Nine references across seven modules named ':latest'. ADR 0006 forbids it and the host refuses it by name — and the refusal had never fired, because the lab pushed every image into its own registry and rewrote each reference to the digest it had just assigned. Deleting that registry made these the only manifests the host would now reject (novox/hq 04-ISSUES/039). The digests are what each tag resolves to today, read from the registry that serves them. This is a stopgap and should be said as one: a digest written into a repository is wrong the moment anybody rebuilds, which is precisely why the design has the repository name artifacts and the mesh hold digests. Until something builds and publishes, a digest that is stale is still better than a tag that silently moves. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
66 lines
1.5 KiB
JSON
66 lines
1.5 KiB
JSON
{
|
|
"module": "de-spiegel",
|
|
"version": "1",
|
|
"slug": "spiegel",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "de-spiegel",
|
|
"port": 35621
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "/var/lib/de-spiegel/route.json"
|
|
},
|
|
"own-secrets": {
|
|
"smtp-user": "/var/lib/de-spiegel/smtp-user.secret",
|
|
"smtp-pass": "/var/lib/de-spiegel/smtp-pass.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 35621,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the de-spiegel site and its /contact endpoint over http; the public name de-spiegel.novox.be is a route grant, and route-proxy reaches it on this published port"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/de-spiegel",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/de-spiegel/server.env",
|
|
"mode": "0600",
|
|
"content": "SMTP_AUTH_USER=${secret:smtp-user}\nSMTP_AUTH_PASS=${secret:smtp-pass}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "de-spiegel"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "de-spiegel",
|
|
"image": "registry-api.novox.be/novox/de-spiegel@sha256:e144b72ce9c145870470d765343549f2c60211728cd118b9ff0e4029f36342ba",
|
|
"network": "de-spiegel",
|
|
"env-file": [
|
|
"/var/lib/de-spiegel/server.env"
|
|
],
|
|
"ports": [
|
|
"35621:35621"
|
|
]
|
|
}
|
|
]
|
|
}
|