Its provisioner runs DDL by shelling out to psql, which the runtime base has no reason to hold. Every create failed with ENOENT and retried for ever.
38 lines
2.4 KiB
Docker
38 lines
2.4 KiB
Docker
# postgres's runtime: the tool runtime, carrying this module's compiled provisioner, tools and
|
|
# event consumer.
|
|
#
|
|
# **Built from this module's own directory and nothing else.** The sdk is in the base image, so
|
|
# nothing is copied out of a neighbouring checkout — which is what lets the mesh build this from a
|
|
# repository and a path (novox/hq ADR 0069) rather than only on a workstation that happens to have
|
|
# the siblings.
|
|
#
|
|
# The base is named by ARG so it can be pinned to a digest the mesh's registry assigned. A tag would
|
|
# make this runtime's contents depend on what somebody last pushed under that name.
|
|
ARG RUNTIME_BASE=127.0.0.1:5000/mesh-tool-runtime@sha256:d4d793c828a5f563fdd8f49e5c6026d17b308a3f7a13c589849188362e4c7415
|
|
|
|
FROM ${RUNTIME_BASE} AS build
|
|
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
|
# node_modules — the module is compiled against exactly the sdk it will run against.
|
|
WORKDIR /app/modules/postgres
|
|
COPY . .
|
|
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
|
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
|
# was assembled.
|
|
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/index.ts tools/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
# **This module talks to its database through psql, so psql has to be here.** The client is how
|
|
# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only
|
|
# what every module needs. Root to install it, then back to the base's unprivileged user: a
|
|
# provisioner holding the superuser password has no business also being root in its container.
|
|
USER root
|
|
RUN apk add --no-cache postgresql-client
|
|
USER node
|
|
COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist
|
|
# What a tool host should load from this module: its event consumer and its tools, which are
|
|
# separate entrypoints because they are loaded by different things. The provisioner is the third,
|
|
# and is not listed here — the declaration names it in the container's `args`, because it is what
|
|
# this module's own container runs. One image, because they are one module and share a client.
|
|
ENV MESH_TOOL_MODULES=/app/modules/postgres/dist/index.js,/app/modules/postgres/dist/tools/index.js
|