mesh/merge-gate fail: builds baserow, grafana, mailu, matrix, mongodb, mosquitto, nodered, postgres, redis, step-ca, supabase, website → ace, novox; no bus…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery-group group feat/health-the-first-declarations rejected: a member's own check failed
mesh/delivery superseded: a newer head of the same pull request
Seven modules' images ship a check the mesh never read. Adopted by name where it says healthy on the live mesh today: nine of mail's containers (not its antivirus, whose six-minute start is past the five-minute bound, nor its cache, whose image ships none), the certificate authority, the spreadsheet app, four of the database suite's (the studio among them, with the address it binds fixed), the flow editor and the chat client. And the endpoints four services already declare, looked at from the machine: tcp on the database, the cache, the document store and the broker; http on the website and the dashboards. The count of undeclared falls from 93 to 70.
186 lines
4.8 KiB
JSON
186 lines
4.8 KiB
JSON
{
|
|
"module": "mosquitto",
|
|
"version": "1",
|
|
"slug": "mosq",
|
|
"provides": [
|
|
{
|
|
"name": "mqtt-topic",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"in": "a Mosquitto client and topic prefix"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"topic.provisioned",
|
|
"topic.deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mosquitto.topic.provisioned",
|
|
"mosquitto.topic.deprovisioned"
|
|
],
|
|
"serves": {
|
|
"mqtt-topic": {
|
|
"scheme": "mqtt",
|
|
"port": 1883
|
|
}
|
|
},
|
|
"receives": {
|
|
"mqtt-topic": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"mqtt-topic": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"admin": {
|
|
"path": "${dir:mesh-state}/admin",
|
|
"taken": "at-start"
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "mqtt",
|
|
"port": 1883,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a topic namespace"
|
|
},
|
|
{
|
|
"name": "mqtt-websockets",
|
|
"port": 8081,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the same broker over MQTT-on-WebSockets, for browser clients"
|
|
}
|
|
],
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "data",
|
|
"path": "${dir:data}",
|
|
"class": "rebuildable",
|
|
"why": "retained messages and sessions; devices publish them again"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"mqtt-topic": {
|
|
"class": "rebuildable",
|
|
"in": "data",
|
|
"why": "retained messages are published again by the devices"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1883:1883"
|
|
},
|
|
{
|
|
"id": "server-conf",
|
|
"type": "file",
|
|
"path": "${dir:state}/mosquitto.conf",
|
|
"mode": "0600",
|
|
"owner": "1883:1883",
|
|
"content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "mosquitto"
|
|
},
|
|
{
|
|
"id": "bootstrap-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/bootstrap.env",
|
|
"mode": "0600",
|
|
"content": "MESH_PROVISION_MQTT=127.0.0.1:${port:1883}\nMESH_PROVISION_ADMIN_USER=mesh-admin\nMESH_PROVISION_PASSWORD_FILE=${dir:mesh-state}/admin\nMESH_DYNSEC_FILE=${dir:data}/dynamic-security.json\nMESH_MQTT_CTRL_IMAGE=eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408\nMESH_MQTT_CTRL_CONTAINER=mosquitto\nMESH_MQTT_ADMIN_APPLIED_FILE=${dir:state}/admin.applied\n"
|
|
},
|
|
{
|
|
"id": "bootstrap",
|
|
"type": "process",
|
|
"name": "mosquitto-bootstrap",
|
|
"artifact": "code",
|
|
"run": [
|
|
"node",
|
|
"bootstrap/index.js"
|
|
],
|
|
"run-once": true,
|
|
"env-file": [
|
|
"${dir:state}/bootstrap.env"
|
|
],
|
|
"restart-on": [
|
|
"bootstrap-env",
|
|
"needs-admin"
|
|
]
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mosquitto",
|
|
"image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408",
|
|
"health": {
|
|
"kind": "tcp",
|
|
"endpoint": "mqtt"
|
|
},
|
|
"network": "mosquitto",
|
|
"ports": [
|
|
"1883",
|
|
"8081"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/mosquitto/data",
|
|
"${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js",
|
|
"bootstrap/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_PROVISION_MQTT": "127.0.0.1:${port:1883}",
|
|
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:mesh-state}/admin",
|
|
"MESH_MQTT_CTRL_CONTAINER": "mosquitto"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|