The tool runtime's own client, mesh serve, started by the mesh on the credential it sealed to the machine (novox/hq ADR 0152, design 34): invokes every tool, listens from the machine only, holds no state. Checked with module check before it was ever registered (hq issue 148).
65 lines
1.3 KiB
JSON
65 lines
1.3 KiB
JSON
{
|
|
"module": "mesh-console",
|
|
"version": "1",
|
|
"slug": "console",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"invokes": [
|
|
"*"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/mesh-console/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "mcp",
|
|
"port": 4270,
|
|
"protocol": "tcp",
|
|
"from": "machine",
|
|
"why": "the mesh's tools for whoever is on this machine, over MCP on loopback; the machine's login is the authority (novox/hq ADR 0152)"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/mesh-console",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-console",
|
|
"network": "host",
|
|
"args": [
|
|
"serve"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_CONSOLE_LISTEN": "127.0.0.1:${port:4270}"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/mesh/mesh-console/broker:/run/secrets/broker:ro"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|