Wave 1: thirteen modules' code moves into bundles the node's runtime serves (hq ADR 0198, to-be 38 WP4c) #245
@@ -1,24 +0,0 @@
|
|||||||
# cloudflare-dns's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/cloudflare-dns
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/cloudflare-dns/dist /app/modules/cloudflare-dns/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/cloudflare-dns/dist/tools/index.js,/app/modules/cloudflare-dns/dist/provisioner/index.js
|
|
||||||
@@ -18,20 +18,13 @@
|
|||||||
"public-dns": "${dir:grants}/mesh.json"
|
"public-dns": "${dir:grants}/mesh.json"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"token": "${dir:state}/token",
|
"token": "${dir:state}/token"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"emits": [
|
"emits": [
|
||||||
"record.created",
|
"record.created",
|
||||||
"record.removed"
|
"record.removed"
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"mode": "0700",
|
|
||||||
"place": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -50,48 +43,30 @@
|
|||||||
"merge": "json",
|
"merge": "json",
|
||||||
"content": "{}",
|
"content": "{}",
|
||||||
"mode": "0600"
|
"mode": "0600"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-cloudflare-dns",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:state}/config.json:/run/config/config.json:ro",
|
|
||||||
"${dir:grants}:/grants",
|
|
||||||
"${dir:state}/token:/run/secrets/token:ro",
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_CLOUDFLARE_TOKEN_FILE": "/run/secrets/token",
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_CLOUDFLARE_CONFIG_FILE": "/run/config/config.json",
|
|
||||||
"MESH_RECEIVES": "/var/lib/cloudflare-dns/grants/mesh.json"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_CLOUDFLARE_TOKEN_FILE": "${dir:state}/token",
|
||||||
|
"MESH_CLOUDFLARE_CONFIG_FILE": "${dir:state}/config.json",
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,24 +0,0 @@
|
|||||||
# grafana's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/grafana
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/grafana/dist /app/modules/grafana/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/grafana/dist/index.js,/app/modules/grafana/dist/tools/index.js
|
|
||||||
+16
-36
@@ -5,8 +5,7 @@
|
|||||||
"alert.firing"
|
"alert.firing"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:mesh-state}/admin",
|
"admin": "${dir:mesh-state}/admin"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
@@ -112,25 +111,6 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{\n \"user\": \"admin\",\n \"password\": \"${secret:admin}\"\n}\n",
|
"content": "{\n \"user\": \"admin\",\n \"password\": \"${secret:admin}\"\n}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-grafana",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_GRAFANA_URL": "http://127.0.0.1:${port:3000}",
|
|
||||||
"MESH_GRAFANA_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
@@ -162,23 +142,23 @@
|
|||||||
"influxdb-api": "${dir:mesh-state}/influxdb-api"
|
"influxdb-api": "${dir:mesh-state}/influxdb-api"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_GRAFANA_URL": "http://127.0.0.1:${port:3000}",
|
||||||
|
"MESH_GRAFANA_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,27 +0,0 @@
|
|||||||
# home-assistant's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/home-assistant
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisions/hass.ts provisions/probe.ts provisions/connections.ts provisions/mesh.ts provisions/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/home-assistant/dist /app/modules/home-assistant/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/home-assistant/dist/index.js,/app/modules/home-assistant/dist/tools/index.js
