Review of the registry work found it node-scoped: a second `distribution` on another machine resolved cleanly there, and only afterwards did the mesh notice `artifact-store` offered by two nodes, with every consumer elsewhere refusing to choose. Worse, a node-scoped requirement with one candidate installs that candidate, so anything that wanted the store beside it would have raised a fresh, empty store on the wrong machine first. There is one store in a mesh, which was already the effective rule; the claim now says it where a second one is assigned, by name, instead of leaving consumers to discover it.
59 lines
1.1 KiB
JSON
59 lines
1.1 KiB
JSON
{
|
|
"module": "distribution",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "artifact-store",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "the-artifact-store",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.registry.image.pushed"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/registry/broker"
|
|
},
|
|
"serves": {
|
|
"artifact-store": {
|
|
"port": 5000
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 5000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "every machine pulls images and artifacts from here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/registry",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "store",
|
|
"type": "container",
|
|
"name": "mesh-registry",
|
|
"image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373",
|
|
"ports": [
|
|
"5000:5000"
|
|
],
|
|
"volumes": [
|
|
"mesh-registry-data:/var/lib/registry"
|
|
]
|
|
}
|
|
]
|
|
}
|