Implements novox/hq ADR 0109, 0110 and 0111 in the catalogue. package-registry becomes npm-package-registry throughout (ADR 0109): gitea provides and serves it, verdaccio provides it, the builder requires, binds and receives its secret under it. gitea's contributions file is grants/npm.json, so a second ecosystem's file has an obvious name beside it. gitea claims two mesh seats (ADR 0110): npm-package-registry, which it delivers, and git, which it now provides with what a clone URL is composed from — http on the forge's web port (ADR 0111). verdaccio provides npm-package-registry and claims nothing: it is the second provider the seat exists to make harmless, since a consumer now resolves to the seat's holder without a pin. No cargo or PyPI provision is added; ADR 0109 defers that. git mints no credential, so gitea's provisioner registers nothing for it — the mesh's own repositories are public, and a clone credential is undecided (ADR 0111). The provisioner still reads where its contributions land from $MESH_RECEIVES, and names no path itself. One variable carries one path, so a second registration in this module would need the mesh to say where each provision's file is; that is not possible yet and is not faked here. Verified: the controller's tests read this catalogue — every claim is a seat in the set, the forge holds both seats and serves what a clone URL needs, the builder requires what the npm seat delivers — and pass. Not verified here: a TypeScript build of gitea, whose dependencies resolve from the private registry.
131 lines
3.1 KiB
JSON
131 lines
3.1 KiB
JSON
{
|
|
"module": "verdaccio",
|
|
"version": "1",
|
|
"slug": "verdacc",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.verdaccio.package.published"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/verdaccio/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 4873,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the package registry, for installs and publishes"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/verdaccio",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "conf",
|
|
"type": "directory",
|
|
"path": "/services/verdaccio/conf",
|
|
"mode": "0755",
|
|
"owner": "10001:10001"
|
|
},
|
|
{
|
|
"id": "storage",
|
|
"type": "directory",
|
|
"path": "/services/verdaccio/storage",
|
|
"mode": "0700",
|
|
"owner": "10001:10001"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/services/verdaccio/conf/config.yaml",
|
|
"mode": "0644",
|
|
"content": "storage: /verdaccio/storage\nauth:\n htpasswd:\n file: /verdaccio/conf/htpasswd\n max_users: 10\nuplinks:\n npmjs:\n url: https://registry.npmjs.org/\npackages:\n \"**\":\n access: $all\n publish: $authenticated\n proxy: npmjs\nserver:\n keepAliveTimeout: 60\n maxBodySize: 10mb\nmiddlewares:\n audit:\n enabled: true\nlog:\n type: stdout\n format: pretty\n level: http\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "verdaccio",
|
|
"image": "verdaccio/verdaccio@sha256:7b067a47ae51fb9dff3dcdce60ec0a2cbd7650c208cb4b9f6d37cb1b09b39d43",
|
|
"ports": [
|
|
"4873"
|
|
],
|
|
"volumes": [
|
|
"/services/verdaccio/storage:/verdaccio/storage",
|
|
"/services/verdaccio/conf:/verdaccio/conf"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/verdaccio/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-verdaccio",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/verdaccio/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/verdaccio/config.json:/run/config/config.json:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_VERDACCIO_URL": "http://127.0.0.1:4873",
|
|
"MESH_VERDACCIO_CONFIG_FILE": "/run/config/config.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "npm",
|
|
"port": 4873
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "/var/lib/mesh/verdaccio/route.json"
|
|
},
|
|
"provides": [
|
|
{
|
|
"name": "npm-package-registry",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|