Nine references across seven modules named ':latest'. ADR 0006 forbids it and the host refuses it by name — and the refusal had never fired, because the lab pushed every image into its own registry and rewrote each reference to the digest it had just assigned. Deleting that registry made these the only manifests the host would now reject (novox/hq 04-ISSUES/039). The digests are what each tag resolves to today, read from the registry that serves them. This is a stopgap and should be said as one: a digest written into a repository is wrong the moment anybody rebuilds, which is precisely why the design has the repository name artifacts and the mesh hold digests. Until something builds and publishes, a digest that is stale is still better than a tag that silently moves. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
106 lines
2.6 KiB
JSON
106 lines
2.6 KiB
JSON
{
|
|
"module": "invoicing",
|
|
"version": "1",
|
|
"slug": "invoice",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"mongodb-database",
|
|
"s3-bucket",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"mongodb-database": {
|
|
"name": "invoicing"
|
|
},
|
|
"s3-bucket": {
|
|
"bucket": "invoicing"
|
|
},
|
|
"route": {
|
|
"label": "invoicing",
|
|
"port": 80
|
|
}
|
|
},
|
|
"binds": {
|
|
"mongodb-database": "/var/lib/invoicing/database.json",
|
|
"s3-bucket": "/var/lib/invoicing/store.json",
|
|
"route": "/var/lib/invoicing/route.json"
|
|
},
|
|
"secrets": {
|
|
"mongodb-database": "/var/lib/invoicing/database.secret",
|
|
"s3-bucket": "/var/lib/invoicing/store.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the invoicing web frontend; a public name is a route grant later"
|
|
},
|
|
{
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the invoicing REST API the frontend and integrations call"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/invoicing",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/invoicing",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "api-env",
|
|
"type": "file",
|
|
"path": "/var/lib/invoicing/api.env",
|
|
"mode": "0600",
|
|
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/invoicing?authSource=admin\nMINIO_BUCKET=invoicing\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "invoicing"
|
|
},
|
|
{
|
|
"id": "app",
|
|
"type": "container",
|
|
"name": "invoicing-app",
|
|
"image": "registry-api.novox.be/novox/invoicing-app@sha256:1e6ed40822f07169b24867cbfe8fc1ab3ef6a15ad642f3b3a2882a8e15c3dbec",
|
|
"network": "invoicing",
|
|
"env": {
|
|
"UID": "2201",
|
|
"GID": "2201"
|
|
},
|
|
"ports": [
|
|
"80"
|
|
]
|
|
},
|
|
{
|
|
"id": "api",
|
|
"type": "container",
|
|
"name": "invoicing-api",
|
|
"image": "registry-api.novox.be/novox/invoicing-api@sha256:efa6fba1fa9ba78849e94e958d33793a76654df0468e3012da9c02c54c265354",
|
|
"network": "invoicing",
|
|
"env": {
|
|
"UID": "2201",
|
|
"GID": "2201"
|
|
},
|
|
"env-file": [
|
|
"/var/lib/invoicing/api.env"
|
|
],
|
|
"ports": [
|
|
"9000"
|
|
]
|
|
}
|
|
]
|
|
}
|