Files
mesh-catalog/modules/verdaccio/client.ts
T
jschoubben 9e156a5b9e Roll out the tool runtime to the remaining tools+events modules (ADR 0052/0051)
Nineteen modules gain a broker-bound runtime container that serves the module's
tools under its own scoped account: bazarr, gitea, grafana, home-assistant,
icecast, influxdb, jackett, keycloak, mailu, nextcloud, nodered, nzbget, ombi,
photos, portainer, qbittorrent, searxng, tautulli, verdaccio.

Config is the assignment's, not the manifest's (ADR 0051): each client's fromEnv
overlays a settings-merged config file (MESH_<M>_CONFIG_FILE) over its env
fallbacks, so URL and credentials come from `settings set`, with the URL defaulting
to the server on the node. nextcloud and mailu also mount the docker socket for
their exec-based tools.

Proven in the mesh-lab: assigned-grafana green — settings deliver the URL and token,
the runtime reads the merged config and serves grafana's tools under the scoped
account, with nothing in the manifest. Two gaps this surfaced are filed as hq
issues 008 (a provider runtime's seal key) and 009 (a settings change does not
restart a container runtime).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-04 23:08:40 +02:00

92 lines
3.2 KiB
TypeScript

// The Verdaccio (npm registry) client — verdaccio's own code, living in the module (novox/hq
// ADR 0044). Both this module's tools and its events entrypoint import it, and nothing outside
// verdaccio does.
import { readFileSync } from "node:fs";
export interface VerdaccioPackage {
name: string;
version?: string;
description?: string;
time?: string;
}
export interface PackageInfo {
name: string;
latest?: string;
versions: string[];
description?: string;
modified?: string;
}
/** The settings-merged config the mesh delivers (novox/hq ADR 0051): { url, apiKey, token, password, user, ... }. */
function meshConfig(file?: string): Record<string, string> {
if (!file) return {};
try { return JSON.parse(readFileSync(file, "utf8")) as Record<string, string>; }
catch { return {}; }
}
export class VerdaccioClient {
readonly baseUrl: string;
// A bearer token is optional: package listing and reading are public on most registries, so the
// token is sent only when configured, for a registry that gates reads behind auth.
constructor(
url: string,
private readonly token?: string,
) {
this.baseUrl = url.replace(/\/+$/, "");
}
/**
* Build from the module's resolved environment. The URL is MESH_VERDACCIO_URL (or the local
* port); an optional MESH_VERDACCIO_TOKEN authenticates. Throws when no URL is configured.
*/
static fromEnv(env: NodeJS.ProcessEnv = process.env): VerdaccioClient {
const cfg = meshConfig(env.MESH_VERDACCIO_CONFIG_FILE);
const url = cfg.url ?? (env.MESH_VERDACCIO_URL ?? `http://127.0.0.1:${env.VERDACCIO_PORT ?? "4873"}`);
if (!url) throw new Error("no verdaccio URL — set MESH_VERDACCIO_URL");
return new VerdaccioClient(url, cfg.token ?? env.MESH_VERDACCIO_TOKEN);
}
private async getJson<T>(path: string): Promise<T> {
const res = await fetch(`${this.baseUrl}${path}`, {
headers: {
Accept: "application/json",
...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
},
});
if (!res.ok) throw new Error(`Verdaccio ${path}: ${res.status} ${await res.text()}`);
return res.json() as Promise<T>;
}
/**
* Every package the registry hosts, from Verdaccio's own web API — the same list its UI shows.
* Each entry carries the latest version and the time it was last published.
*/
async listPackages(): Promise<VerdaccioPackage[]> {
const raw = await this.getJson<any[]>("/-/verdaccio/data/packages");
return (raw ?? []).map((p) => ({
name: p.name,
version: p.version ?? p["dist-tags"]?.latest,
description: p.description,
time: p.time?.modified ?? p.time,
}));
}
/**
* The full detail of one package — its dist-tags, every published version, and timestamps —
* from the standard npm packument endpoint (`GET /<name>`).
*/
async getPackageInfo(name: string): Promise<PackageInfo> {
const doc = await this.getJson<any>(`/${encodeURIComponent(name).replace(/%2F/g, "/")}`);
return {
name: doc.name ?? name,
latest: doc["dist-tags"]?.latest,
versions: Object.keys(doc.versions ?? {}),
description: doc.description,
modified: doc.time?.modified,
};
}
}