The manifest predated the working deployment on three axes: it declared a data directory the running portainer never used (taking it would have started empty), pinned an image digest the machine has moved past (issue 099), and contributed no route while portainer.novox.be rides a traefik container label today. Now: the predecessor's portainer_data path, the running image's digest, 9090:9000 kept as the predecessor's machine port with the route contribution naming it, and 9443 kept for the runtime sidecar's own TLS conversation.
114 lines
2.6 KiB
JSON
114 lines
2.6 KiB
JSON
{
|
|
"module": "portainer",
|
|
"version": "1",
|
|
"slug": "portain",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"listens": [
|
|
{
|
|
"port": 9090,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
|
},
|
|
{
|
|
"port": 9443,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the same dashboard over its own tls; the runtime sidecar talks to it here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/portainer",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/services/portainer/portainer_data",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "portainer",
|
|
"image": "portainer/portainer-ce@sha256:4d616db18cfeb5dd41a69c0958bc825c84483ea9cde1106eb82a5d26f3bd8b0e",
|
|
"ports": [
|
|
"9090:9000",
|
|
"9443:9443"
|
|
],
|
|
"volumes": [
|
|
"/services/portainer/portainer_data:/data",
|
|
"/var/run/docker.sock:/var/run/docker.sock"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/portainer/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-portainer",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/portainer/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/portainer/config.json:/run/config/config.json:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_PORTAINER_URL": "https://127.0.0.1:9443",
|
|
"MESH_PORTAINER_CONFIG_FILE": "/run/config/config.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/portainer/broker"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
},
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "portainer",
|
|
"port": 9090
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "/var/lib/mesh/portainer/route.json"
|
|
}
|
|
}
|