Files
mesh-catalog/modules/umami/module.json
T
jschoubben facd41806d Five modules keep their own secrets from the vault, under local names; route-proxy declares its bases
gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs
under a local name (novox/hq ADR 0094); the broker account stays their own. The
route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
2026-09-21 22:16:10 +02:00

153 lines
3.7 KiB
JSON

{
"module": "umami",
"version": "1",
"capabilities": [
"container-runtime"
],
"requires": [
"postgres-database",
"route",
"secret"
],
"contributes": {
"postgres-database": {
"name": "umami"
},
"route": {
"label": "umami",
"port": 3000
}
},
"binds": {
"postgres-database": "/var/lib/umami/database.json",
"route": "/var/lib/umami/route.json"
},
"secrets": {
"postgres-database": "/var/lib/umami/database.secret",
"secret": {
"app-secret": "/var/lib/umami/app.secret",
"admin": "/var/lib/umami/admin.secret"
}
},
"provides": [
{
"name": "analytics",
"scope": "mesh"
}
],
"serves": {
"analytics": {}
},
"receives": {
"analytics": "/var/lib/umami/grants/mesh.json"
},
"grants": {
"analytics": "/var/lib/umami/grants"
},
"own-secrets": {
"broker": "/var/lib/mesh/umami/broker"
},
"listens": [
{
"port": 3000,
"protocol": "tcp",
"from": "anywhere",
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to \u2014 so the port itself must be reachable from anywhere"
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"path": "/var/lib/mesh/umami",
"mode": "0700"
},
{
"id": "state",
"type": "directory",
"path": "/var/lib/umami",
"mode": "0700"
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/umami/grants",
"mode": "0700"
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/umami/server.env",
"mode": "0600",
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
},
{
"id": "provisioner-env",
"type": "file",
"path": "/var/lib/umami/provisioner.env",
"mode": "0600",
"content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=/var/lib/umami/grants\n"
},
{
"id": "net",
"type": "network",
"name": "umami"
},
{
"id": "server",
"type": "container",
"name": "umami",
"image": "ghcr.io/umami-software/umami@sha256:fa32d116cf20cad52cbc3fad9a63b46e7fa02299d8f967168eb453d49c476b4a",
"network": "umami",
"env-file": [
"/var/lib/umami/server.env"
],
"ports": [
"3000"
],
"secrets-in-environment": "a Next.js/Prisma application: DATABASE_URL and APP_SECRET are read from the environment only; not convertible"
},
{
"id": "runtime",
"type": "container",
"name": "mesh-umami",
"network": "umami",
"volumes": [
"/var/lib/mesh/umami/broker:/run/secrets/broker:ro",
"/var/lib/umami/grants:/var/lib/umami/grants",
"/var/lib/umami/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
},
"env-file": [
"/var/lib/umami/provisioner.env"
],
"artifact": "runtime"
}
],
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
}
}