ombi keeps its Servarr connections in its own database, so the mesh has no file to write them into. A run-once step reads the three bindings and pair credentials and writes host, port, TLS, base path and key into ombi through ombi's own API - only when they differ, and nothing else ombi keeps. Until the operator accepts an app's key for this pair the mesh delivers a value it minted, which no Servarr app accepts. The step tries the key against the app first and, refused, writes nothing and fails naming the secret accept that fixes it, so the old working key in ombi is never replaced by a dead one. Declared last so its failing gates nothing else of ombi (ADR 0136), and restart-on its six inputs so it runs again when a provider moves (ADR 0099).
28 lines
1.5 KiB
Docker
28 lines
1.5 KiB
Docker
# ombi's runtime: the tool runtime, carrying this module's compiled code.
|
|
#
|
|
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
|
|
# the base images, published like any other artifact — which is what makes this buildable by the
|
|
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
|
|
# happens to have the siblings.
|
|
#
|
|
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
|
|
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
WORKDIR /app/modules/ombi
|
|
COPY . .
|
|
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts servarr/settings.ts servarr/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
COPY --from=build /app/modules/ombi/dist /app/modules/ombi/dist
|
|
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
|
# the convention novox/hq issues 060/061 settled.
|
|
ENV MESH_TOOL_MODULES=/app/modules/ombi/dist/index.js,/app/modules/ombi/dist/tools/index.js
|
|
# NOT dist/servarr/index.js: that is a step the host runs to completion, named by the `servarr`
|
|
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
|
# serving sidecar too, and exit it.
|