Consumers were held to an S3 access key's 20 characters whatever they required. Each provider now says what its backend keeps: minio 20, PostgreSQL and MongoDB and DNS 63, Gitea 40, a mailbox 64, SQL Server 128, Keycloak 255, unbounded where the store has no limit, and none for the resolver and route provisions, which keep no name of their consumers. Needs the controller that reads the field (mesh-controller, ADR 0225).
147 lines
3.4 KiB
JSON
147 lines
3.4 KiB
JSON
{
|
|
"module": "influxdb",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "influxdb-api",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"in": "an InfluxDB v1 authorization"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"own-secrets": {
|
|
"admin": "${dir:state}/admin.secret",
|
|
"admin-token": "${dir:state}/admin-token.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "api",
|
|
"port": 8086,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "queries, writes and the web UI, over http; consumers granted influxdb-api sign in with the mesh's credential, and a name is a route grant"
|
|
}
|
|
],
|
|
"serves": {
|
|
"influxdb-api": {
|
|
"scheme": "http",
|
|
"port": 8086,
|
|
"org": "mesh",
|
|
"bucket": "default"
|
|
}
|
|
},
|
|
"receives": {
|
|
"influxdb-api": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"influxdb-api": "${dir:grants}"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/server.env",
|
|
"mode": "0600",
|
|
"content": "DOCKER_INFLUXDB_INIT_MODE=setup\nDOCKER_INFLUXDB_INIT_USERNAME=admin\nDOCKER_INFLUXDB_INIT_PASSWORD_FILE=/run/secrets/admin\nDOCKER_INFLUXDB_INIT_ADMIN_TOKEN_FILE=/run/secrets/admin-token\nDOCKER_INFLUXDB_INIT_ORG=mesh\nDOCKER_INFLUXDB_INIT_BUCKET=default\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "influxdb",
|
|
"image": "influxdb@sha256:f75e48af0598e8aec7986e991a848d19a119101a7d563a2e5db1dfaac9c45daa",
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"ports": [
|
|
"8086"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/var/lib/influxdb2",
|
|
"${dir:config}:/etc/influxdb2",
|
|
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
"${dir:state}/admin-token.secret:/run/secrets/admin-token:ro"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "influxdb",
|
|
"endpoint": "api"
|
|
}
|
|
},
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_INFLUXDB_URL": "http://127.0.0.1:${port:8086}",
|
|
"MESH_INFLUXDB_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
|
"MESH_INFLUXDB_TOKEN_FILE": "${dir:state}/admin-token.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"contributions": [
|
|
{
|
|
"seat": "node-backup",
|
|
"kind": "backup",
|
|
"content": "path ${dir:data}\npath ${dir:config}\n"
|
|
}
|
|
]
|
|
}
|