Files
mesh-catalog/modules/audit-logger/module.json
T
jschoubben c2c26a29a9 audit-logger: the container names its image directly (a container has no artifact)
A container resource takes a digest-pinned image, not a build artifact — the
host refuses 'artifact' on a container. Verified: the mesh assigns it and the
host runs it in the lab.
2026-09-04 02:13:01 +02:00

38 lines
886 B
JSON

{
"module": "audit-logger",
"version": "1",
"consumes": ["#"],
"own-secrets": {
"broker": "/var/lib/audit-logger/broker"
},
"resources": [
{
"id": "state",
"type": "directory",
"path": "/var/lib/audit-logger",
"mode": "0700"
},
{
"id": "trail",
"type": "directory",
"path": "/var/lib/audit-logger/trail",
"mode": "0700"
},
{
"id": "run",
"type": "container",
"name": "mesh-audit-logger",
"image": "mesh-runtime-audit@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
"/var/lib/audit-logger/trail:/trail"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"AUDIT_LOG": "/trail/audit.log"
}
}
]
}