Files
mesh-catalog/modules/mosquitto/tools/index.ts
T
jschoubben c82b3ff706 Convert four hal modules: lidarr, mongodb, mssql, mosquitto
Mirrors the proven catalog patterns field-for-field:
- lidarr  -> the Servarr twin of radarr/sonarr (API v1, artist content); no
  provisioner (it is a consumer app).
- mongodb -> postgres shape: mongodb-database provider, provisioner mints a
  per-consumer db+user (ADR 0053), client shells to mongosh (no npm driver,
  the psql convention).
- mssql   -> postgres shape: mssql-database provider, sqlcmd client.
- mosquitto -> redis shape: mqtt-topic provider via the Dynamic Security
  plugin, deliberately avoiding hal's password_file (that file is nox issue
  011 exactly); provisioner mints a per-consumer MQTT client+role.

All four typecheck (strict, NodeNext) against the built @novox/mesh-sdk, and
their service images are digest-pinned to resolved registry digests. The
mesh-runtime-<mod> images keep the all-zeros placeholder the pipeline pins,
as postgres/redis do, and must bundle each module's CLI (mongosh/sqlcmd/
mosquitto_ctrl) as mesh-runtime-postgres bundles psql.

Not yet lab-verified: each module lists in-code what an integration test must
prove (auth model, provisioner reconcile, mosquitto dynsec bootstrap ordering).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-05 04:17:07 +02:00

55 lines
2.2 KiB
TypeScript

// mosquitto's tools — mosquitto's own code (novox/hq ADR 0044), importing mosquitto's own admin
// client. They return structured data; the mesh serves them through the sdk's tool harness.
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
import { MosquittoClient } from "../client.js";
export function getMosquittoTools(mosquitto: MosquittoClient): ToolDefinition[] {
return [
{
name: "mqtt_list_clients",
description: "List the Dynamic Security clients registered on the mosquitto broker.",
input: {},
run: async () => ({ clients: await mosquitto.listClients() }),
},
{
name: "mqtt_get_client",
description: "Show one Dynamic Security client — its roles and enabled state.",
input: { username: { type: "string", description: "the client's username" } },
run: async (args) => {
const username = String(args.username ?? "");
if (!username) throw new Error("mqtt_get_client: username is required");
return { username, detail: await mosquitto.ctl("getClient", username) };
},
},
{
name: "mqtt_ctrl",
description:
"Run an arbitrary 'mosquitto_ctrl dynsec' subcommand, e.g. 'listRoles', 'getRole myrole'. Admin surface.",
input: { command: { type: "string", description: "the dynsec subcommand and its arguments, space-separated" } },
run: async (args) => {
const parts = tokenize(String(args.command ?? ""));
if (parts.length === 0) throw new Error("mqtt_ctrl: empty command");
const output = await mosquitto.ctl(...parts);
return { command: parts.join(" "), output };
},
},
];
}
/** Split a command line into arguments, honouring double-quoted spans. */
function tokenize(command: string): string[] {
const matches = command.match(/(?:[^\s"]+|"[^"]*")+/g) ?? [];
return matches.map((p) => p.replace(/^"|"$/g, ""));
}
// The tools exist only when the broker can be reached from the environment; without it, mosquitto
// contributes none rather than failing the whole tool runtime.
registerModuleTools("mosquitto", (env) => {
try {
return getMosquittoTools(MosquittoClient.fromEnv(env));
} catch {
return [];
}
});