The mesh builds its own catalogue (issue 060) #27

Merged
jschoubben merged 4 commits from feat/the-mesh-builds-its-catalogue into main 2026-09-20 10:53:04 +00:00
Owner

44 of 70 modules now carry a build section and Dockerfile (was 8), each building from its own directory against the sdk and tool runtime the base images carry. The runtime image names every serve-time entrypoint (tools, events, and a provider's provisioner in one process — the convention hq issue 061 settled); postgres, gitea and lavinmq are retrofitted to it from running their provisioner as a separate args command.

Proven: redis, keycloak, mongodb, mosquitto and openai-consumer build through the mesh's own builder from their own directory; the built-store-cross-node bed builds and runs the retrofitted lavinmq and postgres. All 70 manifests parse.

Deferred, each recorded: model-usage, anthropic-manager and minio need an artifact the mesh build environment cannot fetch (npm packages, a vendor binary) — hq issue 064; route-proxy's build context is another repository. The upstream-image-only modules and the foundation trio are exempt (no code to build, or built by the foundation's own path).

Resolves hq issue 060.

44 of 70 modules now carry a `build` section and Dockerfile (was 8), each building from its own directory against the sdk and tool runtime the base images carry. The runtime image names every serve-time entrypoint (tools, events, and a provider's provisioner in one process — the convention hq issue 061 settled); postgres, gitea and lavinmq are retrofitted to it from running their provisioner as a separate `args` command. Proven: redis, keycloak, mongodb, mosquitto and openai-consumer build through the mesh's own builder from their own directory; the built-store-cross-node bed builds and runs the retrofitted lavinmq and postgres. All 70 manifests parse. Deferred, each recorded: model-usage, anthropic-manager and minio need an artifact the mesh build environment cannot fetch (npm packages, a vendor binary) — hq issue 064; route-proxy's build context is another repository. The upstream-image-only modules and the foundation trio are exempt (no code to build, or built by the foundation's own path). Resolves hq issue 060.
jschoubben added 4 commits 2026-09-18 00:53:26 +00:00
keycloak, mailu, minio, mongodb, mssql, nextcloud, portainer, redis,
umami and verdaccio get the Dockerfile + build section the eight
buildable modules already had; their runtime containers name the
artifact instead of a placeholder digest.

One convention, settled (060's open question, informed by 061): the
runtime container runs serve mode with every serve-time entrypoint in
MESH_TOOL_MODULES — tools serve, events flow, and a provider's
provisioner reconciles in the same process with the broker connected.
postgres, gitea and lavinmq are retrofitted from args-run provisioners,
which served no tools and emitted lifecycle events nowhere.

route-proxy is deferred: its build context is the mesh-controller
repository, a cross-repo shape the build section cannot yet express.
The 21 media/home modules, the SaaS tool modules (cloudflare-dns,
confluence, gitlab, jira), model-usage, and the model-access trio get
the same Dockerfile + build section as batch 1. Scheduled-only modules
(anthropic-consumer, anthropic-manager, openai-consumer) deliberately
declare no MESH_TOOL_MODULES — every container of theirs names its
command. mosquitto's run-once bootstrap container builds from the same
artifact. Modules with third-party deps (model-usage: pg;
anthropic-manager: tweetnacl) install them beside their compiled code.

Also fixes cloudflare-dns's package.json, unparseable since its
description lost a closing quote.

Deliberately still without build sections: builder and mesh-controller
(the foundation builds them by its own path), distribution (provides
the artifact store — building it through itself is refused by design),
route-proxy (cross-repo build context, deferred), and the
upstream-image-only modules, which have no code to build.
Both carry third-party runtime deps (pg; tweetnacl + sealedbox) that
their Dockerfile installs with npm — which 404s in a mesh build, whose
npm points at the mesh's own registry, not public npm. The workstation
build script got away with it by installing on a host with public npm.
Delivering a module's third-party deps into a mesh build is an open
question (how: publish to the mesh registry, or proxy); until it is
answered these two stay on the placeholder path they were already on.
The other 37 modules build from their own directory with no external
fetch.
minio's runtime copies the `mc` client from minio/mc:latest — a
Docker Hub pull the mesh build environment cannot make (its docker
reaches the mesh registry, not public Hub), the same isolation that
blocks npm deps. apt-based installs (mongodb's mongosh, mosquitto)
build fine because the build has real internet for apt; only npm and
Docker Hub are redirected. Delivering an external binary or image layer
into a mesh build is the same open question as the npm deps — deferred
with them.
jschoubben merged commit 43c9c973e2 into main 2026-09-20 10:53:04 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#27