{ "module": "mongodb", "version": "1", "upgrade": { "policy": "record", "why": "a provider whose restart drops every consumer on its machine, and which holds the photos' albums (irreplaceable, kept by photos): a person takes each build, after a backup (hq ADR 0236)" }, "provides": [ { "name": "mongodb-database", "scope": "mesh", "identity": { "max": 63, "in": "a MongoDB database name" } } ], "capabilities": [ "container-runtime" ], "emits": [ "database.provisioned", "database.deprovisioned" ], "consumes": [ "mongodb.database.provisioned", "mongodb.database.deprovisioned" ], "listens": [ { "name": "database", "port": 27017, "protocol": "tcp", "from": "mesh", "why": "modules on any machine that were granted a database" } ], "serves": { "mongodb-database": { "port": 27017 } }, "receives": { "mongodb-database": "${dir:grants}/mesh.json" }, "grants": { "mongodb-database": "${dir:grants}" }, "own-secrets": { "root": "${dir:state}/root.secret" }, "data": { "own": [ { "id": "data", "path": "${dir:data}", "class": "valuable", "backup": { "dump": "docker exec mongodb-server sh -c 'printf \"password: %s\\n\" \"$(cat /run/secrets/root)\" > /tmp/.backup.yaml && mongodump --quiet --config /tmp/.backup.yaml --username root --authenticationDatabase admin --archive; s=$?; rm -f /tmp/.backup.yaml; exit $s' > ${dir:dumps}/all.archive.partial && mv ${dir:dumps}/all.archive.partial ${dir:dumps}/all.archive", "into": "dumps" }, "why": "every consumer's database; copied by the dump, not as live files" }, { "id": "dumps", "path": "${dir:dumps}", "class": "rebuildable", "why": "last night's dump, made again every night" } ], "consumers": { "mongodb-database": { "class": "valuable", "in": "data", "why": "a consumer's documents are the only copy of what it wrote; a consumer that keeps something irreplaceable here says so (kept-by)" } } }, "resources": [ { "id": "state", "type": "directory", "mode": "0700", "place": "." }, { "id": "grants", "type": "directory", "mode": "0700" }, { "id": "data", "type": "directory", "mode": "0700" }, { "id": "dumps", "type": "directory", "mode": "0700" }, { "id": "net", "type": "network", "name": "mongodb" }, { "id": "server-root", "type": "file", "path": "${dir:state}/server-root.secret", "mode": "0400", "owner": "999:999", "content": "${secret:root}" }, { "id": "server", "type": "container", "name": "mongodb-server", "image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3", "health": { "kind": "tcp", "endpoint": "database" }, "network": "mongodb", "env": { "MONGO_INITDB_ROOT_USERNAME": "root", "MONGO_INITDB_ROOT_PASSWORD_FILE": "/run/secrets/root" }, "ports": [ "27017" ], "volumes": [ "${dir:data}:/data/db", "${dir:state}/server-root.secret:/run/secrets/root:ro" ] } ], "build": { "artifacts": [ { "name": "code", "kind": "bundle", "language": "typescript", "entrypoints": [ "index.js", "tools/index.js", "provisioner/index.js" ], "loads": [ "index.js", "tools/index.js", "provisioner/index.js" ], "env": { "MESH_PROVISION_MONGODB": "mongodb://root@127.0.0.1:${port:27017}/admin?authSource=admin", "MESH_PROVISION_PASSWORD_FILE": "${dir:state}/root.secret", "MESH_RECEIVES": "${dir:grants}/mesh.json" } } ] } }