Step 1.1 and 1.2 of novox/hq ADR 0116. The server is a built artifact rather than the upstream image directly, because it needs an entrypoint of its own: the host can only recreate a container, and recreating the bus for every permission change drops every connection and every in-flight ack. nats-server reloads on SIGHUP by itself, so the config is mounted as a directory (not digest-tracked, hq issue 103) and the entrypoint watches the one file. Verified against the real server, not assumed: a user added to the config connects, a revoked one is refused, both within one poll interval, with the container's PID and restart count unchanged and "Reloaded: accounts" in its log. Two corrections found by checking rather than reading: - the seat delivers nothing now (hq ADR 0117), and the controller's parser refused the manifest until it did — "nats claims mesh-broker, whose holder answers for amqp, and nats does not provide amqp" - pinned to the multi-arch index digest; the first pin was the amd64 manifest, which builds here and fails on any other architecture
19 lines
1.1 KiB
Docker
19 lines
1.1 KiB
Docker
# nats's server image: the upstream server, plus an entrypoint that reloads it in place when the
|
|
# mesh rewrites its configuration. See entrypoint.sh for why that belongs here and not in the host.
|
|
#
|
|
# **Pinned to the multi-architecture index digest, not a platform's.** `docker manifest inspect`
|
|
# reports a platform manifest per architecture and the index that lists them; pinning a platform's
|
|
# digest builds on this workstation and fails on any node of another architecture, with an error
|
|
# that names a manifest rather than the mistake. This is the index — `docker pull` reports the same
|
|
# one, and `RepoDigests` confirms it.
|
|
#
|
|
# Unlike every other module's Dockerfile, this builds no TypeScript and uses no mesh base image:
|
|
# the module's code is the server, which upstream already built. There is no BUILD_BASE here on
|
|
# purpose — nothing is compiled.
|
|
FROM nats@sha256:b83efabe3e7def1e0a4a31ec6e078999bb17c80363f881df35edc70fcb6bb927
|
|
|
|
COPY entrypoint.sh /usr/local/bin/mesh-nats-entrypoint
|
|
RUN chmod 0755 /usr/local/bin/mesh-nats-entrypoint
|
|
|
|
ENTRYPOINT ["/usr/local/bin/mesh-nats-entrypoint"]
|