ADR 0004, design 25 \u00a74), and so does a module's runtime. With it on, every connection\n# in the mesh is refused at the TLS handshake, before any password is looked at \u2014 and the error is\n# \"client didn't provide a certificate\", which reads as a client fault.\n#\n# TLS is still required: a tls block is what makes it required, and verify only decides whether\n# client certificates are checked. What is given up is a second factor the mesh has no machinery\n# to issue or rotate \u2014 a certificate per module per node \u2014 and what is kept is stronger than a\n# name check in both directions: an exact pin outward, a per-user password inward.\n\njetstream {\n store_dir: \"/data\"\n}\n\n# Every user of the mesh, composed by the controller and rewritten whenever a module is\n# assigned, a node enrols or a person's access changes.\n#\n# **Relative, and in this same directory, because it has to be.** An absolute include path is\n# resolved relative to the including file's directory, not from the root: nats-server given\n# `include /etc/nats/accounts.conf` from /etc/nats-server/nats.conf looks for\n# /etc/nats-server/etc/nats/accounts.conf and refuses to start. Verified against the server.\ninclude accounts.conf\n",
"mode": "0644"
},
{
"id": "server",
"type": "container",
"name": "mesh-broker-nats",
"ports": [
"4222:4222",
"127.0.0.1:8222:8222"
],
"volumes": [
"/var/lib/mesh-broker-nats:/data",
"/var/lib/nats-module/conf:/etc/nats:ro",
"/var/lib/mesh-broker-nats-tls:/tls:ro"
],
"artifact": "server"
}
],
"accesses": [
{
"path": "/var/lib/mesh-broker-nats-tls",
"mode": "read"
}
],
"build": {
"artifacts": [
{
"name": "server",
"kind": "image",
"from": "Dockerfile"
}
]
}
}
-36
View File
@@ -1,36 +0,0 @@
{
"module": "networkmanager",
"version": "1",
"capabilities": [
"package-manager",
"service-manager"
],
"claims": [
{
"name": "node-uplink",
"scope": "node"
}
],
"resources": [
{
"id": "package",
"type": "package",
"package": "networkmanager"
},
{
"id": "config",
"type": "file",
"path": "/etc/NetworkManager/conf.d/50-mesh.conf",
"mode": "0644",
"content": "# Managed by the mesh (module networkmanager). Replaced on every push; edit the\n# catalogue instead.\n#\n# This machine's uplink is NetworkManager's, and this file is the whole of what\n# the mesh asks of it (novox/hq ADR 0117): leave the resolver file to the mesh,\n# and leave the private network's interface alone. Nothing more. The mesh never\n# declares a connection profile, an address, a route, a wireless network or its\n# credentials \u2014 those are joined at the machine, by the person using it, and\n# the link they make is the only channel the mesh reaches this machine over. A\n# push that got a link wrong could not be undone by the next one.\n#\n# A drop-in of the mesh's own, beside NetworkManager.conf and whatever else the\n# operator keeps in this directory. NetworkManager reads the files here sorted by\n# name and a later one wins a key it sets again \u2014 so a file of the operator's\n# that sorts after this one (any name starting with a letter does) and sets dns=\n# or unmanaged-devices= overrides it. That is the operator's to decide, and the\n# reason this file sets nothing but the two keys it must.\n#\n# NetworkManager itself is the machine's: the mesh never starts, stops, enables\n# or disables it (its service is declared with no state), because stopping it\n# takes every link down, this machine's channel to the mesh included \u2014 and a\n# module unassigned by mistake must not be able to do that. When this file\n# changes, a running NetworkManager is reloaded (its D-Bus Reload call, which\n# re-reads its configuration \u2014 NetworkManager(8)), never restarted.