mqtt-topic served nothing: with two listens the mesh could not say which port a consumer dials, so a
consumer had to type 1883 into its config. It now serves the MQTT listener's port (the machine's,
once assigned) and the scheme, so `${bound:mqtt-topic:port}` fills.
The provisioner confined every consumer to `<as>/#`, which leaves nothing for the consumers the
broker exists for: Home Assistant discovers under homeassistant/# and tasmota/discovery/#, and
Node-RED's flows follow the devices' own topics. A consumer now contributes `topics` (MQTT topic
filters) to its mqtt-topic requirement and is granted exactly those; with none, its own subtree as
before. Settings merge into contributions, so an operator narrows a grant per assignment. The role
is brought to exactly the wanted ACLs (stale ones removed), `holds` checks the ACLs too, and an
invalid list is refused, never quietly narrowed. Only the role named for the consumer is touched:
a client carried from the predecessor's password file keeps its own.
29 lines
1.7 KiB
Docker
29 lines
1.7 KiB
Docker
# mosquitto's runtime: the tool runtime, carrying this module's compiled code.
|
|
#
|
|
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
# happens to have the siblings.
|
|
#
|
|
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
WORKDIR /app/modules/mosquitto
|
|
COPY . .
|
|
RUN node /app/node_modules/typescript/bin/tsc topics.ts client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
# mosquitto's client and bootstrap drive `mosquitto_ctrl`; the apt package carries it with its
|
|
# shared libraries — the musl binary from the eclipse image would not load on this glibc base.
|
|
RUN apt-get update && apt-get install -y --no-install-recommends mosquitto \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
COPY --from=build /app/modules/mosquitto/dist /app/modules/mosquitto/dist
|
|
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
# the convention novox/hq issues 060/061 settled.
|
|
ENV MESH_TOOL_MODULES=/app/modules/mosquitto/dist/index.js,/app/modules/mosquitto/dist/tools/index.js,/app/modules/mosquitto/dist/provisioner/index.js
|