Mirrors the proven catalog patterns field-for-field: - lidarr -> the Servarr twin of radarr/sonarr (API v1, artist content); no provisioner (it is a consumer app). - mongodb -> postgres shape: mongodb-database provider, provisioner mints a per-consumer db+user (ADR 0053), client shells to mongosh (no npm driver, the psql convention). - mssql -> postgres shape: mssql-database provider, sqlcmd client. - mosquitto -> redis shape: mqtt-topic provider via the Dynamic Security plugin, deliberately avoiding hal's password_file (that file is nox issue 011 exactly); provisioner mints a per-consumer MQTT client+role. All four typecheck (strict, NodeNext) against the built @novox/mesh-sdk, and their service images are digest-pinned to resolved registry digests. The mesh-runtime-<mod> images keep the all-zeros placeholder the pipeline pins, as postgres/redis do, and must bundle each module's CLI (mongosh/sqlcmd/ mosquitto_ctrl) as mesh-runtime-postgres bundles psql. Not yet lab-verified: each module lists in-code what an integration test must prove (auth model, provisioner reconcile, mosquitto dynsec bootstrap ordering). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
55 lines
2.2 KiB
TypeScript
55 lines
2.2 KiB
TypeScript
// mosquitto's tools — mosquitto's own code (novox/hq ADR 0044), importing mosquitto's own admin
|
|
// client. They return structured data; the mesh serves them through the sdk's tool harness.
|
|
|
|
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
|
import { MosquittoClient } from "../client.js";
|
|
|
|
export function getMosquittoTools(mosquitto: MosquittoClient): ToolDefinition[] {
|
|
return [
|
|
{
|
|
name: "mqtt_list_clients",
|
|
description: "List the Dynamic Security clients registered on the mosquitto broker.",
|
|
input: {},
|
|
run: async () => ({ clients: await mosquitto.listClients() }),
|
|
},
|
|
{
|
|
name: "mqtt_get_client",
|
|
description: "Show one Dynamic Security client — its roles and enabled state.",
|
|
input: { username: { type: "string", description: "the client's username" } },
|
|
run: async (args) => {
|
|
const username = String(args.username ?? "");
|
|
if (!username) throw new Error("mqtt_get_client: username is required");
|
|
return { username, detail: await mosquitto.ctl("getClient", username) };
|
|
},
|
|
},
|
|
{
|
|
name: "mqtt_ctrl",
|
|
description:
|
|
"Run an arbitrary 'mosquitto_ctrl dynsec' subcommand, e.g. 'listRoles', 'getRole myrole'. Admin surface.",
|
|
input: { command: { type: "string", description: "the dynsec subcommand and its arguments, space-separated" } },
|
|
run: async (args) => {
|
|
const parts = tokenize(String(args.command ?? ""));
|
|
if (parts.length === 0) throw new Error("mqtt_ctrl: empty command");
|
|
const output = await mosquitto.ctl(...parts);
|
|
return { command: parts.join(" "), output };
|
|
},
|
|
},
|
|
];
|
|
}
|
|
|
|
/** Split a command line into arguments, honouring double-quoted spans. */
|
|
function tokenize(command: string): string[] {
|
|
const matches = command.match(/(?:[^\s"]+|"[^"]*")+/g) ?? [];
|
|
return matches.map((p) => p.replace(/^"|"$/g, ""));
|
|
}
|
|
|
|
// The tools exist only when the broker can be reached from the environment; without it, mosquitto
|
|
// contributes none rather than failing the whole tool runtime.
|
|
registerModuleTools("mosquitto", (env) => {
|
|
try {
|
|
return getMosquittoTools(MosquittoClient.fromEnv(env));
|
|
} catch {
|
|
return [];
|
|
}
|
|
});
|