diff --git a/modules/baserow/Dockerfile b/modules/baserow/Dockerfile deleted file mode 100644 index e60fe27..0000000 --- a/modules/baserow/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# baserow's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/baserow -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/baserow/dist /app/modules/baserow/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/baserow/dist/tools/index.js diff --git a/modules/baserow/module.json b/modules/baserow/module.json index 66a229a..7a70c65 100644 --- a/modules/baserow/module.json +++ b/modules/baserow/module.json @@ -25,8 +25,7 @@ "postgres-database": "${dir:state}/database.secret" }, "own-secrets": { - "admin": "${dir:state}/admin.secret", - "broker": "${dir:mesh-state}/broker" + "admin": "${dir:state}/admin.secret" }, "listens": [ { @@ -92,45 +91,21 @@ "mode": "0600", "content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n", "merge": "json" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-baserow", - "network": "baserow", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_BASEROW_URL": "http://baserow:80", - "MESH_BASEROW_CONFIG_FILE": "/run/config/config.json" - }, - "restart-on": [ - "runtime-config" - ], - "artifact": "runtime" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_BASEROW_URL": "http://127.0.0.1:${port:80}", + "MESH_BASEROW_CONFIG_FILE": "${dir:mesh-state}/config.json" + } } ] } diff --git a/modules/confluence/Dockerfile b/modules/confluence/Dockerfile deleted file mode 100644 index f2e075a..0000000 --- a/modules/confluence/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# confluence's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/confluence -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/confluence/dist /app/modules/confluence/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/confluence/dist/tools/index.js diff --git a/modules/confluence/module.json b/modules/confluence/module.json index 5e32288..27d6298 100644 --- a/modules/confluence/module.json +++ b/modules/confluence/module.json @@ -3,16 +3,9 @@ "version": "1", "slug": "confl", "own-secrets": { - "token": "${dir:state}/token", - "broker": "${dir:mesh-state}/broker" + "token": "${dir:state}/token" }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -26,46 +19,24 @@ "merge": "json", "content": "{}", "mode": "0600" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-runtime-confluence", - "network": "host", - "volumes": [ - "${dir:state}/config.json:/run/config/config.json:ro", - "${dir:state}/token:/run/secrets/token:ro", - "${dir:mesh-state}/broker:/run/secrets/broker:ro" - ], - "env": { - "MESH_CONFLUENCE_TOKEN_FILE": "/run/secrets/token", - "MESH_CONFLUENCE_CONFIG_FILE": "/run/config/config.json", - "MESH_BROKER_FILE": "/run/secrets/broker" - }, - "artifact": "runtime" } ], "capabilities": [ "container-runtime" ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_CONFLUENCE_TOKEN_FILE": "${dir:state}/token", + "MESH_CONFLUENCE_CONFIG_FILE": "${dir:state}/config.json" + } } ] } diff --git a/modules/gitlab/Dockerfile b/modules/gitlab/Dockerfile deleted file mode 100644 index 4a27d6c..0000000 --- a/modules/gitlab/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# gitlab's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/gitlab -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/gitlab/dist /app/modules/gitlab/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/gitlab/dist/tools/index.js diff --git a/modules/gitlab/module.json b/modules/gitlab/module.json index 1667c10..b14d51b 100644 --- a/modules/gitlab/module.json +++ b/modules/gitlab/module.json @@ -2,16 +2,9 @@ "module": "gitlab", "version": "1", "own-secrets": { - "token": "${dir:state}/token", - "broker": "${dir:mesh-state}/broker" + "token": "${dir:state}/token" }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -25,46 +18,24 @@ "merge": "json", "content": "{}", "mode": "0600" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-runtime-gitlab", - "network": "host", - "volumes": [ - "${dir:state}/config.json:/run/config/config.json:ro", - "${dir:state}/token:/run/secrets/token:ro", - "${dir:mesh-state}/broker:/run/secrets/broker:ro" - ], - "env": { - "MESH_GITLAB_TOKEN_FILE": "/run/secrets/token", - "MESH_GITLAB_CONFIG_FILE": "/run/config/config.json", - "MESH_BROKER_FILE": "/run/secrets/broker" - }, - "artifact": "runtime" } ], "capabilities": [ "container-runtime" ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_GITLAB_TOKEN_FILE": "${dir:state}/token", + "MESH_GITLAB_CONFIG_FILE": "${dir:state}/config.json" + } } ] } diff --git a/modules/jira/Dockerfile b/modules/jira/Dockerfile deleted file mode 100644 index 0d9cabb..0000000 --- a/modules/jira/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# jira's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/jira -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/jira/dist /app/modules/jira/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/jira/dist/tools/index.js diff --git a/modules/jira/module.json b/modules/jira/module.json index 5cf05cc..513ffff 100644 --- a/modules/jira/module.json +++ b/modules/jira/module.json @@ -2,16 +2,9 @@ "module": "jira", "version": "1", "own-secrets": { - "token": "${dir:state}/token", - "broker": "${dir:mesh-state}/broker" + "token": "${dir:state}/token" }, "resources": [ - { - "id": "mesh-state", - "type": "directory", - "mode": "0700", - "place": "mesh" - }, { "id": "state", "type": "directory", @@ -25,46 +18,24 @@ "merge": "json", "content": "{}", "mode": "0600" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-runtime-jira", - "network": "host", - "volumes": [ - "${dir:state}/config.json:/run/config/config.json:ro", - "${dir:state}/token:/run/secrets/token:ro", - "${dir:mesh-state}/broker:/run/secrets/broker:ro" - ], - "env": { - "MESH_JIRA_TOKEN_FILE": "/run/secrets/token", - "MESH_JIRA_CONFIG_FILE": "/run/config/config.json", - "MESH_BROKER_FILE": "/run/secrets/broker" - }, - "artifact": "runtime" } ], "capabilities": [ "container-runtime" ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_JIRA_TOKEN_FILE": "${dir:state}/token", + "MESH_JIRA_CONFIG_FILE": "${dir:state}/config.json" + } } ] } diff --git a/modules/letta/Dockerfile b/modules/letta/Dockerfile deleted file mode 100644 index cd28e15..0000000 --- a/modules/letta/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# letta's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/letta -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/letta/dist /app/modules/letta/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/letta/dist/tools/index.js diff --git a/modules/letta/module.json b/modules/letta/module.json index c3107a2..3ea4c05 100644 --- a/modules/letta/module.json +++ b/modules/letta/module.json @@ -26,8 +26,7 @@ }, "own-secrets": { "server-password": "${dir:state}/server-password.secret", - "openai-api-key": "${dir:state}/openai-api-key.secret", - "broker": "${dir:mesh-state}/broker" + "openai-api-key": "${dir:state}/openai-api-key.secret" }, "listens": [ { @@ -84,45 +83,21 @@ "mode": "0600", "content": "{\n \"password\": \"${secret:server-password}\"\n}\n", "merge": "json" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-letta", - "network": "letta", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_LETTA_URL": "http://letta:8283", - "MESH_LETTA_CONFIG_FILE": "/run/config/config.json" - }, - "restart-on": [ - "runtime-config" - ], - "artifact": "runtime" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_LETTA_URL": "http://127.0.0.1:${port:8283}", + "MESH_LETTA_CONFIG_FILE": "${dir:mesh-state}/config.json" + } } ] } diff --git a/modules/searxng/Dockerfile b/modules/searxng/Dockerfile deleted file mode 100644 index 12e7f29..0000000 --- a/modules/searxng/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# searxng's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/searxng -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/searxng/dist /app/modules/searxng/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/searxng/dist/tools/index.js diff --git a/modules/searxng/module.json b/modules/searxng/module.json index 9ecc0ab..b95b4a8 100644 --- a/modules/searxng/module.json +++ b/modules/searxng/module.json @@ -8,8 +8,7 @@ "secret": { "path": "${dir:mesh-state}/secret", "taken": "at-start" - }, - "broker": "${dir:mesh-state}/broker" + } }, "listens": [ { @@ -91,25 +90,6 @@ "path": "${dir:mesh-state}/config.json", "mode": "0600", "content": "{}\n" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-searxng", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_SEARXNG_URL": "http://127.0.0.1:${port:8080}", - "MESH_SEARXNG_CONFIG_FILE": "/run/config/config.json" - }, - "restart-on": [ - "runtime-config" - ], - "artifact": "runtime" } ], "requires": [ @@ -125,23 +105,18 @@ "route": "${dir:state}/route.json" }, "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_SEARXNG_URL": "http://127.0.0.1:${port:8080}", + "MESH_SEARXNG_CONFIG_FILE": "${dir:mesh-state}/config.json" + } } ] } diff --git a/modules/unifi/Dockerfile b/modules/unifi/Dockerfile deleted file mode 100644 index cea9f20..0000000 --- a/modules/unifi/Dockerfile +++ /dev/null @@ -1,24 +0,0 @@ -# unifi's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE - -FROM ${BUILD_BASE} AS build -WORKDIR /app/modules/unifi -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/unifi/dist /app/modules/unifi/dist -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. -ENV MESH_TOOL_MODULES=/app/modules/unifi/dist/tools/index.js diff --git a/modules/unifi/module.json b/modules/unifi/module.json index d4e1934..b1edb49 100644 --- a/modules/unifi/module.json +++ b/modules/unifi/module.json @@ -122,25 +122,6 @@ "mode": "0600", "content": "{\n \"site\": \"default\",\n \"password\": \"${secret:controller}\"\n}\n", "merge": "json" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-unifi", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_UNIFI_URL": "https://127.0.0.1:${port:8443}", - "MESH_UNIFI_CONFIG_FILE": "/run/config/config.json" - }, - "restart-on": [ - "runtime-config" - ], - "artifact": "runtime" } ], "requires": [ @@ -158,27 +139,21 @@ "route": "${dir:state}/route.json" }, "own-secrets": { - "broker": "${dir:mesh-state}/broker", "controller": "${dir:mesh-state}/controller" }, "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "tools", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "tools/index.js" + ], + "env": { + "MESH_UNIFI_URL": "https://127.0.0.1:${port:8443}", + "MESH_UNIFI_CONFIG_FILE": "${dir:mesh-state}/config.json" + } } ] }