mesh/merge-gate fail: builds baserow, grafana, mailu, matrix, mongodb, mosquitto, nodered, postgres, redis, step-ca, supabase, website → ace, novox; no bus…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery-group group feat/health-the-first-declarations rejected: a member's own check failed
mesh/delivery superseded: a newer head of the same pull request
Seven modules' images ship a check the mesh never read. Adopted by name where it says healthy on the live mesh today: nine of mail's containers (not its antivirus, whose six-minute start is past the five-minute bound, nor its cache, whose image ships none), the certificate authority, the spreadsheet app, four of the database suite's (the studio among them, with the address it binds fixed), the flow editor and the chat client. And the endpoints four services already declare, looked at from the machine: tcp on the database, the cache, the document store and the broker; http on the website and the dashboards. The count of undeclared falls from 93 to 70.
162 lines
4.0 KiB
JSON
162 lines
4.0 KiB
JSON
{
|
|
"module": "mongodb",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "a provider whose restart drops every consumer on its machine, and which holds the photos' albums (irreplaceable, kept by photos): a person takes each build, after a backup (hq ADR 0236)"
|
|
},
|
|
"provides": [
|
|
{
|
|
"name": "mongodb-database",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 63,
|
|
"in": "a MongoDB database name"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"database.provisioned",
|
|
"database.deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mongodb.database.provisioned",
|
|
"mongodb.database.deprovisioned"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "database",
|
|
"port": 27017,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a database"
|
|
}
|
|
],
|
|
"serves": {
|
|
"mongodb-database": {
|
|
"port": 27017
|
|
}
|
|
},
|
|
"receives": {
|
|
"mongodb-database": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"mongodb-database": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"root": "${dir:state}/root.secret"
|
|
},
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "data",
|
|
"path": "${dir:data}",
|
|
"class": "valuable",
|
|
"backup": {
|
|
"dump": "docker exec mongodb-server sh -c 'printf \"password: %s\\n\" \"$(cat /run/secrets/root)\" > /tmp/.backup.yaml && mongodump --quiet --config /tmp/.backup.yaml --username root --authenticationDatabase admin --archive; s=$?; rm -f /tmp/.backup.yaml; exit $s' > ${dir:dumps}/all.archive.partial && mv ${dir:dumps}/all.archive.partial ${dir:dumps}/all.archive",
|
|
"into": "dumps"
|
|
},
|
|
"why": "every consumer's database; copied by the dump, not as live files"
|
|
},
|
|
{
|
|
"id": "dumps",
|
|
"path": "${dir:dumps}",
|
|
"class": "rebuildable",
|
|
"why": "last night's dump, made again every night"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"mongodb-database": {
|
|
"class": "valuable",
|
|
"in": "data",
|
|
"why": "a consumer's documents are the only copy of what it wrote; a consumer that keeps something irreplaceable here says so (kept-by)"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "dumps",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "mongodb"
|
|
},
|
|
{
|
|
"id": "server-root",
|
|
"type": "file",
|
|
"path": "${dir:state}/server-root.secret",
|
|
"mode": "0400",
|
|
"owner": "999:999",
|
|
"content": "${secret:root}"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mongodb-server",
|
|
"image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3",
|
|
"health": {
|
|
"kind": "tcp",
|
|
"endpoint": "database"
|
|
},
|
|
"network": "mongodb",
|
|
"env": {
|
|
"MONGO_INITDB_ROOT_USERNAME": "root",
|
|
"MONGO_INITDB_ROOT_PASSWORD_FILE": "/run/secrets/root"
|
|
},
|
|
"ports": [
|
|
"27017"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data/db",
|
|
"${dir:state}/server-root.secret:/run/secrets/root:ro"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_PROVISION_MONGODB": "mongodb://root@127.0.0.1:${port:27017}/admin?authSource=admin",
|
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/root.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|