A module's identity is the software it is (ADR 0040). Two were named after the job instead, and the job already had a name. firewall installs the nftables package and runs nftables.service. The seat it claims is the-packet-filter, which is correctly named for the role. Calling the module firewall named neither the software nor the provision, and promised that any firewall could sit there — the false genericity the naming rule forbids. registry runs Distribution, the OCI reference implementation, and provides artifact-store. So registry was a third name for a thing that already had two, which is how one word ended up meaning the module, the software and the concept in the same paragraph. The capability stays firewall, and correctly: a capability IS a functionality, so a node having one and fail2ban requiring one are both right. Only the module moves. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
59 lines
1.1 KiB
JSON
59 lines
1.1 KiB
JSON
{
|
|
"module": "distribution",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "artifact-store",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "the-artifact-store",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.registry.image.pushed"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/registry/broker"
|
|
},
|
|
"serves": {
|
|
"artifact-store": {
|
|
"port": 5000
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 5000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "every machine pulls images and artifacts from here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/registry",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "store",
|
|
"type": "container",
|
|
"name": "mesh-registry",
|
|
"image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373",
|
|
"ports": [
|
|
"5000:5000"
|
|
],
|
|
"volumes": [
|
|
"mesh-registry-data:/var/lib/registry"
|
|
]
|
|
}
|
|
]
|
|
}
|