\n\n[main]\n# The resolver file is the mesh's: resolv-conf writes /etc/resolv.conf and names\n# the mesh's resolver. Without this line NetworkManager rewrites that file on\n# every connectivity change \u2014 every network joined, every lease renewed \u2014\n# and the mesh's resolver is silently replaced while every surface of the mesh\n# still reads green. none: \"NetworkManager will not modify resolv.conf. This\n# implies rc-manager unmanaged\" (NetworkManager.conf(5), 1.58). On an adopted\n# machine the predecessor wrote the same line in a file of its own; both say one\n# thing, and the predecessor's is retired by hand after the take.\ndns=none\n\n[keyfile]\n# mesh0 is the private network's interface: the mesh brings it up and the mesh\n# alone configures it. A manager that considers every interface its own could\n# try to configure it, or tear it down on a profile change.\n#\n# unmanaged-devices rather than a [device-mesh0] section with managed=0, because\n# NetworkManager.conf(5) says a device unmanaged by this key \"is strictly\n# unmanaged and cannot be overruled by using the API like nmcli device set\n# $IFNAME managed yes\", while device*.managed \"can be overruled at runtime via\n# D-Bus\". The same page adds that device*.managed \"may be a better choice\" for\n# exactly those reasons \u2014 for an interface the operator might want to hand back\n# at runtime. For the mesh's own interface, strict is the point.\n#\n# += rather than =: the same page documents appending to a list-valued key set\n# earlier (\"plugins+=another-plugin\") as an extension of its key file format,\n# and unmanaged-devices is a device list. = would replace whatever devices the\n# operator already keeps NetworkManager away from; += adds this one to them\n# (novox/hq ADR 0102: a list is added to, never replaced). A file of the\n# operator's read after this one that sets the key with = replaces it again;\n# that is the operator's to decide.\nunmanaged-devices+=interface-name:mesh0\n"
},
{
"id": "service",
"type": "service",
"unit": "NetworkManager.service",
"reload-on": [
"config"
]
}
]
}
-10
View File
@@ -9,11 +9,6 @@
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. # image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
ARG BUILD_BASE ARG BUILD_BASE
ARG RUNTIME_BASE ARG RUNTIME_BASE
ARG DOCKER_CLI
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
FROM ${DOCKER_CLI} AS dockercli
FROM ${BUILD_BASE} AS build FROM ${BUILD_BASE} AS build
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
@@ -27,11 +22,6 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts
FROM ${RUNTIME_BASE} FROM ${RUNTIME_BASE}
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
# systemd unit, no package manager tree pulled in for it).
COPY --from=dockercli /usr/local/bin/docker /usr/local/bin/docker
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a # Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
# provider's provisioner runs its reconcile loop in the same process, with the broker connected — # provider's provisioner runs its reconcile loop in the same process, with the broker connected —
# the convention novox/hq issues 060/061 settled. A container that instead ran only its # the convention novox/hq issues 060/061 settled. A container that instead ran only its
+2 -7
View File
@@ -52,13 +52,8 @@ export class NextcloudClient {
const container = cfg.container ?? env.MESH_NEXTCLOUD_CONTAINER ?? "nextcloud"; const container = cfg.container ?? env.MESH_NEXTCLOUD_CONTAINER ?? "nextcloud";
const ocsUrl = cfg.url ?? env.MESH_NEXTCLOUD_URL ?? `http://127.0.0.1:${env.NEXTCLOUD_PORT ?? "80"}`; const ocsUrl = cfg.url ?? env.MESH_NEXTCLOUD_URL ?? `http://127.0.0.1:${env.NEXTCLOUD_PORT ?? "80"}`;
const adminUser = cfg.user ?? env.MESH_NEXTCLOUD_ADMIN_USER ?? "admin"; const adminUser = cfg.user ?? env.MESH_NEXTCLOUD_ADMIN_USER ?? "admin";
const passwordFile = env.MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE; const adminPassword = cfg.password ?? env.MESH_NEXTCLOUD_ADMIN_PASSWORD;
