Files
mesh-catalog/modules/mongodb/module.json
T
jochen 1fd2914ae1 Say which modules wait for a person's push, and announce the files a merge deleted (hq ADR 0236)
With a gate on the first machine and a rollback after it, a module's build rolls out by
default. The ones kept back say why: the network path a rollback could not cross, the
providers every consumer on a machine drops with, and the stores holding the photos.
A merge's deleted files are announced, so a module whose manifest went is forgotten
rather than asked to build (the public-acme plan failure).
2026-10-06 18:39:13 +02:00

158 lines
3.9 KiB
JSON

{
"module": "mongodb",
"version": "1",
"upgrade": {
"policy": "record",
"why": "a provider whose restart drops every consumer on its machine, and which holds the photos' albums (irreplaceable, kept by photos): a person takes each build, after a backup (hq ADR 0236)"
},
"provides": [
{
"name": "mongodb-database",
"scope": "mesh",
"identity": {
"max": 63,
"in": "a MongoDB database name"
}
}
],
"capabilities": [
"container-runtime"
],
"emits": [
"database.provisioned",
"database.deprovisioned"
],
"consumes": [
"mongodb.database.provisioned",
"mongodb.database.deprovisioned"
],
"listens": [
{
"name": "database",
"port": 27017,
"protocol": "tcp",
"from": "mesh",
"why": "modules on any machine that were granted a database"
}
],
"serves": {
"mongodb-database": {
"port": 27017
}
},
"receives": {
"mongodb-database": "${dir:grants}/mesh.json"
},
"grants": {
"mongodb-database": "${dir:grants}"
},
"own-secrets": {
"root": "${dir:state}/root.secret"
},
"data": {
"own": [
{
"id": "data",
"path": "${dir:data}",
"class": "valuable",
"backup": {
"dump": "docker exec mongodb-server sh -c 'printf \"password: %s\\n\" \"$(cat /run/secrets/root)\" > /tmp/.backup.yaml && mongodump --quiet --config /tmp/.backup.yaml --username root --authenticationDatabase admin --archive; s=$?; rm -f /tmp/.backup.yaml; exit $s' > ${dir:dumps}/all.archive.partial && mv ${dir:dumps}/all.archive.partial ${dir:dumps}/all.archive",
"into": "dumps"
},
"why": "every consumer's database; copied by the dump, not as live files"
},
{
"id": "dumps",
"path": "${dir:dumps}",
"class": "rebuildable",
"why": "last night's dump, made again every night"
}
],
"consumers": {
"mongodb-database": {
"class": "valuable",
"in": "data",
"why": "a consumer's documents are the only copy of what it wrote; a consumer that keeps something irreplaceable here says so (kept-by)"
}
}
},
"resources": [
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"mode": "0700"
},
{
"id": "data",
"type": "directory",
"mode": "0700"
},
{
"id": "dumps",
"type": "directory",
"mode": "0700"
},
{
"id": "net",
"type": "network",
"name": "mongodb"
},
{
"id": "server-root",
"type": "file",
"path": "${dir:state}/server-root.secret",
"mode": "0400",
"owner": "999:999",
"content": "${secret:root}"
},
{
"id": "server",
"type": "container",
"name": "mongodb-server",
"image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3",
"network": "mongodb",
"env": {
"MONGO_INITDB_ROOT_USERNAME": "root",
"MONGO_INITDB_ROOT_PASSWORD_FILE": "/run/secrets/root"
},
"ports": [
"27017"
],
"volumes": [
"${dir:data}:/data/db",
"${dir:state}/server-root.secret:/run/secrets/root:ro"
]
}
],
"build": {
"artifacts": [
{
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"loads": [
"index.js",
"tools/index.js",
"provisioner/index.js"
],
"env": {
"MESH_PROVISION_MONGODB": "mongodb://root@127.0.0.1:${port:27017}/admin?authSource=admin",
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/root.secret",
"MESH_RECEIVES": "${dir:grants}/mesh.json"
}
}
]
}
}