Naming it from the binding was right and arrived too early. The moment the machine had a name, the builder pushed to <node>.internal:5000 and the runtime refused it: "http: server gave HTTP response to HTTPS client". The registry serves plaintext, and anything that is not loopback is required to be HTTPS. So there are two phases, and this is the first. Before the mesh has a certificate authority of its own, loopback is the only trusted path that is honest — it is trusted because it cannot leave the machine, not because anyone checked anything. The mesh-reachable name belongs to the second phase, with TLS from the mesh's own CA, and the binding expression returns then. Not a revert of the reasoning: novox/hq issue 048 stays open and this is why. The same one-line change lands again once a certificate module is running. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
61 lines
1.4 KiB
JSON
61 lines
1.4 KiB
JSON
{
|
|
"module": "builder",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "the-build-machine",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"requires": [
|
|
"artifact-store"
|
|
],
|
|
"emits": [
|
|
"module.builder.built"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/builder/broker"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/builder",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "workspace",
|
|
"type": "directory",
|
|
"path": "/var/lib/builder/workspace",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "builder-env",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/builder/builder.env",
|
|
"mode": "0600",
|
|
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=127.0.0.1:${bound:artifact-store:port}\nMESH_WORKSPACE=/workspace\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-builder",
|
|
"image": "mesh-builder@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"env-file": [
|
|
"/var/lib/mesh/builder/builder.env"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/mesh/builder:/run/mesh:ro",
|
|
"/var/lib/builder/workspace:/workspace",
|
|
"/var/run/docker.sock:/var/run/docker.sock"
|
|
],
|
|
"restart-on": [
|
|
"builder-env"
|
|
]
|
|
}
|
|
]
|
|
}
|