const adminPassword = cfg.password ?? env.MESH_NEXTCLOUD_ADMIN_PASSWORD if (!adminPassword) throw new Error("no Nextcloud admin password — set MESH_NEXTCLOUD_ADMIN_PASSWORD");
?? (passwordFile ? readFileSync(passwordFile, "utf8").trim() : undefined);
if (!adminPassword) {
throw new Error("no Nextcloud admin password — set MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE " +
"(or MESH_NEXTCLOUD_ADMIN_PASSWORD)");
}
return new NextcloudClient(container, ocsUrl.replace(/\/$/, ""), adminUser, adminPassword); return new NextcloudClient(container, ocsUrl.replace(/\/$/, ""), adminUser, adminPassword);
} }
+2 -2
View File
@@ -26,7 +26,7 @@ async function pollUsers(client: NextcloudClient): Promise<void> {
const users = client.listUsers(); const users = client.listUsers();
for (const u of users) { for (const u of users) {
if (knownUsers.has(u.uid)) continue; if (knownUsers.has(u.uid)) continue;
if (usersPrimed) await emit("user.created", { uid: u.uid, displayName: u.displayName }); if (usersPrimed) await emit("module.nextcloud.user.created", { uid: u.uid, displayName: u.displayName });
knownUsers.add(u.uid); knownUsers.add(u.uid);
} }
usersPrimed = true; usersPrimed = true;
@@ -38,7 +38,7 @@ async function pollShares(client: NextcloudClient): Promise<void> {
const shares = await client.listShares(); const shares = await client.listShares();
for (const s of shares) { for (const s of shares) {
if (knownShares.has(s.id)) continue; if (knownShares.has(s.id)) continue;
if (sharesPrimed) await emit("share.created", { id: s.id, path: s.path, shareType: s.shareType, shareWith: s.shareWith, owner: s.owner }); if (sharesPrimed) await emit("module.nextcloud.share.created", { id: s.id, path: s.path, shareType: s.shareType, shareWith: s.shareWith, owner: s.owner });
knownShares.add(s.id); knownShares.add(s.id);
} }
sharesPrimed = true; sharesPrimed = true;
+21 -24
View File
@@ -11,26 +11,29 @@
"postgres-database": { "postgres-database": {
"name": "nextcloud" "name": "nextcloud"
}, },
"s3-bucket": {
"bucket": "nextcloud"
},
"route": { "route": {
"label": "drive", "label": "drive",
"port": 80 "port": 80
} }
}, },
"binds": { "binds": {
"postgres-database": "${dir:state}/database.json", "postgres-database": "/var/lib/nextcloud-module/database.json",
"s3-bucket": "${dir:state}/store.json", "s3-bucket": "/var/lib/nextcloud-module/store.json",
"route": "${dir:state}/route.json" "route": "/var/lib/nextcloud-module/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "${dir:state}/database.secret", "postgres-database": "/var/lib/nextcloud-module/database.secret",
"s3-bucket": "${dir:state}/store.secret" "s3-bucket": "/var/lib/nextcloud-module/store.secret"
}, },
"emits": [ "emits": [
"user.created", "module.nextcloud.user.created",
"share.created" "module.nextcloud.share.created"
], ],
"own-secrets": { "own-secrets": {
"admin": "${dir:state}/admin.secret", "admin": "/var/lib/nextcloud-module/admin.secret",
"broker": "/var/lib/mesh/nextcloud/broker" "broker": "/var/lib/mesh/nextcloud/broker"
}, },
"capabilities": [ "capabilities": [
@@ -54,19 +57,20 @@
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",
"mode": "0700", "path": "/var/lib/nextcloud-module",
"place": "." "mode": "0700"
}, },
{ {
"id": "server-env", "id": "server-env",
"type": "file", "type": "file",
"path": "${dir:state}/server.env", "path": "/var/lib/nextcloud-module/server.env",
"mode": "0600", "mode": "0600",
"content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=mesh-admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=mesh-novox-ncloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\nOBJECTSTORE_S3_REGION=${bound:s3-bucket:region}\n" "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=nextcloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\n"
}, },
{ {
"id": "html", "id": "html",
"type": "directory", "type": "directory",
"path": "/services/nextcloud/html",
