After wave 1, mosquitto's tools ran mosquitto_ctrl from a host package. On a machine whose package index is stale (hq issue 205), the package cannot be installed, and every dynsec tool failed with ENOENT.
The broker's image already carries mosquitto_ctrl at the broker's own version, so:
The tools run it through docker exec into the broker's container, against 127.0.0.1:1883 inside it. The bundle gets MESH_MQTT_CTRL_CONTAINER.
The bootstrap seeds the security file from a throwaway container of the pinned image. The broker may never have started yet, so it cannot exec. The step gets MESH_MQTT_CTRL_IMAGE.
The host package resource is removed.
Without either variable, the code runs the machine's own mosquitto_ctrl, as before.
Checked: the module typechecks and its tests pass, 7 of 7, including two new tests for where the tool runs. On the live machine, the runtime's account can run docker exec mosquitto mosquitto_ctrl.
After wave 1, mosquitto's tools ran `mosquitto_ctrl` from a host package. On a machine whose package index is stale (hq issue 205), the package cannot be installed, and every dynsec tool failed with ENOENT.
The broker's image already carries `mosquitto_ctrl` at the broker's own version, so:
- The tools run it through `docker exec` into the broker's container, against 127.0.0.1:1883 inside it. The bundle gets `MESH_MQTT_CTRL_CONTAINER`.
- The bootstrap seeds the security file from a throwaway container of the pinned image. The broker may never have started yet, so it cannot exec. The step gets `MESH_MQTT_CTRL_IMAGE`.
- The host package resource is removed.
- Without either variable, the code runs the machine's own `mosquitto_ctrl`, as before.
Checked: the module typechecks and its tests pass, 7 of 7, including two new tests for where the tool runs. On the live machine, the runtime's account can run `docker exec mosquitto mosquitto_ctrl`.
The module's code moved out of its container and took mosquitto_ctrl from a host package. A
machine whose package index is stale cannot install it (hq issue 205), so the tools failed. The
broker's own image carries the tool at the broker's version: the tools exec into the running
broker, and the bootstrap seeds from a throwaway container of the same image.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
After wave 1, mosquitto's tools ran
mosquitto_ctrlfrom a host package. On a machine whose package index is stale (hq issue 205), the package cannot be installed, and every dynsec tool failed with ENOENT.The broker's image already carries
mosquitto_ctrlat the broker's own version, so:docker execinto the broker's container, against 127.0.0.1:1883 inside it. The bundle getsMESH_MQTT_CTRL_CONTAINER.MESH_MQTT_CTRL_IMAGE.mosquitto_ctrl, as before.Checked: the module typechecks and its tests pass, 7 of 7, including two new tests for where the tool runs. On the live machine, the runtime's account can run
docker exec mosquitto mosquitto_ctrl.