Files
mesh-catalog/modules/builder/module.json
T
jschoubben 755b0a5599 builder: consume package-registry as a real mesh grant, not a hand-faked one
The 'package-binding' resource was a hardcoded JSON fragment standing in
for a real grant — {"provision": "package-registry", "from": "gitea",
"at": "127.0.0.1", ...} written as if it were mesh-resolved, when nothing
resolved it. Declares requires: package-registry properly instead, with
binds/secrets pointing at the same file paths the resource used to
manually author, so the mesh mints the grant and writes it there.

npm-password renamed to package-registry.secret: it's gitea's generic
user+password, not npm-specific — the same credential works for basic
auth against cargo/PyPI/Go package endpoints too, once gitea's manifest
grows them (novox/hq ADR 0109).

Known gap, not fixed here (novox/hq issue 117): this makes builder
correct for the steady state but breaks a genesis bootstrap — gitea's own
image is built by builder, so builder cannot yet hold this grant the
first time either has to exist. Filed rather than silently accepted.
2026-09-25 17:08:12 +02:00

69 lines
1.8 KiB
JSON

{
"module": "builder",
"version": "1",
"capabilities": [
"container-runtime"
],
"claims": [
{
"name": "the-build-machine",
"scope": "node"
}
],
"requires": [
"artifact-store",
"package-registry"
],
"binds": {
"package-registry": "/var/lib/mesh/builder/package-registry.json"
},
"secrets": {
"package-registry": "/var/lib/mesh/builder/package-registry.secret"
},
"emits": [
"module.builder.built"
],
"own-secrets": {
"broker": "/var/lib/mesh/builder/broker"
},
"resources": [
{
"id": "mesh-state",
"type": "directory",
"path": "/var/lib/mesh/builder",
"mode": "0700"
},
{
"id": "workspace",
"type": "directory",
"path": "/var/lib/builder/workspace",
"mode": "0700"
},
{
"id": "builder-env",
"type": "file",
"path": "/var/lib/mesh/builder/builder.env",
"mode": "0600",
"content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n"
},
{
"id": "server",
"type": "container",
"name": "mesh-builder",
"image": "mesh-builder@sha256:42f5203a6838776447790d9e7d27f22a56e9462bdd25401645f22d188da56704",
"env-file": [
"/var/lib/mesh/builder/builder.env"
],
"volumes": [
"/var/lib/mesh/builder:/run/mesh:ro",
"/var/lib/builder/workspace:/var/lib/builder/workspace",
"/var/run/docker.sock:/var/run/docker.sock"
],
"restart-on": [
"builder-env"
],
"network": "host"
}
]
}