n8n: its own image built from source, placed data, and what its workflows use #172

Open
mesh-admin wants to merge 1 commits from feat/n8n-for-ace into main
Contributor

The module named /var/lib/n8n, /services/n8n/n8n-data and n8n.novox.be -
paths and a domain no definition may carry (ADR 0112). State and data are
placed directories; the public name is ${bound:route:name} (depends on
mesh-controller #149), for N8N_HOST and WEBHOOK_URL alike.

The endpoint said 5682 while the container publishes 5678. 5682 was one
machine's host port; the endpoint is the software's port and the mesh
assigns the machine's (ADR 0038).

n8n had been run from an image in a registry that no longer exists: the
upstream image plus shadow, a media group (2000) with node in it, and
a global uuid. That recipe is now this module's Dockerfile, built on the
upstream 1.71.3 image named in build.on by digest, with uuid pinned to the
version the running image carries (14.0.1) - Code nodes require() it. The
media group is how the container writes into the shared media library, a
read-write access (ADR 0051), mounted where workflows expect it,
/media-library.

The workflows also use a redis (the Redis nodes of the chat workflows) and a
Selenium Chrome (the scraper), which the previous deployment ran beside n8n.
Both are containers on the module's own network, publishing nothing, pinned
to the digests in use; redis keeps its append-only file in a placed
directory.

The basic-auth secret is gone: N8N_BASIC_AUTH_* was removed in n8n 1.0 and
did nothing. The grant's password is a 0400 file owned by node, read
through DB_POSTGRESDB_PASSWORD_FILE, so nothing secret is in the
environment. The credentials' encryption key is n8n's own, in the data
directory (config), and moves with it - nothing to mint or accept.

Verified: catalogue tests with MESH_CATALOGUE set; the Dockerfile built
against the pinned base gives n8n 1.71.3, uid 1000 in group 2000, uuid
14.0.1 - the running image's shape. Throwaway containers: an instance on
PostgreSQL 15 with an owner, a workflow and an encrypted credential;
stopped, copied, dumped from the copy, restored (--no-owner --role, the
uuid-ossp extension pre-made by the superuser) into a grant-shaped
database on the postgres module's pgvector image (PG17); the new shape
(password from the file, data dir copied) serves /healthz, the owner logs
in, the workflow is listed, and the credential decrypts with the carried
key. The node user writes into a root:2000 0775 library through the media
group; redis and Selenium resolve by name on the module network and
Selenium reports ready. Test containers and data removed.

Depends on mesh-controller #149 for ${bound:route:name} (N8N_HOST, WEBHOOK_URL). The media library access keeps the generic default path; the machine's real path is an assignment matter once hq 153 lands. Prepared for ace's migration; nothing is assigned.

The module named /var/lib/n8n, /services/n8n/n8n-data and n8n.novox.be - paths and a domain no definition may carry (ADR 0112). State and data are placed directories; the public name is ${bound:route:name} (depends on mesh-controller #149), for N8N_HOST and WEBHOOK_URL alike. The endpoint said 5682 while the container publishes 5678. 5682 was one machine's host port; the endpoint is the software's port and the mesh assigns the machine's (ADR 0038). n8n had been run from an image in a registry that no longer exists: the upstream image plus shadow, a `media` group (2000) with `node` in it, and a global `uuid`. That recipe is now this module's Dockerfile, built on the upstream 1.71.3 image named in build.on by digest, with uuid pinned to the version the running image carries (14.0.1) - Code nodes require() it. The media group is how the container writes into the shared media library, a read-write `access` (ADR 0051), mounted where workflows expect it, /media-library. The workflows also use a redis (the Redis nodes of the chat workflows) and a Selenium Chrome (the scraper), which the previous deployment ran beside n8n. Both are containers on the module's own network, publishing nothing, pinned to the digests in use; redis keeps its append-only file in a placed directory. The basic-auth secret is gone: N8N_BASIC_AUTH_* was removed in n8n 1.0 and did nothing. The grant's password is a 0400 file owned by `node`, read through DB_POSTGRESDB_PASSWORD_FILE, so nothing secret is in the environment. The credentials' encryption key is n8n's own, in the data directory (config), and moves with it - nothing to mint or accept. Verified: catalogue tests with MESH_CATALOGUE set; the Dockerfile built against the pinned base gives n8n 1.71.3, uid 1000 in group 2000, uuid 14.0.1 - the running image's shape. Throwaway containers: an instance on PostgreSQL 15 with an owner, a workflow and an encrypted credential; stopped, copied, dumped from the copy, restored (--no-owner --role, the uuid-ossp extension pre-made by the superuser) into a grant-shaped database on the postgres module's pgvector image (PG17); the new shape (password from the file, data dir copied) serves /healthz, the owner logs in, the workflow is listed, and the credential decrypts with the carried key. The node user writes into a root:2000 0775 library through the media group; redis and Selenium resolve by name on the module network and Selenium reports ready. Test containers and data removed. Depends on mesh-controller #149 for `${bound:route:name}` (N8N_HOST, WEBHOOK_URL). The media library access keeps the generic default path; the machine's real path is an assignment matter once hq 153 lands. Prepared for ace's migration; nothing is assigned.
mesh-admin added 1 commit 2026-09-30 10:26:02 +00:00
The module named /var/lib/n8n, /services/n8n/n8n-data and n8n.novox.be -
paths and a domain no definition may carry (ADR 0112). State and data are
placed directories; the public name is ${bound:route:name} (depends on
mesh-controller #149), for N8N_HOST and WEBHOOK_URL alike.

The endpoint said 5682 while the container publishes 5678. 5682 was one
machine's host port; the endpoint is the software's port and the mesh
assigns the machine's (ADR 0038).

n8n had been run from an image in a registry that no longer exists: the
upstream image plus shadow, a `media` group (2000) with `node` in it, and
a global `uuid`. That recipe is now this module's Dockerfile, built on the
upstream 1.71.3 image named in build.on by digest, with uuid pinned to the
version the running image carries (14.0.1) - Code nodes require() it. The
media group is how the container writes into the shared media library, a
read-write `access` (ADR 0051), mounted where workflows expect it,
/media-library.

The workflows also use a redis (the Redis nodes of the chat workflows) and a
Selenium Chrome (the scraper), which the previous deployment ran beside n8n.
Both are containers on the module's own network, publishing nothing, pinned
to the digests in use; redis keeps its append-only file in a placed
directory.

The basic-auth secret is gone: N8N_BASIC_AUTH_* was removed in n8n 1.0 and
did nothing. The grant's password is a 0400 file owned by `node`, read
through DB_POSTGRESDB_PASSWORD_FILE, so nothing secret is in the
environment. The credentials' encryption key is n8n's own, in the data
directory (config), and moves with it - nothing to mint or accept.

Verified: catalogue tests with MESH_CATALOGUE set; the Dockerfile built
against the pinned base gives n8n 1.71.3, uid 1000 in group 2000, uuid
14.0.1 - the running image's shape. Throwaway containers: an instance on
PostgreSQL 15 with an owner, a workflow and an encrypted credential;
stopped, copied, dumped from the copy, restored (--no-owner --role, the
uuid-ossp extension pre-made by the superuser) into a grant-shaped
database on the postgres module's pgvector image (PG17); the new shape
(password from the file, data dir copied) serves /healthz, the owner logs
in, the workflow is listed, and the credential decrypts with the carried
key. The node user writes into a root:2000 0775 library through the media
group; redis and Selenium resolve by name on the module network and
Selenium reports ready. Test containers and data removed.
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/n8n-for-ace:feat/n8n-for-ace
git checkout feat/n8n-for-ace
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#172