grafana's data source and Node-RED's influxdb nodes reached ace's InfluxDB by a LAN IP or a public name nobody routes, with a credential somebody made by hand. Now a consumer requires influxdb-api and is told where it is, which org and default bucket it serves, and signs in with the password the mesh minted for the pair. The credential is a v1-compatibility authorization, made per grant by the new provisioner: InfluxDB 2.x generates API tokens itself and ignores one the caller sends, so a v2 token could only be accepted by hand per pair; a v1 authorization takes a caller-chosen password (8-72 characters, the mesh mints 40) and reads/writes every bucket as a database of its name over InfluxQL and line protocol. A consumer contributes `access` (read, write, read-write) and, for writing, the buckets; a missing bucket is made and never deleted. Only authorizations named mesh_* and marked [mesh] are ever changed or removed; anything else of that name is refused and left alone. The org and default bucket are served facts the assignment's settings set, reaching both the consumers and the provisioner's config.json.
164 lines
3.8 KiB
JSON
164 lines
3.8 KiB
JSON
{
|
|
"module": "influxdb",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "influxdb-api",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/influxdb/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "api",
|
|
"port": 8086,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "queries, writes and the web UI, over http; consumers granted influxdb-api sign in with the mesh's credential, and a name is a route grant"
|
|
}
|
|
],
|
|
"serves": {
|
|
"influxdb-api": {
|
|
"scheme": "http",
|
|
"port": 8086,
|
|
"org": "mesh",
|
|
"bucket": "default"
|
|
}
|
|
},
|
|
"receives": {
|
|
"influxdb-api": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"influxdb-api": "${dir:grants}"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/influxdb",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/server.env",
|
|
"mode": "0600",
|
|
"content": "DOCKER_INFLUXDB_INIT_MODE=setup\nDOCKER_INFLUXDB_INIT_USERNAME=admin\nDOCKER_INFLUXDB_INIT_PASSWORD_FILE=/run/secrets/admin\nDOCKER_INFLUXDB_INIT_ADMIN_TOKEN_FILE=/run/secrets/admin-token\nDOCKER_INFLUXDB_INIT_ORG=mesh\nDOCKER_INFLUXDB_INIT_BUCKET=default\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "influxdb",
|
|
"image": "influxdb@sha256:f75e48af0598e8aec7986e991a848d19a119101a7d563a2e5db1dfaac9c45daa",
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"ports": [
|
|
"8086"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/var/lib/influxdb2",
|
|
"${dir:config}:/etc/influxdb2",
|
|
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/influxdb/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-influxdb",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/influxdb/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/influxdb/config.json:/run/config/config.json:ro",
|
|
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro",
|
|
"${dir:grants}:${dir:grants}:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_INFLUXDB_URL": "http://127.0.0.1:${port:8086}",
|
|
"MESH_INFLUXDB_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_INFLUXDB_TOKEN_FILE": "/run/secrets/admin-token",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"requires": [
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "influxdb",
|
|
"endpoint": "api"
|
|
}
|
|
},
|
|
"secrets": {
|
|
"secret": {
|
|
"admin": "${dir:state}/admin.secret",
|
|
"admin-token": "${dir:state}/admin-token.secret"
|
|
}
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|