Files
mesh-catalog/modules/postgres/module.json
T
jschoubben 32cd92baeb Back up every store: the restic module holds node-backup, the stores contribute their dumps
ADR 0214 / to-be 43. restic keeps one repository per machine and takes a nightly snapshot per
module — 14 daily, 8 weekly, 6 monthly — and restores beside the live data, never over it. postgres,
mssql and mongodb contribute a consistent dump; minio, influxdb, the vault, mailu, gitea and
nextcloud the directories that hold their data.
2026-10-05 11:47:59 +02:00

140 lines
3.2 KiB
JSON

{
"module": "postgres",
"version": "1",
"provides": [
{
"name": "postgres-database",
"scope": "mesh"
}
],
"claims": [
{
"name": "mesh-store",
"scope": "mesh",
"serves": [
"databases",
"query"
]
}
],
"capabilities": [
"container-runtime"
],
"emits": [
"database.provisioned",
"database.deprovisioned"
],
"consumes": [
"postgres.database.provisioned",
"postgres.database.deprovisioned"
],
"listens": [
{
"name": "database",
"port": 5432,
"protocol": "tcp",
"from": "mesh",
"why": "modules on any machine that were granted a database"
}
],
"guards": [
5432
],
"serves": {
"postgres-database": {
"port": 5432
}
},
"receives": {
"postgres-database": "${dir:grants}/mesh.json"
},
"grants": {
"postgres-database": "${dir:grants}"
},
"own-secrets": {
"superuser": "${dir:state}/superuser.secret",
"reader": "${dir:state}/reader.secret"
},
"resources": [
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"mode": "0700"
},
{
"id": "store-data",
"type": "directory",
"path": "/var/lib/mesh-store",
"mode": "0700",
"owner": "999:70"
},
{
"id": "dumps",
"type": "directory",
"path": "${dir:store-data}/dumps",
"mode": "0700",
"owner": "999:70"
},
{
"id": "server",
"type": "container",
"name": "postgres",
"image": "pgvector/pgvector@sha256:cf134a767f474095eeba57e0117be8e568e011a63f33fbf252f14c9b760f8e6f",
"env": {
"POSTGRES_PASSWORD_FILE": "/run/secrets/superuser",
"PGDATA": "/var/lib/postgresql/data/pgdata"
},
"ports": [
"5432:5432"
],
"volumes": [
"/var/lib/mesh-store:/var/lib/postgresql/data",
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
]
},
{
"id": "client",
"type": "package",
"package": "postgresql-libs"
}
],
"build": {
"artifacts": [
{
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"loads": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"env": {
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/superuser.secret",
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_POSTGRES_READER_PASSWORD_FILE": "${dir:state}/reader.secret"
}
}
]
},
"contributions": [
{
"seat": "node-backup",
"kind": "backup",
"content": "run docker exec -u postgres postgres sh -c 'cd /var/lib/postgresql/data/dumps && for db in $(psql -Atc \"select datname from pg_database where oid >= 16384 order by 1\"); do pg_dump -Fc -f \"$db.dump.partial\" \"$db\" && mv \"$db.dump.partial\" \"$db.dump\" || exit 1; done'\npath ${dir:dumps}\n"
}
]
}