First batch of the hal→nox module conversion, each mirroring a proven catalog pattern and typechecking (strict, NodeNext) against the built @novox/mesh-sdk.
Module
Pattern
Provider
Image (digest-pinned)
lidarr
radarr/sonarr twin (Servarr API v1)
— (consumer app)
linuxserver/lidarr
mongodb
postgres shape
mongodb-database
mongo:6.0.6
mssql
postgres shape
mssql-database
mssql/server:2022-latest
mosquitto
redis shape
mqtt-topic
eclipse-mosquitto:2
Each backend module ships a provisioner/ that mints a per-consumer credential (ADR 0053); the clients shell out to the backend CLI (mongosh/sqlcmd/mosquitto_ctrl), taking no npm dependency beyond the SDK — the same convention as postgres driving psql.
Notable: mosquitto deliberately avoids hal's password_file model because that file isnox issue 011 — a host-reconciled seed file wiped every heartbeat. It uses the Dynamic Security plugin instead.
Verified: all four compile; service images pinned to resolved registry digests.
Not yet verified (documented in-code, per module):
The mesh-runtime-<mod> images must bundle each CLI (mongosh/sqlcmd/mosquitto_ctrl), as mesh-runtime-postgres bundles psql. Those runtime images are the pipeline's to build.
Lab integration tests still owed: auth model, provisioner reconcile round-trip, and mosquitto's dynsec bootstrap-ordering gap (the resource model has no run-once primitive to seed the admin client before broker start).
Remaining after this batch: ~14 service conversions (baserow, bookshelf, invoicing, letta, marrytts, matrix, only-office, penpot, supabase, unifi, n8n, kometa, + tools-only integrations) and 4 architecture decisions (certbot, fail2ban, wireguard, mediahuis).
First batch of the hal→nox module conversion, each mirroring a proven catalog pattern and **typechecking (strict, NodeNext) against the built `@novox/mesh-sdk`**.
| Module | Pattern | Provider | Image (digest-pinned) |
|---|---|---|---|
| **lidarr** | radarr/sonarr twin (Servarr API v1) | — (consumer app) | linuxserver/lidarr |
| **mongodb** | postgres shape | `mongodb-database` | mongo:6.0.6 |
| **mssql** | postgres shape | `mssql-database` | mssql/server:2022-latest |
| **mosquitto** | redis shape | `mqtt-topic` | eclipse-mosquitto:2 |
Each backend module ships a `provisioner/` that mints a per-consumer credential (ADR 0053); the clients shell out to the backend CLI (`mongosh`/`sqlcmd`/`mosquitto_ctrl`), taking **no npm dependency beyond the SDK** — the same convention as postgres driving `psql`.
**Notable:** mosquitto deliberately avoids hal's `password_file` model because that file *is* [nox issue 011](https://git.novox.be/novox/hq/src/branch/main/04-ISSUES/011-reconciling-a-seed-file-wipes-what-grew-in-it) — a host-reconciled seed file wiped every heartbeat. It uses the Dynamic Security plugin instead.
**Verified:** all four compile; service images pinned to resolved registry digests.
**Not yet verified (documented in-code, per module):**
- The `mesh-runtime-<mod>` images must bundle each CLI (`mongosh`/`sqlcmd`/`mosquitto_ctrl`), as `mesh-runtime-postgres` bundles `psql`. Those runtime images are the pipeline's to build.
- Lab integration tests still owed: auth model, provisioner reconcile round-trip, and mosquitto's dynsec **bootstrap-ordering** gap (the resource model has no run-once primitive to seed the admin client before broker start).
**Remaining after this batch:** ~14 service conversions (baserow, bookshelf, invoicing, letta, marrytts, matrix, only-office, penpot, supabase, unifi, n8n, kometa, + tools-only integrations) and **4 architecture decisions** (certbot, fail2ban, wireguard, mediahuis).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Mirrors the proven catalog patterns field-for-field:
- lidarr -> the Servarr twin of radarr/sonarr (API v1, artist content); no
provisioner (it is a consumer app).
- mongodb -> postgres shape: mongodb-database provider, provisioner mints a
per-consumer db+user (ADR 0053), client shells to mongosh (no npm driver,
the psql convention).
- mssql -> postgres shape: mssql-database provider, sqlcmd client.
- mosquitto -> redis shape: mqtt-topic provider via the Dynamic Security
plugin, deliberately avoiding hal's password_file (that file is nox issue
011 exactly); provisioner mints a per-consumer MQTT client+role.
All four typecheck (strict, NodeNext) against the built @novox/mesh-sdk, and
their service images are digest-pinned to resolved registry digests. The
mesh-runtime-<mod> images keep the all-zeros placeholder the pipeline pins,
as postgres/redis do, and must bundle each module's CLI (mongosh/sqlcmd/
mosquitto_ctrl) as mesh-runtime-postgres bundles psql.
Not yet lab-verified: each module lists in-code what an integration test must
prove (auth model, provisioner reconcile, mosquitto dynsec bootstrap ordering).
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
First batch of the hal→nox module conversion, each mirroring a proven catalog pattern and typechecking (strict, NodeNext) against the built
@novox/mesh-sdk.mongodb-databasemssql-databasemqtt-topicEach backend module ships a
provisioner/that mints a per-consumer credential (ADR 0053); the clients shell out to the backend CLI (mongosh/sqlcmd/mosquitto_ctrl), taking no npm dependency beyond the SDK — the same convention as postgres drivingpsql.Notable: mosquitto deliberately avoids hal's
password_filemodel because that file is nox issue 011 — a host-reconciled seed file wiped every heartbeat. It uses the Dynamic Security plugin instead.Verified: all four compile; service images pinned to resolved registry digests.
Not yet verified (documented in-code, per module):
mesh-runtime-<mod>images must bundle each CLI (mongosh/sqlcmd/mosquitto_ctrl), asmesh-runtime-postgresbundlespsql. Those runtime images are the pipeline's to build.Remaining after this batch: ~14 service conversions (baserow, bookshelf, invoicing, letta, marrytts, matrix, only-office, penpot, supabase, unifi, n8n, kometa, + tools-only integrations) and 4 architecture decisions (certbot, fail2ban, wireguard, mediahuis).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF