From 755b0a559964526aabe8a911cf70c7dea9b3b88f Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 17:08:12 +0200 Subject: [PATCH 1/2] builder: consume package-registry as a real mesh grant, not a hand-faked one MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The 'package-binding' resource was a hardcoded JSON fragment standing in for a real grant — {"provision": "package-registry", "from": "gitea", "at": "127.0.0.1", ...} written as if it were mesh-resolved, when nothing resolved it. Declares requires: package-registry properly instead, with binds/secrets pointing at the same file paths the resource used to manually author, so the mesh mints the grant and writes it there. npm-password renamed to package-registry.secret: it's gitea's generic user+password, not npm-specific — the same credential works for basic auth against cargo/PyPI/Go package endpoints too, once gitea's manifest grows them (novox/hq ADR 0109). Known gap, not fixed here (novox/hq issue 117): this makes builder correct for the steady state but breaks a genesis bootstrap — gitea's own image is built by builder, so builder cannot yet hold this grant the first time either has to exist. Filed rather than silently accepted. --- modules/builder/module.json | 34 ++++++++++++---------------------- 1 file changed, 12 insertions(+), 22 deletions(-) diff --git a/modules/builder/module.json b/modules/builder/module.json index 6d02dfd..8e32ccc 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -11,14 +11,20 @@ } ], "requires": [ - "artifact-store" + "artifact-store", + "package-registry" ], + "binds": { + "package-registry": "/var/lib/mesh/builder/package-registry.json" + }, + "secrets": { + "package-registry": "/var/lib/mesh/builder/package-registry.secret" + }, "emits": [ "module.builder.built" ], "own-secrets": { - "broker": "/var/lib/mesh/builder/broker", - "npm-password": "/var/lib/mesh/builder/npm-password" + "broker": "/var/lib/mesh/builder/broker" }, "resources": [ { @@ -38,27 +44,13 @@ "type": "file", "path": "/var/lib/mesh/builder/builder.env", "mode": "0600", - "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/npm-password\nMESH_WORKSPACE=/var/lib/builder/workspace\n" - }, - { - "id": "package-binding", - "type": "file", - "path": "/var/lib/mesh/builder/package-registry.json", - "mode": "0600", - "merge": "json", - "protected": [ - "provision", - "from", - "at", - "as" - ], - "content": "{\"provision\": \"package-registry\", \"from\": \"gitea\", \"at\": \"127.0.0.1\", \"as\": \"mesh-builder\", \"serves\": {\"scheme\": \"http\", \"port\": 3000, \"npm-path\": \"/api/packages/novox/npm/\"}}\n" + "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n" }, { "id": "server", "type": "container", "name": "mesh-builder", - "image": "mesh-builder@sha256:0000000000000000000000000000000000000000000000000000000000000000", + "image": "mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704", "env-file": [ "/var/lib/mesh/builder/builder.env" ], @@ -68,9 +60,7 @@ "/var/run/docker.sock:/var/run/docker.sock" ], "restart-on": [ - "builder-env", - "package-binding", - "needs-npm-password" + "builder-env" ], "network": "host" } -- 2.54.0 From 1b02dc1f66cc06f5b797d0e69c4818c361adbbe9 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 17:10:56 +0200 Subject: [PATCH 2/2] builder: qualify its own image with the registry host MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bare mesh-builder@sha256:... is only resolvable for a module with a build section — the mesh's own build step rewrites the reference to a real registry path as part of resolving build.artifacts. builder is handed over, not built, so nothing ever rewrites it: pushed as written, docker read it literally and tried Docker Hub. Took the live node's mesh-builder down for the length of one push-and-fix (docker: pull access denied for mesh-builder, repository does not exist). novox.internal:5100, not the literal external IP docker inspect showed live, for the same reason addresses generally don't get hardcoded in this catalogue. --- modules/builder/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/builder/module.json b/modules/builder/module.json index 8e32ccc..229ca97 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -50,7 +50,7 @@ "id": "server", "type": "container", "name": "mesh-builder", - "image": "mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704", + "image": "novox.internal:5100/mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704", "env-file": [ "/var/lib/mesh/builder/builder.env" ], -- 2.54.0