Converts HAL's gitlab into a self-contained mesh module and establishes the template for every tools-only external-SaaS integration (jira, confluence, code-review follow mechanically).
Shape (modelled on the shipping cloudflare-dns): runtime-only container, no service, no listener, no provisioner. Public GITLAB_URL via a config.jsonmerge:json file resource; the GitLab API token as an own-secrets entry the operator supplies with secret accept (origin accepted) — not the model-access licence mechanism (that's model-specific).
23 tools ported faithfully from HAL's real surface (projects, merge requests, pipelines/jobs, project + group variables) — HAL's entire gitlab tool set, translated to mesh-sdk's shape. No tools invented.
Servarr lesson honoured: the client is lazy and never throws at registration, so the runtime serves all 23 tools even with no valid token; a tool only fails when actually invoked without creds.
Lab-proven green:assigned-tools-gitlab — the runtime comes up under the mesh, stays up (RestartCount 0) with no token, logs serving 23 tool(s), binds its serve queues, and gets its scoped broker account. SUITE_EXIT=0 on a real incus VM (mesh-host aa441ba, mesh-control 3b0f17b).
Converts HAL's `gitlab` into a self-contained mesh module and establishes the **template for every tools-only external-SaaS integration** (jira, confluence, code-review follow mechanically).
Shape (modelled on the shipping `cloudflare-dns`): runtime-only container, no service, no listener, no provisioner. Public `GITLAB_URL` via a `config.json` `merge:json` file resource; the GitLab API token as an `own-secrets` entry the operator supplies with `secret accept` (origin `accepted`) — **not** the model-access licence mechanism (that's model-specific).
- **23 tools** ported faithfully from HAL's real surface (projects, merge requests, pipelines/jobs, project + group variables) — HAL's entire gitlab tool set, translated to mesh-sdk's shape. No tools invented.
- **Servarr lesson honoured:** the client is lazy and never throws at registration, so the runtime serves all 23 tools even with no valid token; a tool only fails when actually invoked without creds.
- **Lab-proven green:** `assigned-tools-gitlab` — the runtime comes up under the mesh, stays up (RestartCount 0) with no token, logs `serving 23 tool(s)`, binds its serve queues, and gets its scoped broker account. SUITE_EXIT=0 on a real incus VM (mesh-host aa441ba, mesh-control 3b0f17b).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Port the HAL gitlab module (whose tools lived in @hal/sdk) into a
self-contained mesh-catalog module modelled on cloudflare-dns: the GitLab
API client and all its tools live in the module (ADR 0039), served through
mesh-sdk's registerModuleTools harness.
Tools-only, outbound-only external-SaaS shape: a runtime-only container on
network:host, no service, no listener, no provisioner. The token is an
own-secret; GITLAB_URL is a public setting in a merge:json config file.
The client is built lazily and never throws at registration, so the runtime
comes up and serves all 23 tools even with no valid token (the Servarr
lesson) — it only fails when a tool is actually invoked unconfigured.
Ported 23 tools: projects (list, get), merge requests (list, get, create,
approve, add note), pipelines (list, get, retry, cancel, list jobs, job log),
and project + group CI/CD variables (list, get, create, update, delete each).
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Converts HAL's
gitlabinto a self-contained mesh module and establishes the template for every tools-only external-SaaS integration (jira, confluence, code-review follow mechanically).Shape (modelled on the shipping
cloudflare-dns): runtime-only container, no service, no listener, no provisioner. PublicGITLAB_URLvia aconfig.jsonmerge:jsonfile resource; the GitLab API token as anown-secretsentry the operator supplies withsecret accept(originaccepted) — not the model-access licence mechanism (that's model-specific).assigned-tools-gitlab— the runtime comes up under the mesh, stays up (RestartCount 0) with no token, logsserving 23 tool(s), binds its serve queues, and gets its scoped broker account. SUITE_EXIT=0 on a real incus VM (mesh-host aa441ba, mesh-control 3b0f17b).https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF