Consumers were held to an S3 access key's 20 characters whatever they required. Each provider now says what its backend keeps: minio 20, PostgreSQL and MongoDB and DNS 63, Gitea 40, a mailbox 64, SQL Server 128, Keycloak 255, unbounded where the store has no limit, and none for the resolver and route provisions, which keep no name of their consumers. Needs the controller that reads the field (mesh-controller, ADR 0225).
134 lines
3.1 KiB
JSON
134 lines
3.1 KiB
JSON
{
|
|
"module": "mongodb",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "mongodb-database",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 63,
|
|
"in": "a MongoDB database name"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"database.provisioned",
|
|
"database.deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mongodb.database.provisioned",
|
|
"mongodb.database.deprovisioned"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "database",
|
|
"port": 27017,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a database"
|
|
}
|
|
],
|
|
"serves": {
|
|
"mongodb-database": {
|
|
"port": 27017
|
|
}
|
|
},
|
|
"receives": {
|
|
"mongodb-database": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"mongodb-database": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"root": "${dir:state}/root.secret"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "dumps",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "mongodb"
|
|
},
|
|
{
|
|
"id": "server-root",
|
|
"type": "file",
|
|
"path": "${dir:state}/server-root.secret",
|
|
"mode": "0400",
|
|
"owner": "999:999",
|
|
"content": "${secret:root}"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mongodb-server",
|
|
"image": "mongo@sha256:e3fa459b4f4b72f3257c67a23c145e250b8b5700f033860392c68539b998bbe3",
|
|
"network": "mongodb",
|
|
"env": {
|
|
"MONGO_INITDB_ROOT_USERNAME": "root",
|
|
"MONGO_INITDB_ROOT_PASSWORD_FILE": "/run/secrets/root"
|
|
},
|
|
"ports": [
|
|
"27017"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/data/db",
|
|
"${dir:state}/server-root.secret:/run/secrets/root:ro"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_PROVISION_MONGODB": "mongodb://root@127.0.0.1:${port:27017}/admin?authSource=admin",
|
|
"MESH_PROVISION_PASSWORD_FILE": "${dir:state}/root.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"contributions": [
|
|
{
|
|
"seat": "node-backup",
|
|
"kind": "backup",
|
|
"content": "run docker exec mongodb-server sh -c 'printf \"password: %s\\n\" \"$(cat /run/secrets/root)\" > /tmp/.backup.yaml && mongodump --quiet --config /tmp/.backup.yaml --username root --authenticationDatabase admin --archive; s=$?; rm -f /tmp/.backup.yaml; exit $s' > ${dir:dumps}/all.archive.partial && mv ${dir:dumps}/all.archive.partial ${dir:dumps}/all.archive\npath ${dir:dumps}\n"
|
|
}
|
|
]
|
|
}
|