hq issue 091, measured 2026-09-22: 14 of 46 modules with containers fix the machine side of a published port in their own manifest -- a fact about one machine (which port HAL happened to publish it on) written into a definition meant for any node. ADR 0038 already says the mesh assigns the machine side and a module says only what it needs; the machinery already does it (internal/inventory/ports.go's PortFor, declaration.go's publishedOn rewrites a bare port automatically). These 14 just never complied. Fixed 11 of them -- stripped to the bare software port, letting assignment take over: de-spiegel, gitea, hello-web (the demo module), mailu, mssql, n8n, novox.be, only-office, photos, photos-eef, photos-filip. Left alone, the two defensible kinds the issue names: postgres/lavinmq/ distribution (foundation, genesis-rewritten per ADR 0100 -- the number in the manifest is a default, not a claim) and unifi (protocol/ device-discovery fixes the number; nothing else can find the controller). gitea was a live one, not just a tidiness fix: its manifest said 2222:22, but the actual adopted, running container is on 222. Harmless while held, but the next 'take' would have recreated it on the wrong port and broken SSH git access. Recorded 222 as novox's own setting for it (settings set gitea -node novox) so that doesn't happen.
92 lines
2.7 KiB
JSON
92 lines
2.7 KiB
JSON
{
|
|
"module": "photos",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"s3-bucket",
|
|
"mongodb-database",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"s3-bucket": {
|
|
"bucket": "photos"
|
|
},
|
|
"mongodb-database": {
|
|
"name": "photos"
|
|
},
|
|
"route": {
|
|
"label": "photos",
|
|
"port": 4001
|
|
}
|
|
},
|
|
"binds": {
|
|
"s3-bucket": "/var/lib/photos/store.json",
|
|
"mongodb-database": "/var/lib/photos/database.json",
|
|
"route": "/var/lib/photos/route.json"
|
|
},
|
|
"secrets": {
|
|
"s3-bucket": "/var/lib/photos/store.secret",
|
|
"mongodb-database": "/var/lib/photos/database.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the photos backend API; the client sites on the module network call it"
|
|
},
|
|
{
|
|
"port": 4001,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the admin client site over http; the public name photos.novox.be is a route grant, and route-proxy reaches it on this published port"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/photos",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/photos/server.env",
|
|
"mode": "0600",
|
|
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=admin\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_BUCKET=photos\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\nMINIO_USE_SSL=false\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "photos"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "photos-server",
|
|
"image": "registry-api.novox.be/novox/photos-server@sha256:3f165acbbd1fd731b12fe798c95879c081a44b00e2c569ef7f47165f6a527201",
|
|
"network": "photos",
|
|
"env-file": [
|
|
"/var/lib/photos/server.env"
|
|
],
|
|
"ports": [
|
|
"9000"
|
|
],
|
|
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (photos server/src/config.js); converting is that repository's change"
|
|
},
|
|
{
|
|
"id": "admin-client",
|
|
"type": "container",
|
|
"name": "photos-admin-client",
|
|
"image": "registry-api.novox.be/novox/photos-admin-client@sha256:f437fa9ed28b29a012f715fb8d9b809a15cff4a672794c620d5d400f57695580",
|
|
"network": "photos",
|
|
"ports": [
|
|
"80"
|
|
]
|
|
}
|
|
]
|
|
}
|