Now a real assigned module, not just a handler: consumes '#', declares its
broker own-secret, and runs the runtime image as a container that mounts the
sealed credential and its trail. own-secrets:{broker} is the file the mesh
seals it (module issue); the container reads MESH_BROKER_FILE from the mount
and takes its node/module identity from the credential. Parses against the
catalogue schema.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
47 lines
1.0 KiB
JSON
47 lines
1.0 KiB
JSON
{
|
|
"module": "audit-logger",
|
|
"version": "1",
|
|
"consumes": ["#"],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/audit-logger/broker"
|
|
},
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "upstream",
|
|
"from": "registry.invalid/mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000"
|
|
}
|
|
]
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/audit-logger",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "trail",
|
|
"type": "directory",
|
|
"path": "/var/lib/audit-logger/trail",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "run",
|
|
"type": "container",
|
|
"name": "mesh-audit-logger",
|
|
"artifact": "runtime",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
|
|
"/var/lib/audit-logger/trail:/trail"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"AUDIT_LOG": "/trail/audit.log"
|
|
}
|
|
}
|
|
]
|
|
}
|