|
|
||||||
# NOT dist/provisions/index.js: that is a step the host runs to completion, named by the
|
|
||||||
# `provisions` container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run
|
|
||||||
# inside the serving sidecar too, and exit it.
|
|
||||||
@@ -9,7 +9,6 @@
|
|||||||
"state.changed"
|
"state.changed"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "${dir:mesh-state}/broker",
|
|
||||||
"token": "${dir:mesh-state}/token"
|
"token": "${dir:mesh-state}/token"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
@@ -80,55 +79,27 @@
|
|||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "provisions-env",
|
||||||
"type": "container",
|
"type": "file",
|
||||||
"name": "mesh-home-assistant",
|
"path": "${dir:state}/provisions.env",
|
||||||
"network": "host",
|
"mode": "0600",
|
||||||
"volumes": [
|
"content": "MESH_HOMEASSISTANT_URL=http://127.0.0.1:${port:8123}\nMESH_HOMEASSISTANT_TOKEN_FILE=${dir:mesh-state}/token\nMESH_PROVISIONS_DIR=${dir:state}\nMESH_WRITTEN_DIR=${dir:written}\n"
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/token:/run/secrets/token:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:${port:8123}",
|
|
||||||
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
|
||||||
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "provisions",
|
"id": "provisions",
|
||||||
"type": "container",
|
"type": "process",
|
||||||
"name": "mesh-home-assistant-provisions",
|
"name": "home-assistant-provisions",
|
||||||
"network": "host",
|
"artifact": "code",
|
||||||
"run-once": true,
|
"run": [
|
||||||
"volumes": [
|
"node",
|
||||||
"${dir:mesh-state}/token:/run/secrets/token:ro",
|
"provisions/index.js"
|
||||||
"${dir:written}:/var/lib/home-assistant-provisions",
|
|
||||||
"${dir:state}/mqtt-topic.json:/run/provisions/mqtt-topic.json:ro",
|
|
||||||
"${dir:state}/mqtt-topic.secret:/run/provisions/mqtt-topic.secret:ro",
|
|
||||||
"${dir:state}/sonarr-api.json:/run/provisions/sonarr-api.json:ro",
|
|
||||||
"${dir:state}/sonarr-api.secret:/run/provisions/sonarr-api.secret:ro",
|
|
||||||
"${dir:state}/radarr-api.json:/run/provisions/radarr-api.json:ro",
|
|
||||||
"${dir:state}/radarr-api.secret:/run/provisions/radarr-api.secret:ro",
|
|
||||||
"${dir:state}/lidarr-api.json:/run/provisions/lidarr-api.json:ro",
|
|
||||||
"${dir:state}/lidarr-api.secret:/run/provisions/lidarr-api.secret:ro"
|
|
||||||
],
|
],
|
||||||
"env": {
|
"run-once": true,
|
||||||
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:${port:8123}",
|
"env-file": [
|
||||||
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
"${dir:state}/provisions.env"
|
||||||
"MESH_PROVISIONS_DIR": "/run/provisions",
|
|
||||||
"MESH_WRITTEN_DIR": "/var/lib/home-assistant-provisions"
|
|
||||||
},
|
|
||||||
"args": [
|
|
||||||
"run",
|
|
||||||
"/app/modules/home-assistant/dist/provisions/index.js"
|
|
||||||
],
|
],
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
|
"provisions-env",
|
||||||
"bound-mqtt-topic",
|
"bound-mqtt-topic",
|
||||||
"secret-mqtt-topic",
|
"secret-mqtt-topic",
|
||||||
"bound-sonarr-api",
|
"bound-sonarr-api",
|
||||||
@@ -137,8 +108,7 @@
|
|||||||
"secret-radarr-api",
|
"secret-radarr-api",
|
||||||
"bound-lidarr-api",
|
"bound-lidarr-api",
|
||||||
"secret-lidarr-api"
|
"secret-lidarr-api"
|
||||||
],
|
]
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
@@ -173,23 +143,25 @@
|
|||||||
"lidarr-api": "${dir:state}/lidarr-api.secret"
|
"lidarr-api": "${dir:state}/lidarr-api.secret"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisions/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:${port:8123}",
|
||||||
|
"MESH_HOMEASSISTANT_TOKEN_FILE": "${dir:mesh-state}/token",
|
||||||
|
"MESH_HOMEASSISTANT_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,24 +0,0 @@
|
|||||||
# icecast's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/icecast
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/icecast/dist /app/modules/icecast/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/icecast/dist/index.js,/app/modules/icecast/dist/tools/index.js
|
|
||||||
+15
-37
@@ -28,9 +28,6 @@
|
|||||||
"stream.started",
|
"stream.started",
|
||||||
"stream.stopped"
|
"stream.stopped"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
"name": "stream",
|
"name": "stream",
|
||||||
@@ -95,45 +92,26 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-icecast",
|
|
||||||
"network": "icecast",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_ICECAST_URL": "http://icecast:8000",
|
|
||||||
"MESH_ICECAST_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_ICECAST_URL": "http://127.0.0.1:${port:8000}",
|
||||||
|
"MESH_ICECAST_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,24 +0,0 @@
|
|||||||
# influxdb's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/influxdb
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts grants.ts provisioner/index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/influxdb/dist /app/modules/influxdb/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/influxdb/dist/tools/index.js,/app/modules/influxdb/dist/provisioner/index.js
