{ "module": "network-checker", "version": "1", "slug": "netcheck", "listens": [ { "name": "probe", "port": 9876, "protocol": "tcp", "from": "mesh", "why": "what the other machines' checkers dial. Deliberately this module's own endpoint and nothing else's: it is admitted by exactly the rule that governs every internally-exposed service, so it fails when that rule is wrong. A probe on a port that is never closed — ssh, say — would have passed throughout the outage this module exists to catch (novox/hq ADR 0145)" } ], "facts": { "roster": { "path": "/var/lib/network-checker/roster.json", "template": "{\n \"generated\": \"by the mesh — do not edit; replaced whenever a machine joins or leaves\",\n \"node\": \"{{.Node}}\",\n \"machines\": [{{range $i, $m := .Machines}}{{if $i}},{{end}}\n { \"name\": \"{{$m.Name}}\", \"fqdn\": \"{{$m.FQDN}}\", \"address\": \"{{$m.Address}}\" }{{end}}\n ]\n}\n" } }, "build": { "artifacts": [ { "name": "code", "kind": "bundle", "language": "typescript", "entrypoints": ["probe/index.js", "check/index.js"] } ] }, "resources": [ { "id": "state", "type": "directory", "path": "/var/lib/network-checker", "mode": "0700" }, { "id": "probe", "type": "container", "name": "mesh-network-checker-probe", "args": ["run", "/app/modules/network-checker/dist/probe/index.js"], "ports": ["9876"], "state": "running", "env": { "MESH_NETWORK_CHECKER_PORT": "9876" } }, { "id": "check", "type": "container", "name": "mesh-network-checker-check", "network": "host", "schedule": "*/5 * * * *", "args": ["run", "/app/modules/network-checker/dist/check/index.js"], "volumes": ["/var/lib/network-checker:/run/state"], "env": { "MESH_NETWORK_CHECKER_ROSTER": "/run/state/roster.json", "MESH_NETWORK_CHECKER_STATE": "/run/state", "MESH_NETWORK_CHECKER_PORT": "${port:9876}" } } ] }