The vault's claim makes a second provider of secret a second claimant, refused by name. The three uplink definitions declare uplink-networkmanager, uplink-systemd-networkd and uplink-dhcpcd, which the host reports for the manager it finds active, so the holder for a manager the machine does not run is refused the way any missing capability is. Merges after the controller holds the seat and the host reports the capability.
109 lines
2.1 KiB
JSON
109 lines
2.1 KiB
JSON
{
|
|
"module": "mesh-vault",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "secret",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"secret.provisioned",
|
|
"secret.rotated",
|
|
"secret.deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mesh-vault.secret.provisioned",
|
|
"mesh-vault.secret.rotated",
|
|
"mesh-vault.secret.deprovisioned"
|
|
],
|
|
"receives": {
|
|
"secret": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"secret": "${dir:grants}"
|
|
},
|
|
"keeps": "/var/lib/mesh-vault/root",
|
|
"own-secrets": {
|
|
"broker": "${dir:mesh-state}/broker"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "ledger",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "root",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-vault",
|
|
"network": "host",
|
|
"volumes": [
|
|
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
"${dir:grants}:${dir:grants}:ro",
|
|
"${dir:ledger}:${dir:ledger}",
|
|
"${dir:root}:${dir:root}:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_VAULT_LEDGER": "${dir:ledger}",
|
|
"MESH_VAULT_ROOT": "${dir:root}"
|
|
},
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "mesh-vault",
|
|
"scope": "mesh"
|
|
}
|
|
]
|
|
}
|