dnsmasq still required resolver-data, a provision that died with the mesh-resolver module — assigning it would refuse with "nothing provides resolver-data". It asks for the node-zones fact now, at the same path its config already reads, restarting on the fact's own id. gitea and verdaccio both provide package-registry now — ADR 0075's provision, which neither declared, so ADR 0014's "consumes from the private registry" had no provider anywhere in the catalogue. Two providers, mesh-scoped: the resolver refuses until one is assigned, and choosing is assigning, which is the designed shape. audit-logger runs a container and declared no capability, alone among the containerised modules. A machine without a runtime would have been assigned it and failed at apply rather than at assignment. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
65 lines
1.2 KiB
JSON
65 lines
1.2 KiB
JSON
{
|
|
"module": "audit-logger",
|
|
"version": "1",
|
|
"slug": "audit",
|
|
"consumes": [
|
|
"#"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/audit-logger/broker"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/audit-logger",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "trail",
|
|
"type": "directory",
|
|
"path": "/var/lib/audit-logger/trail",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "run",
|
|
"type": "container",
|
|
"name": "mesh-audit-logger",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
|
|
"/var/lib/audit-logger/trail:/trail"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"AUDIT_LOG": "/trail/audit.log"
|
|
},
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
]
|
|
}
|