# mesh-vault's runtime: the tool runtime, carrying this module's compiled provisioner, tools and event # consumer. The same shape as postgres's, minus the client the database needs: mesh-vault reaches no # server, because what it provides is a value the mesh already delivered to its node. # # **Built from this module's own directory and nothing else.** The sdk is in the base image, so # nothing is copied out of a neighbouring checkout (novox/hq ADR 0069). Two bases, named rather than # pinned — the image this is COMPILED in and the image it RUNS in — answered by the mesh from # `build.on` in module.json (novox/hq issue 044). ARG BUILD_BASE ARG RUNTIME_BASE FROM ${BUILD_BASE} AS build WORKDIR /app/modules/vault COPY . . RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \ --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist FROM ${RUNTIME_BASE} COPY --from=build /app/modules/vault/dist /app/modules/vault/dist # The entrypoints a tool host loads from this module: its event consumer, its tools and its # provisioner — one image, one process, one broker account (novox/hq ADR 0052). ENV MESH_TOOL_MODULES=/app/modules/vault/dist/index.js,/app/modules/vault/dist/tools/index.js,/app/modules/vault/dist/provisioner/index.js