|
|
||||||
@@ -11,7 +11,6 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "${dir:mesh-state}/broker",
|
|
||||||
"admin": "${dir:state}/admin.secret",
|
"admin": "${dir:state}/admin.secret",
|
||||||
"admin-token": "${dir:state}/admin-token.secret"
|
"admin-token": "${dir:state}/admin-token.secret"
|
||||||
},
|
},
|
||||||
@@ -100,29 +99,6 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-influxdb",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
|
||||||
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_INFLUXDB_URL": "http://127.0.0.1:${port:8086}",
|
|
||||||
"MESH_INFLUXDB_CONFIG_FILE": "/run/config/config.json",
|
|
||||||
"MESH_INFLUXDB_TOKEN_FILE": "/run/secrets/admin-token",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
@@ -135,23 +111,25 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_INFLUXDB_URL": "http://127.0.0.1:${port:8086}",
|
||||||
|
"MESH_INFLUXDB_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
||||||
|
"MESH_INFLUXDB_TOKEN_FILE": "${dir:state}/admin-token.secret",
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
# keycloak's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/keycloak
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts oidc.ts index.ts provisioner/index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/keycloak/dist /app/modules/keycloak/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/keycloak/dist/index.js,/app/modules/keycloak/dist/tools/index.js,/app/modules/keycloak/dist/provisioner/index.js
|
|
||||||
@@ -62,8 +62,7 @@
|
|||||||
"oidc-client": "${dir:grants}"
|
"oidc-client": "${dir:grants}"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:state}/admin.secret",
|
"admin": "${dir:state}/admin.secret"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
@@ -144,49 +143,30 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-keycloak",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
|
||||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
|
||||||
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json",
|
|
||||||
"MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
||||||
|
"MESH_KEYCLOAK_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
||||||
|
"MESH_KEYCLOAK_PASSWORD_FILE": "${dir:state}/admin.secret",
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,40 +0,0 @@
|
|||||||
# minio's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
ARG MC_CLI
|
|
||||||
|
|
||||||
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
|
|
||||||
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
|
|
||||||
FROM ${MC_CLI} AS mccli
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/minio
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/minio/dist /app/modules/minio/dist
|
|
||||||
# The provisioner shells out to mc to actually create buckets and service accounts on the running
|
|
||||||
# minio server — mc itself was never in this runtime image, only in minio's own. Silently retried
|
|
||||||
# "spawn mc ENOENT" forever: a requirement was granted at the control-plane level without ever
|
|
||||||
# materializing the credential on minio. /usr/bin/mc there is a symlink to the real binary, mcli —
|
|
||||||
# both copied so the symlink resolves.
|
|
||||||
COPY --from=mccli /usr/bin/mcli /usr/bin/mcli
|
|
||||||
COPY --from=mccli /usr/bin/mc /usr/bin/mc
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js
|
|
||||||
+24
-45
@@ -59,16 +59,9 @@
|
|||||||
"s3-bucket": "${dir:grants}"
|
"s3-bucket": "${dir:grants}"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"root": "${dir:state}/root.secret",
|
"root": "${dir:state}/root.secret"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"mode": "0700",
|
|
||||||
"place": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -127,48 +120,34 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "client",
|
||||||
"type": "container",
|
"type": "package",
|
||||||
"name": "mesh-minio",
|
"package": "minio-client"
|
||||||
"network": "minio-net",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro",
|
|
||||||
"${dir:state}/root.secret:/run/secrets/root:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_MINIO_ENDPOINT": "http://minio:9000",
|
|
||||||
"MESH_MINIO_ROOT_USER": "meshroot",
|
|
||||||
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
|
||||||
"MESH_MINIO_REGION": "eu-west",
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "MC_CLI",
|
|
||||||
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_MINIO_ENDPOINT": "http://127.0.0.1:${port:9000}",
|
||||||
|
"MESH_MINIO_ROOT_USER": "meshroot",
|
||||||
|
"MESH_MINIO_ROOT_PASSWORD_FILE": "${dir:state}/root.secret",
|
||||||
|
"MESH_MINIO_REGION": "eu-west",
|
||||||
|
"MESH_MINIO_MC_BIN": "mcli",
|
||||||
|
"MESH_MINIO_MC_CONFIG": "${dir:state}/mc",
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,28 +0,0 @@
|
|||||||
# mosquitto's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/mosquitto
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc topics.ts client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
