# nextcloud's runtime: the tool runtime, carrying this module's compiled code. # # **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in # the base images, published like any other artifact — which is what makes this buildable by the # mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that # happens to have the siblings. # # Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the # image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. ARG BUILD_BASE ARG RUNTIME_BASE ARG DOCKER_CLI FROM ${BUILD_BASE} AS build # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own # node_modules — the module is compiled against exactly the sdk it will run against. The compiler # is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image # resolved away. WORKDIR /app/modules/nextcloud COPY . . RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist FROM ${RUNTIME_BASE} # ARGs declared before the first FROM are out of scope past it; redeclared here so COPY --from # below can see it. ARG DOCKER_CLI COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist # occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs # the docker CLI itself present here, not only the socket. Copied from Docker's own official client # image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no # systemd unit, no package manager tree pulled in for it). COPY --from=${DOCKER_CLI} /usr/local/bin/docker /usr/local/bin/docker # Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a # provider's provisioner runs its reconcile loop in the same process, with the broker connected — # the convention novox/hq issues 060/061 settled. A container that instead ran only its # provisioner (`run`) served no tools and emitted no events; a container that named no command # ran no provisioner at all. ENV MESH_TOOL_MODULES=/app/modules/nextcloud/dist/index.js,/app/modules/nextcloud/dist/tools/index.js