The restic holder copied JetStream's store while the server wrote it; such a copy may not restore. The nats image now carries mesh-nats-snapshot, run by the declared dump under the module's own bus account (snapshot API only): every stream one at a time, flow-controlled, into one tar with a manifest of counts, sequences and checksums. Restore builds a new store beside the live one with the bus's own server; a person swaps it in. Proven against throwaway nats 2.11 servers being written to during the snapshot.
48 lines
2.7 KiB
Docker
48 lines
2.7 KiB
Docker
# nats's server image: the upstream server, plus an entrypoint that reloads it in place when the
|
|
# mesh rewrites its configuration. See entrypoint.sh for why that belongs here and not in the host.
|
|
#
|
|
# **Pinned to the multi-architecture index digest, not a platform's.** `docker manifest inspect`
|
|
# reports a platform manifest per architecture and the index that lists them; pinning a platform's
|
|
# digest builds on this workstation and fails on any node of another architecture, with an error
|
|
# that names a manifest rather than the mistake. This is the index — `docker pull` reports the same
|
|
# one, and `RepoDigests` confirms it.
|
|
#
|
|
# **The release the digest is, said here because a digest does not say it:**
|
|
#
|
|
# upstream: nats 2.11.17-alpine
|
|
#
|
|
# Kept equal to the server version cmd/nats-tools tests against (its go.mod), and a test there fails
|
|
# when they differ: that test is what says the server delivers every message to a consumer with
|
|
# several filters. 2.10.29 did not — it moved such a consumer past a message now and then without
|
|
# handing it over, and the controller never heard of a merge (novox/hq issue 266).
|
|
#
|
|
# Unlike every other module's Dockerfile, this builds no TypeScript and uses no mesh base image:
|
|
# the module's code is the server, which upstream already built. There is no BUILD_BASE here on
|
|
# purpose — the server is not compiled; only the snapshot program below is. The upstream image is
|
|
# declared in the manifest under build.on and arrives as NATS_BASE, like every other base the mesh
|
|
# copies into its own store before a build (novox/hq ADR 0097); the digest above is the index one
|
|
# for the reason given. So does GO_BASE, the toolchain the snapshot program is built with.
|
|
#
|
|
# **One thing is compiled: the bus's snapshot program** (novox/hq ADR 0235). The machine's backup
|
|
# holder runs the module's declared dump — `docker exec` into this container — and the program asks
|
|
# the server for each stream through the snapshot API, writing a tar on stdout. It is here, beside
|
|
# the server, for two reasons: the dump runs where the server is without mounting anything into it,
|
|
# and a restore needs nats-server itself — the very binary this image already carries — to fill a new
|
|
# store. Its own Go module (snapshot/go.mod), so this build fetches only public modules.
|
|
ARG NATS_BASE
|
|
ARG GO_BASE
|
|
FROM ${GO_BASE} AS snapshot
|
|
WORKDIR /src
|
|
COPY snapshot/go.mod snapshot/go.sum ./
|
|
RUN go mod download
|
|
COPY snapshot/*.go ./
|
|
RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' -o /mesh-nats-snapshot .
|
|
|
|
FROM ${NATS_BASE}
|
|
|
|
COPY entrypoint.sh /usr/local/bin/mesh-nats-entrypoint
|
|
RUN chmod 0755 /usr/local/bin/mesh-nats-entrypoint
|
|
COPY --from=snapshot /mesh-nats-snapshot /usr/local/bin/mesh-nats-snapshot
|
|
|
|
ENTRYPOINT ["/usr/local/bin/mesh-nats-entrypoint"]
|