# mosquitto's client and bootstrap drive `mosquitto_ctrl`; the apt package carries it with its
|
|
||||||
# shared libraries — the musl binary from the eclipse image would not load on this glibc base.
|
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends mosquitto \
|
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
|
||||||
COPY --from=build /app/modules/mosquitto/dist /app/modules/mosquitto/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/mosquitto/dist/index.js,/app/modules/mosquitto/dist/tools/index.js,/app/modules/mosquitto/dist/provisioner/index.js
|
|
||||||
@@ -32,8 +32,7 @@
|
|||||||
"mqtt-topic": "${dir:grants}"
|
"mqtt-topic": "${dir:grants}"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:mesh-state}/admin",
|
"admin": "${dir:mesh-state}/admin"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -89,25 +88,28 @@
|
|||||||
"name": "mosquitto"
|
"name": "mosquitto"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "bootstrap",
|
"id": "bootstrap-env",
|
||||||
"type": "container",
|
"type": "file",
|
||||||
"name": "mosquitto-bootstrap",
|
"path": "${dir:state}/bootstrap.env",
|
||||||
"run-once": true,
|
"mode": "0600",
|
||||||
"volumes": [
|
"content": "MESH_PROVISION_MQTT=127.0.0.1:${port:1883}\nMESH_PROVISION_ADMIN_USER=mesh-admin\nMESH_PROVISION_PASSWORD_FILE=${dir:mesh-state}/admin\nMESH_DYNSEC_FILE=${dir:data}/dynamic-security.json\n"
|
||||||
"${dir:data}:/mosquitto/data",
|
|
||||||
"${dir:mesh-state}/admin:/run/secrets/admin:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
|
||||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin",
|
|
||||||
"MESH_DYNSEC_FILE": "/mosquitto/data/dynamic-security.json"
|
|
||||||
},
|
},
|
||||||
"args": [
|
{
|
||||||
"run",
|
"id": "bootstrap",
|
||||||
"/app/modules/mosquitto/dist/bootstrap/index.js"
|
"type": "process",
|
||||||
|
"name": "mosquitto-bootstrap",
|
||||||
|
"artifact": "code",
|
||||||
|
"run": [
|
||||||
|
"node",
|
||||||
|
"bootstrap/index.js"
|
||||||
],
|
],
|
||||||
"artifact": "runtime"
|
"run-once": true,
|
||||||
|
"env-file": [
|
||||||
|
"${dir:state}/bootstrap.env"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"bootstrap-env"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
@@ -125,43 +127,34 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "client",
|
||||||
"type": "container",
|
"type": "package",
|
||||||
"name": "mesh-mosquitto",
|
"package": "mosquitto"
|
||||||
"network": "mosquitto",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro",
|
|
||||||
"${dir:mesh-state}/admin:/run/secrets/admin:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
||||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
|
||||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js",
|
||||||
|
"bootstrap/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||||
|
"MESH_PROVISION_MQTT": "127.0.0.1:${port:1883}",
|
||||||
|
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:mesh-state}/admin"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,40 +0,0 @@
