Port the HAL confluence and jira integrations to the tools-only, outbound-only external-SaaS pattern proven by the merged gitlab module: runtime-only containers (container-runtime capability), own-secret token + broker, a settings-managed config.json for public config, and a per-module runtime image. Each module carries its own Atlassian API client and tools (ADR 0039), translated from HAL's @hal/sdk zod-schema/MCP-content shape into mesh-sdk's input/run-returns-data shape. Public config (ATLASSIAN_URL, ATLASSIAN_EMAIL) lives in config.json; the API token is the one own-secret. Clients are built lazily and never throw at registration, so each runtime serves its full tool surface with no credentials (the Servarr lesson) — confluence serves 3 tools, jira serves 8. jira's periodic ticket-poller (update-tickets.service/.timer) is NOT ported: the mesh has no scheduled-task primitive yet (a pending decision). Only jira's tools are ported; a top-of-file note records the deferral. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
51 lines
1.3 KiB
JSON
51 lines
1.3 KiB
JSON
{
|
|
"module": "confluence",
|
|
"version": "1",
|
|
"own-secrets": {
|
|
"token": "/var/lib/confluence/token",
|
|
"broker": "/var/lib/mesh/confluence/broker"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/confluence",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/confluence",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/var/lib/confluence/config.json",
|
|
"merge": "json",
|
|
"content": "{}",
|
|
"mode": "0600"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-runtime-confluence",
|
|
"image": "mesh-runtime-confluence@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/confluence/config.json:/run/config/config.json:ro",
|
|
"/var/lib/confluence/token:/run/secrets/token:ro",
|
|
"/var/lib/mesh/confluence/broker:/run/secrets/broker:ro"
|
|
],
|
|
"env": {
|
|
"MESH_CONFLUENCE_TOKEN_FILE": "/run/secrets/token",
|
|
"MESH_CONFLUENCE_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_BROKER_FILE": "/run/secrets/broker"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
]
|
|
}
|