Files
mesh-catalog/modules/postgres/module.json
T
jochen f87f4cdfe5
mesh/merge-gate pass: builds baserow, grafana, mailu, matrix, mongodb, mosquitto, nodered, postgres, redis, step-ca, supabase, website → ace, novox; no bus…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-first-declarations delivered: every member is delivered
Say how the first twenty-three long-running resources are ready (hq ADR 0240, to-be 48 Phase E)
Seven modules' images ship a check the mesh never read. Adopted by name where
it says healthy on the live mesh today: nine of mail's containers (not its
antivirus, whose six-minute start is past the five-minute bound, nor its cache,
whose image ships none), the certificate authority, the spreadsheet app, four
of the database suite's (the studio among them, with the address it binds
fixed), the flow editor and the chat client. And the endpoints four services
already declare, looked at from the machine: tcp on the database, the cache,
the document store and the broker; http on the website and the dashboards.
The count of undeclared falls from 93 to 70.
2026-10-07 18:47:58 +02:00

168 lines
4.1 KiB
JSON

{
"module": "postgres",
"version": "1",
"upgrade": {
"policy": "record",
"why": "a provider whose restart drops every consumer on its machine, and whose new major version changes its data's format: a person takes each build, after a backup (hq ADR 0236)"
},
"provides": [
{
"name": "postgres-database",
"scope": "mesh",
"identity": {
"max": 63,
"in": "a PostgreSQL role and database name"
}
}
],
"claims": [
{
"name": "mesh-store",
"scope": "mesh",
"serves": [
"databases",
"query"
]
}
],
"capabilities": [
"container-runtime"
],
"emits": [
"database.provisioned",
"database.deprovisioned"
],
"consumes": [
"postgres.database.provisioned",
"postgres.database.deprovisioned"
],
"listens": [
{
"name": "database",
"port": 5432,
"protocol": "tcp",
"from": "mesh",
"why": "modules on any machine that were granted a database"
}
],
"guards": [
5432
],
"serves": {
"postgres-database": {
"port": 5432
}
},
"receives": {
"postgres-database": "${dir:grants}/mesh.json"
},
"grants": {
"postgres-database": "${dir:grants}"
},
"own-secrets": {
"superuser": "${dir:state}/superuser.secret",
"reader": "${dir:state}/reader.secret"
},
"data": {
"own": [
{
"id": "store",
"path": "${dir:store-data}",
"class": "valuable",
"backup": {
"dump": "docker exec -u postgres postgres sh -c 'cd /var/lib/postgresql/data/dumps && for db in $(psql -Atc \"select datname from pg_database where oid >= 16384 order by 1\"); do pg_dump -Fc -f \"$db.dump.partial\" \"$db\" && mv \"$db.dump.partial\" \"$db.dump\" || exit 1; done'",
"into": "dumps"
},
"why": "every consumer's database; copied by the dump below, since a running store's files are not a consistent copy"
},
{
"id": "dumps",
"path": "${dir:dumps}",
"class": "rebuildable",
"why": "last night's dump of the store, made again every night"
}
],
"consumers": {
"postgres-database": {
"class": "valuable",
"in": "store",
"why": "a consumer's rows are the only copy of what it wrote"
}
}
},
"resources": [
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"mode": "0700"
},
{
"id": "store-data",
"type": "directory",
"path": "/var/lib/mesh-store",
"mode": "0700",
"owner": "999:70"
},
{
"id": "dumps",
"type": "directory",
"path": "${dir:store-data}/dumps",
"mode": "0700",
"owner": "999:70"
},
{
"id": "server",
"type": "container",
"name": "postgres",
"image": "pgvector/pgvector@sha256:cf134a767f474095eeba57e0117be8e568e011a63f33fbf252f14c9b760f8e6f",
"health": {
"kind": "tcp",
"endpoint": "database"
},
"env": {
"POSTGRES_PASSWORD_FILE": "/run/secrets/superuser",
"PGDATA": "/var/lib/postgresql/data/pgdata"
},
"ports": [
"5432:5432"
],
"volumes": [
"/var/lib/mesh-store:/var/lib/postgresql/data",
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
]
},
{
"id": "client",
"type": "package",
"package": "postgresql-libs"
}
],
"build": {
"artifacts": [
{
"name": "code",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/postgres-provider",
"binary": "postgres-provider",
"loads": [
"postgres-provider"
],
"env": {
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/superuser.secret",
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_POSTGRES_READER_PASSWORD_FILE": "${dir:state}/reader.secret"
}
}
]
}
}