|
|||||||
# nextcloud's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
ARG DOCKER_CLI
|
|
||||||
|
|
||||||
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
|
|
||||||
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
|
|
||||||
FROM ${DOCKER_CLI} AS dockercli
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/nextcloud
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
|
|
||||||
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
|
|
||||||
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client
|
|
||||||
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
|
|
||||||
# systemd unit, no package manager tree pulled in for it).
|
|
||||||
COPY --from=dockercli /usr/local/bin/docker /usr/local/bin/docker
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/nextcloud/dist/index.js,/app/modules/nextcloud/dist/tools/index.js
|
|
||||||
@@ -30,8 +30,7 @@
|
|||||||
"share.created"
|
"share.created"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "${dir:state}/admin.secret",
|
"admin": "${dir:state}/admin.secret"
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
@@ -94,53 +93,28 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n",
|
||||||
"merge": "json"
|
"merge": "json"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-nextcloud",
|
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
|
||||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
||||||
"/var/run/docker.sock:/var/run/docker.sock"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}",
|
|
||||||
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json",
|
|
||||||
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
|
|
||||||
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "DOCKER_CLI",
|
|
||||||
"image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}",
|
||||||
|
"MESH_NEXTCLOUD_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
||||||
|
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
|
||||||
|
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,27 +0,0 @@
|
|||||||
# nodered's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
WORKDIR /app/modules/nodered
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts mqtt/probe.ts mqtt/connection.ts mqtt/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/nodered/dist /app/modules/nodered/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/nodered/dist/tools/index.js
|
|
||||||
# NOT dist/mqtt/index.js: that is a step the host runs to completion, named by the `mqtt`
|
|
||||||
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
|
||||||
# serving sidecar too, and exit it.
|
|
||||||
+31
-55
@@ -12,8 +12,7 @@
|
|||||||
"api-token": {
|
"api-token": {
|
||||||
"path": "${dir:mesh-state}/api-token",
|
"path": "${dir:mesh-state}/api-token",
|
||||||
"taken": "at-start"
|
"taken": "at-start"
|
||||||
},
|
}
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
@@ -101,53 +100,31 @@
|
|||||||
"content": "{\n \"token\": \"${secret:api-token}\"\n}\n"
|
"content": "{\n \"token\": \"${secret:api-token}\"\n}\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "mqtt-env",
|
||||||
"type": "container",
|
"type": "file",
|
||||||
"name": "mesh-nodered",
|
"path": "${dir:state}/mqtt.env",
|
||||||
"network": "host",
|
"mode": "0600",
|
||||||
"volumes": [
|
"content": "MESH_NODERED_URL=http://127.0.0.1:${port:1880}\nMESH_NODERED_CONFIG_FILE=${dir:mesh-state}/config.json\nMESH_PROVISIONS_DIR=${dir:state}\nMESH_WRITTEN_DIR=${dir:written}\n"
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_NODERED_URL": "http://127.0.0.1:${port:1880}",
|
|
||||||
"MESH_NODERED_CONFIG_FILE": "/run/config/config.json"
|
|
||||||
},
|
|
||||||
"restart-on": [
|
|
||||||
"runtime-config"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "mqtt",
|
"id": "mqtt",
|
||||||
"type": "container",
|
"type": "process",
|
||||||
"name": "mesh-nodered-mqtt",
|
"name": "nodered-mqtt",
|
||||||
"network": "host",
|
"artifact": "code",
|
||||||
"run-once": true,
|
"run": [
|
||||||
"volumes": [
|
"node",
|
||||||
"${dir:mesh-state}/config.json:/run/config/config.json:ro",
|
"mqtt/index.js"
|
||||||
"${dir:written}:/var/lib/nodered-provisions",
|
|
||||||
"${dir:state}/mqtt-topic.json:/run/provisions/mqtt-topic.json:ro",
|
|
||||||
"${dir:state}/mqtt-topic.secret:/run/provisions/mqtt-topic.secret:ro",
|
|
||||||
"${dir:state}/settings.json:/run/provisions/settings.json:ro"
|
|
||||||
],
|
],
|
||||||
"env": {
|
"run-once": true,
|
||||||
"MESH_NODERED_URL": "http://127.0.0.1:${port:1880}",
|
"env-file": [
|
||||||
"MESH_NODERED_CONFIG_FILE": "/run/config/config.json",
|
"${dir:state}/mqtt.env"
|
||||||
"MESH_PROVISIONS_DIR": "/run/provisions",
|
|
||||||
"MESH_WRITTEN_DIR": "/var/lib/nodered-provisions"
|
|
||||||
},
|
|
||||||
"args": [
|
|
||||||
"run",
|
|
||||||
"/app/modules/nodered/dist/mqtt/index.js"
|
|
||||||
],
|
],
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
|
"mqtt-env",
|
||||||
"bound-mqtt-topic",
|
"bound-mqtt-topic",
|
||||||
"secret-mqtt-topic",
|
"secret-mqtt-topic",
|
||||||
"settings"
|
"settings"
|
||||||
],
|
]
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
@@ -173,23 +150,22 @@
|
|||||||
"mqtt-topic": "${dir:state}/mqtt-topic.secret"
|
"mqtt-topic": "${dir:state}/mqtt-topic.secret"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"tools/index.js",
|
||||||
|
"mqtt/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"tools/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_NODERED_URL": "http://127.0.0.1:${port:1880}",
