Files
mesh-catalog/modules/verdaccio/index.ts
T
jschoubben 7b06a7a408 Event names are local now, in the manifests and in the code
Every module named its events the way the old bus spelled a routing key —
`module.<module>.<verb>`. Design 29 says a module names an event locally and the
mesh works out where it lands, so all 37 were stale against a rule already
decided. On the new bus that derives into a namespace belonging to a module
called "module", so no cross-module subscription in the mesh matched anything:
nothing failed, nothing reacted (novox/hq 04-ISSUES/127).

36 manifests converted, and 43 files of module code with them. The code mattered
as much as the manifests: the runtime builds the subject from what `emit()` is
handed, so a converted manifest with unconverted code would have had the
permission and the subject disagree.

Three things the new check found on the way:

- `photos` emitted an event its manifest never declared, which the new bus refuses
  outright. Declared.
- `showcase` waited for an event nothing emits, so its demo could never be
  triggered — only `showcase` may publish under its own name. It emits both halves
  now.
- `distribution` declared an event named after a different module. It emits
  `image.pushed` under its own name. An event about a *role* belongs on the seat,
  where the name outlives whoever holds it, but the sdk has no way to publish on a
  seat yet, so that stays recorded rather than declared.

The audit logger's "everything" pattern is `**` rather than the old bus's `#`.
2026-09-27 14:42:28 +02:00

46 lines
1.8 KiB
TypeScript

// verdaccio's events. The tool runtime imports this once the broker is bound.
//
// Emits (novox/hq ADR 0041/0042):
// module.verdaccio.package.published — a new package version was published to the registry
//
// A genuinely useful signal: a package was just published, so anything on the mesh that pins,
// mirrors or announces dependency releases can react without polling the registry. Verdaccio has
// no publish webhook, so the module discovers it by diffing the package list's latest versions.
//
// The polling is deliberately unhurried: a publish a minute late is still the event, whereas
// hammering the registry for immediacy nobody asked for is not.
import { emit } from "@novox/mesh-sdk/events";
import { VerdaccioClient } from "./client.js";
const verdaccio = VerdaccioClient.fromEnv();
// The latest version we have seen per package name. Primed silently on the first look so a registry
// that was already populated when this started does not announce its whole catalog as freshly
// published.
const latest = new Map<string, string>();
let primed = false;
async function pollPackages(): Promise<void> {
const packages = await verdaccio.listPackages();
for (const pkg of packages) {
if (!pkg.version) continue;
const known = latest.get(pkg.name);
if (known !== pkg.version) {
// A name we have not seen, or a name whose latest version moved — both are a publish.
if (primed) await emit("package.published", { name: pkg.name, version: pkg.version });
latest.set(pkg.name, pkg.version);
}
}
primed = true;
}
const tick = (fn: () => Promise<void>, everyMs: number): void => {
const run = (): void => void fn().catch((err) => console.error(`[verdaccio] ${err}`));
setInterval(run, everyMs);
run();
};
tick(pollPackages, 60_000);
console.log("[verdaccio] watching the registry for newly published packages");