From 2dab3069d2842800eabfaebba4b7786eba055de4 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 23:05:25 +0200 Subject: [PATCH 1/2] The builder names the registry by the binding again (ADR 0082) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The one-line change e0c9219 parked "until there is a certificate" returns — with the overlay recorded as the registry's transport security and every node's runtime told the store speaks plain HTTP, a reference under the provider's internal name is one every machine can pull. References minted at genesis stay loopback and are valid where they matter, on the machine that made them. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- modules/builder/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/builder/module.json b/modules/builder/module.json index fb2c6f5..18e8347 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -38,7 +38,7 @@ "type": "file", "path": "/var/lib/mesh/builder/builder.env", "mode": "0600", - "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=127.0.0.1:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n" + "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n" }, { "id": "package-binding", -- 2.54.0 From 1891b09c65834e83645f6d5706126f9668c38bed Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 23:54:56 +0200 Subject: [PATCH 2/2] lavinmq's runtime container runs its provisioner MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The runtime container named no command, so it ran the image default — the tool host — and the provisioner entrypoint compiled beside it never ran anywhere: no vhost was ever minted, while the grants sat applied in its mounted directory. postgres already names its provisioner in args; lavinmq now does the same. Surfaced by the built-store-cross-node bed, run 9 — the first bed to reach the vhost assertion honestly. --- modules/lavinmq/module.json | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/modules/lavinmq/module.json b/modules/lavinmq/module.json index a2afd95..2a4b36e 100644 --- a/modules/lavinmq/module.json +++ b/modules/lavinmq/module.json @@ -107,7 +107,11 @@ "MESH_PROVISION_LAVINMQ": "http://127.0.0.1:15672", "MESH_PROVISION_ADMIN_USER": "guest", "MESH_LAVINMQ_ADMIN_PASSWORD": "guest" - } + }, + "args": [ + "run", + "/app/modules/lavinmq/dist/provisioner/index.js" + ] } ], "build": { -- 2.54.0