|
||||||
|
"MESH_NODERED_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,41 +0,0 @@
|
|||||||
# postgres's runtime: the tool runtime, carrying this module's compiled provisioner, tools and
|
|
||||||
# event consumer.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk is in the base image, so
|
|
||||||
# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a
|
|
||||||
# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have
|
|
||||||
# the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned: the image this is COMPILED in, and the image it RUNS in.
|
|
||||||
# They are different images on purpose — the first carries a compiler and the second must not, or
|
|
||||||
# every running container would carry one it never invokes. The mesh answers both with the copies it
|
|
||||||
# holds, because a fingerprint written here would name one particular copy and no other mesh has it
|
|
||||||
# (novox/hq issue 044). Declared in module.json's `build.on`; deliberately no defaults, so a build
|
|
||||||
# nobody told stops here and says which module to build first.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against.
|
|
||||||
WORKDIR /app/modules/postgres
|
|
||||||
COPY . .
|
|
||||||
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
|
||||||
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
|
||||||
# was assembled.
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
# **This module talks to its database through psql, so psql has to be here.** The client is how
|
|
||||||
# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only
|
|
||||||
# what every module needs.
|
|
||||||
RUN apt-get update \
|
|
||||||
&& apt-get install -y --no-install-recommends postgresql-client \
|
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
|
||||||
COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist
|
|
||||||
# What a tool host should load from this module: its event consumer and its tools, which are
|
|
||||||
# separate entrypoints because they are loaded by different things. The provisioner is the third,
|
|
||||||
# and is not listed here — the declaration names it in the container's `args`, because it is what
|
|
||||||
# this module's own container runs. One image, because they are one module and share a client.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js,/app/modules/postgres/dist/tools/index.js,/app/modules/postgres/dist/provisioner/index.js
|
|
||||||
@@ -53,16 +53,9 @@
|
|||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"superuser": "${dir:state}/superuser.secret",
|
"superuser": "${dir:state}/superuser.secret",
|
||||||
"broker": "${dir:mesh-state}/broker",
|
|
||||||
"reader": "${dir:state}/reader.secret"
|
"reader": "${dir:state}/reader.secret"
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"mode": "0700",
|
|
||||||
"place": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -99,45 +92,33 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "client",
|
||||||
"type": "container",
|
"type": "package",
|
||||||
"name": "mesh-postgres",
|
"package": "postgresql-libs"
|
||||||
"network": "host",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:${dir:grants}:ro",
|
|
||||||
"${dir:state}/superuser.secret:/run/secrets/superuser:ro",
|
|
||||||
"${dir:state}/reader.secret:/run/secrets/reader:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
|
|
||||||
"MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
||||||
"MESH_POSTGRES_READER_PASSWORD_FILE": "/run/secrets/reader"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/superuser.secret",
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||||
|
"MESH_POSTGRES_READER_PASSWORD_FILE": "${dir:state}/reader.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
# redis's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/redis
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts provisioner/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/redis/dist /app/modules/redis/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/redis/dist/index.js,/app/modules/redis/dist/tools/index.js,/app/modules/redis/dist/provisioner/index.js
|
|
||||||
+18
-42
@@ -35,9 +35,6 @@
|
|||||||
"secrets": {
|
"secrets": {
|
||||||
"secret": "${dir:state}/default.secret"
|
"secret": "${dir:state}/default.secret"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
"name": "cache",
|
"name": "cache",
|
||||||
@@ -48,12 +45,6 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"mode": "0700",
|
|
||||||
"place": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -103,44 +94,29 @@
|
|||||||
"restart-on": [
|
"restart-on": [
|
||||||
"server-conf"
|
"server-conf"
|
||||||
]
|
]
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-redis",
|
|
||||||
"network": "redis",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:/var/lib/redis-module/grants:ro",
|
|
||||||
"${dir:state}/default.secret:/run/secrets/default:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "/var/lib/redis-module/grants/mesh.json",
|
|
||||||
"MESH_PROVISION_REDIS": "redis:6379",
|
|
||||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
|
|
||||||
},
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"index.js",
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||||
|
"MESH_PROVISION_REDIS": "127.0.0.1:${port:6379}",
|
||||||
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/default.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
