mesh-minio's s3-bucket provisioner shells out to mc to create buckets and service accounts on the live server, but mc was never in this module's own runtime image, only in minio's own. It's been silently retrying 'spawn mc ENOENT' forever, so every s3-bucket grant reached the control-plane layer (store.json, sealed secret) without the credential ever actually existing on minio — nextcloud's live instance just hit this as InvalidAccessKeyId on a real user session. Copies mc from minio's own image (docker.io/pgsty/minio, already pinned and pulled as this module's server container) rather than introducing a new base — mc there is a working, already-verified binary. /usr/bin/mc is a symlink to mcli; both are copied so it resolves.
41 lines
2.3 KiB
Docker
41 lines
2.3 KiB
Docker
# minio's runtime: the tool runtime, carrying this module's compiled code.
|
|
#
|
|
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
# happens to have the siblings.
|
|
#
|
|
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
ARG MC_CLI
|
|
|
|
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
|
|
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
|
|
FROM ${MC_CLI} AS mccli
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler
|
|
# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image
|
|
# resolved away.
|
|
WORKDIR /app/modules/minio
|
|
COPY . .
|
|
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provisioner/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
COPY --from=build /app/modules/minio/dist /app/modules/minio/dist
|
|
# The provisioner shells out to mc to actually create buckets and service accounts on the running
|
|
# minio server — mc itself was never in this runtime image, only in minio's own. Silently retried
|
|
# "spawn mc ENOENT" forever: a requirement was granted at the control-plane level without ever
|
|
# materializing the credential on minio. /usr/bin/mc there is a symlink to the real binary, mcli —
|
|
# both copied so the symlink resolves.
|
|
COPY --from=mccli /usr/bin/mcli /usr/bin/mcli
|
|
COPY --from=mccli /usr/bin/mc /usr/bin/mc
|
|
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
# the convention novox/hq issues 060/061 settled.
|
|
ENV MESH_TOOL_MODULES=/app/modules/minio/dist/tools/index.js,/app/modules/minio/dist/provisioner/index.js
|