mesh/merge-gate pass: builds baserow, grafana, mailu, matrix, mongodb, mosquitto, nodered, postgres, redis, step-ca, supabase, website → ace, novox; no bus…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-first-declarations delivered: every member is delivered
Seven modules' images ship a check the mesh never read. Adopted by name where it says healthy on the live mesh today: nine of mail's containers (not its antivirus, whose six-minute start is past the five-minute bound, nor its cache, whose image ships none), the certificate authority, the spreadsheet app, four of the database suite's (the studio among them, with the address it binds fixed), the flow editor and the chat client. And the endpoints four services already declare, looked at from the machine: tcp on the database, the cache, the document store and the broker; http on the website and the dashboards. The count of undeclared falls from 93 to 70.
168 lines
4.1 KiB
JSON
168 lines
4.1 KiB
JSON
{
|
|
"module": "postgres",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "a provider whose restart drops every consumer on its machine, and whose new major version changes its data's format: a person takes each build, after a backup (hq ADR 0236)"
|
|
},
|
|
"provides": [
|
|
{
|
|
"name": "postgres-database",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 63,
|
|
"in": "a PostgreSQL role and database name"
|
|
}
|
|
}
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-store",
|
|
"scope": "mesh",
|
|
"serves": [
|
|
"databases",
|
|
"query"
|
|
]
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"database.provisioned",
|
|
"database.deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"postgres.database.provisioned",
|
|
"postgres.database.deprovisioned"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "database",
|
|
"port": 5432,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a database"
|
|
}
|
|
],
|
|
"guards": [
|
|
5432
|
|
],
|
|
"serves": {
|
|
"postgres-database": {
|
|
"port": 5432
|
|
}
|
|
},
|
|
"receives": {
|
|
"postgres-database": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"postgres-database": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"superuser": "${dir:state}/superuser.secret",
|
|
"reader": "${dir:state}/reader.secret"
|
|
},
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "store",
|
|
"path": "${dir:store-data}",
|
|
"class": "valuable",
|
|
"backup": {
|
|
"dump": "docker exec -u postgres postgres sh -c 'cd /var/lib/postgresql/data/dumps && for db in $(psql -Atc \"select datname from pg_database where oid >= 16384 order by 1\"); do pg_dump -Fc -f \"$db.dump.partial\" \"$db\" && mv \"$db.dump.partial\" \"$db.dump\" || exit 1; done'",
|
|
"into": "dumps"
|
|
},
|
|
"why": "every consumer's database; copied by the dump below, since a running store's files are not a consistent copy"
|
|
},
|
|
{
|
|
"id": "dumps",
|
|
"path": "${dir:dumps}",
|
|
"class": "rebuildable",
|
|
"why": "last night's dump of the store, made again every night"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"postgres-database": {
|
|
"class": "valuable",
|
|
"in": "store",
|
|
"why": "a consumer's rows are the only copy of what it wrote"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "store-data",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-store",
|
|
"mode": "0700",
|
|
"owner": "999:70"
|
|
},
|
|
{
|
|
"id": "dumps",
|
|
"type": "directory",
|
|
"path": "${dir:store-data}/dumps",
|
|
"mode": "0700",
|
|
"owner": "999:70"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "postgres",
|
|
"image": "pgvector/pgvector@sha256:cf134a767f474095eeba57e0117be8e568e011a63f33fbf252f14c9b760f8e6f",
|
|
"health": {
|
|
"kind": "tcp",
|
|
"endpoint": "database"
|
|
},
|
|
"env": {
|
|
"POSTGRES_PASSWORD_FILE": "/run/secrets/superuser",
|
|
"PGDATA": "/var/lib/postgresql/data/pgdata"
|
|
},
|
|
"ports": [
|
|
"5432:5432"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/mesh-store:/var/lib/postgresql/data",
|
|
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
|
|
]
|
|
},
|
|
{
|
|
"id": "client",
|
|
"type": "package",
|
|
"package": "postgresql-libs"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/postgres-provider",
|
|
"binary": "postgres-provider",
|
|
"loads": [
|
|
"postgres-provider"
|
|
],
|
|
"env": {
|
|
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
|
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/superuser.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_POSTGRES_READER_PASSWORD_FILE": "${dir:state}/reader.secret"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|