# umami's runtime: the tool runtime, carrying this module's compiled code.
|
|
||||||
#
|
|
||||||
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
||||||
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
||||||
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
||||||
# happens to have the siblings.
|
|
||||||
#
|
|
||||||
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
||||||
ARG BUILD_BASE
|
|
||||||
ARG RUNTIME_BASE
|
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
||||||
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
||||||
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
||||||
# resolved away.
|
|
||||||
WORKDIR /app/modules/umami
|
|
||||||
COPY . .
|
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \
|
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
|
||||||
COPY --from=build /app/modules/umami/dist /app/modules/umami/dist
|
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
||||||
# the convention novox/hq issues 060/061 settled. A container that instead ran only its
|
|
||||||
# provisioner (`run`) served no tools and emitted no events; a container that named no command
|
|
||||||
# ran no provisioner at all.
|
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/umami/dist/tools/index.js,/app/modules/umami/dist/provisioner/index.js
|
|
||||||
+16
-51
@@ -44,9 +44,6 @@
|
|||||||
"grants": {
|
"grants": {
|
||||||
"analytics": "${dir:grants}"
|
"analytics": "${dir:grants}"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
|
||||||
"broker": "${dir:mesh-state}/broker"
|
|
||||||
},
|
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
"name": "web",
|
"name": "web",
|
||||||
@@ -57,12 +54,6 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
|
||||||
"id": "mesh-state",
|
|
||||||
"type": "directory",
|
|
||||||
"mode": "0700",
|
|
||||||
"place": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
@@ -81,13 +72,6 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
|
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "provisioner-env",
|
|
||||||
"type": "file",
|
|
||||||
"path": "${dir:state}/provisioner.env",
|
|
||||||
"mode": "0600",
|
|
||||||
"content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=${dir:grants}\n"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "net",
|
"id": "net",
|
||||||
"type": "network",
|
"type": "network",
|
||||||
@@ -106,46 +90,27 @@
|
|||||||
"3000"
|
"3000"
|
||||||
],
|
],
|
||||||
"secrets-in-environment": "a Next.js/Prisma application: DATABASE_URL and APP_SECRET are read from the environment only; not convertible"
|
"secrets-in-environment": "a Next.js/Prisma application: DATABASE_URL and APP_SECRET are read from the environment only; not convertible"
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "runtime",
|
|
||||||
"type": "container",
|
|
||||||
"name": "mesh-umami",
|
|
||||||
"network": "umami",
|
|
||||||
"volumes": [
|
|
||||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
||||||
"${dir:grants}:${dir:grants}",
|
|
||||||
"${dir:state}/admin.secret:/run/secrets/admin:ro"
|
|
||||||
],
|
|
||||||
"env": {
|
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
||||||
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
|
||||||
},
|
|
||||||
"env-file": [
|
|
||||||
"${dir:state}/provisioner.env"
|
|
||||||
],
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
|
||||||
{
|
|
||||||
"arg": "BUILD_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "build"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"arg": "RUNTIME_BASE",
|
|
||||||
"module": "mesh-tools",
|
|
||||||
"artifact": "runtime"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
{
|
{
|
||||||
"name": "runtime",
|
"name": "code",
|
||||||
"kind": "image",
|
"kind": "bundle",
|
||||||
"from": "Dockerfile"
|
"language": "typescript",
|
||||||
|
"entrypoints": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"loads": [
|
||||||
|
"tools/index.js",
|
||||||
|
"provisioner/index.js"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||||
|
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret",
|
||||||
|
"MESH_PROVISION_UMAMI_URL": "http://127.0.0.1:${port:3000}"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user