"mode": "0750", "mode": "0750",
"owner": "33:33" "owner": "33:33"
}, },
@@ -74,15 +78,15 @@
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "nextcloud", "name": "nextcloud",
"image": "nextcloud@sha256:fb966733647ea03f0446b0c22eac9733c8eb616d37b960caca9d4c3010e14a08", "image": "nextcloud@sha256:0b8261f6335af6b95264ce893b4d645857638e0fa151b5ba620f25f377318ae1",
"env-file": [ "env-file": [
"${dir:state}/server.env" "/var/lib/nextcloud-module/server.env"
], ],
"ports": [ "ports": [
"80" "80"
], ],
"volumes": [ "volumes": [
"${dir:html}:/var/www/html" "/services/nextcloud/html:/var/www/html"
], ],
"secrets-in-environment": "the image honours POSTGRES_PASSWORD_FILE and NEXTCLOUD_ADMIN_PASSWORD_FILE (entrypoint file_env); OBJECTSTORE_S3_SECRET has none and needs a generated config fragment; convertible, awaiting a bed" "secrets-in-environment": "the image honours POSTGRES_PASSWORD_FILE and NEXTCLOUD_ADMIN_PASSWORD_FILE (entrypoint file_env); OBJECTSTORE_S3_SECRET has none and needs a generated config fragment; convertible, awaiting a bed"
}, },
@@ -102,15 +106,12 @@
"volumes": [ "volumes": [
"/var/lib/mesh/nextcloud/broker:/run/secrets/broker:ro", "/var/lib/mesh/nextcloud/broker:/run/secrets/broker:ro",
"/var/lib/mesh/nextcloud/config.json:/run/config/config.json:ro", "/var/lib/mesh/nextcloud/config.json:/run/config/config.json:ro",
"${dir:state}/admin.secret:/run/secrets/admin:ro",
"/var/run/docker.sock:/var/run/docker.sock" "/var/run/docker.sock:/var/run/docker.sock"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}", "MESH_NEXTCLOUD_URL": "http://127.0.0.1:80",
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json", "MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json"
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
}, },
"restart-on": [ "restart-on": [
"runtime-config" "runtime-config"
@@ -129,10 +130,6 @@
"arg": "RUNTIME_BASE", "arg": "RUNTIME_BASE",
"module": "mesh-tools", "module": "mesh-tools",
"artifact": "runtime" "artifact": "runtime"
},
{
"arg": "DOCKER_CLI",
"image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca"
} }
], ],
"artifacts": [ "artifacts": [
+2 -2
View File
@@ -6,7 +6,7 @@
], ],
"claims": [ "claims": [
{ {
"name": "node-packet-filter", "name": "the-packet-filter",
"scope": "node" "scope": "node"
} }
], ],
@@ -30,7 +30,7 @@
"id": "stock-unit-stop", "id": "stock-unit-stop",
"type": "file", "type": "file",
"path": "/etc/systemd/system/nftables.service.d/mesh.conf", "path": "/etc/systemd/system/nftables.service.d/mesh.conf",
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) \u2014 a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n", "content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
"mode": "0644" "mode": "0644"
}, },
{ {
+1 -1
View File
@@ -2,7 +2,7 @@
"module": "nodered", "module": "nodered",
"version": "1", "version": "1",
"emits": [ "emits": [
"flows.deployed" "module.nodered.flows.deployed"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/nodered/broker" "broker": "/var/lib/mesh/nodered/broker"
+1 -1
View File
@@ -43,7 +43,7 @@ export function getNodeRedTools(nodered: NodeRedClient): ToolDefinition[] {
const result = await nodered.deployFlows(flows, type); const result = await nodered.deployFlows(flows, type);
// Best-effort announcement — a deploy must not fail because the broker is unbound here. // Best-effort announcement — a deploy must not fail because the broker is unbound here.
try { try {
await emit("flows.deployed", { rev: result.rev, nodeCount: result.nodeCount, type }); await emit("module.nodered.flows.deployed", { rev: result.rev, nodeCount: result.nodeCount, type });
} catch (err) { } catch (err) {
console.error(`[nodered] deployed but could not emit: ${err}`); console.error(`[nodered] deployed but could not emit: ${err}`);
} }

Some files were not shown because too many files have changed in this diff Show More