Three modules' tools act through `sudo -n` and nothing declared that the account may; each machine said so in a hand-set line in /etc/sudoers. The module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked by visudo in its manifest test, and serves sudo_rules, sudo_check and sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which would collide with this module on the node that runs both (hq ADR 0207, to-be 42 Phase 1).
89 lines
1.5 KiB
JSON
89 lines
1.5 KiB
JSON
{
|
|
"module": "lab",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime",
|
|
"virtualisation"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "work",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-lab-runs",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "runtime-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/lab.env",
|
|
"mode": "0600",
|
|
"content": "MESH_LAB_FORGE=${setting:forge}\n"
|
|
},
|
|
{
|
|
"id": "git",
|
|
"type": "package",
|
|
"package": "git"
|
|
},
|
|
{
|
|
"id": "make",
|
|
"type": "package",
|
|
"package": "make"
|
|
},
|
|
{
|
|
"id": "python",
|
|
"type": "package",
|
|
"package": "python"
|
|
},
|
|
{
|
|
"id": "file",
|
|
"type": "package",
|
|
"package": "file"
|
|
},
|
|
{
|
|
"id": "iproute2",
|
|
"type": "package",
|
|
"package": "iproute2"
|
|
},
|
|
{
|
|
"id": "npm",
|
|
"type": "package",
|
|
"package": "npm"
|
|
},
|
|
{
|
|
"id": "go",
|
|
"type": "package",
|
|
"package": "go"
|
|
},
|
|
{
|
|
"id": "incus",
|
|
"type": "package",
|
|
"package": "incus"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js"
|
|
],
|
|
"loads": [
|
|
"tools/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_LAB_WORK": "${dir:work}",
|
|
"MESH_LAB_ENV_FILE": "${dir:state}/lab.env"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|