{ "module": "route-proxy", "version": "1", "slug": "rproxy", "capabilities": [ "container-runtime" ], "provides": [ { "name": "route", "scope": "mesh" } ], "serves": { "route": {} }, "receives": { "route": "/var/lib/route-proxy/routes/mesh.json" }, "requires": [ "acme-ca", "internal-acme-ca" ], "binds": { "acme-ca": "/var/lib/route-proxy/acme-ca.json", "internal-acme-ca": "/var/lib/route-proxy/internal-acme-ca.json" }, "listens": [ { "port": 80, "protocol": "tcp", "from": "anywhere", "why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified" }, { "port": 443, "protocol": "tcp", "from": "anywhere", "why": "public HTTPS for every name the mesh routes here" } ], "resources": [ { "id": "state", "type": "directory", "path": "/var/lib/route-proxy", "mode": "0700" }, { "id": "routes-dir", "type": "directory", "path": "/var/lib/route-proxy/routes", "mode": "0700" }, { "id": "acme-cache", "type": "directory", "path": "/var/lib/route-proxy/acme", "mode": "0700" }, { "id": "ca-dir", "type": "directory", "path": "/var/lib/route-proxy/ca", "mode": "0755" }, { "id": "acme-env", "type": "file", "path": "/var/lib/route-proxy/acme.env", "mode": "0600", "content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n" }, { "id": "internal-acme-env", "type": "file", "path": "/var/lib/route-proxy/internal-acme.env", "mode": "0600", "content": "INTERNAL_ACME_DIRECTORY=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:path}\nINTERNAL_ACME_ROOTS=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}\nINTERNAL_ACME_ROOTS_PATH=${bound:internal-acme-ca:roots}\n" }, { "id": "trust", "type": "container", "name": "route-proxy-trust", "artifact": "trust", "run-once": true, "network": "host", "env-file": [ "/var/lib/route-proxy/acme.env" ], "volumes": [ "/var/lib/route-proxy/ca:/ca" ], "args": [ "sh", "-c", "if [ -z \"$ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1" ], "restart-on": [ "acme-env" ] }, { "id": "internal-trust", "type": "container", "name": "route-proxy-internal-trust", "artifact": "trust", "run-once": true, "network": "host", "env-file": [ "/var/lib/route-proxy/internal-acme.env" ], "volumes": [ "/var/lib/route-proxy/ca:/ca" ], "args": [ "sh", "-c", "if [ -z \"$INTERNAL_ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/internal-root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/internal-root.crt \"$INTERNAL_ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/internal-root.crt && exit 0; sleep 2; done; echo \"the authority at $INTERNAL_ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1" ], "restart-on": [ "internal-acme-env" ] }, { "id": "server", "type": "container", "name": "route-proxy", "artifact": "server", "network": "host", "env-file": [ "/var/lib/route-proxy/acme.env", "/var/lib/route-proxy/internal-acme.env" ], "volumes": [ "/var/lib/route-proxy/routes:/routes:ro", "/var/lib/route-proxy/acme:/acme", "/var/lib/route-proxy/ca:/ca:ro" ], "env": { "ROUTES": "/routes/mesh.json", "LISTEN": ":80", "TLS_LISTEN": ":443", "ACME_CACHE": "/acme", "ACME_CA_BUNDLE": "/ca/root.crt", "INTERNAL_ACME_CA_BUNDLE": "/ca/internal-root.crt" }, "restart-on": [ "trust", "acme-env", "internal-trust", "internal-acme-env" ] } ], "build": { "artifacts": [ { "name": "server", "kind": "image", "from": "Dockerfile", "context": { "repository": "https://git.novox.be/novox/mesh-controller.git", "ref": "main" } }, { "name": "trust", "kind": "upstream", "from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b" } ], "on": [ { "arg": "GO_BASE", "image": "golang@sha256:699337d620559a59b4a2bb298ad59611e535d2ee755a34cf2d2a98f37578dc80" }, { "arg": "ALPINE_BASE", "image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc" } ] } }