Files
mesh-catalog/modules/nats/Dockerfile
T
jochen 419e82cded Back up the bus by the server's own snapshot of each stream, not its live files (hq ADR 0235)
The restic holder copied JetStream's store while the server wrote it; such a
copy may not restore. The nats image now carries mesh-nats-snapshot, run by
the declared dump under the module's own bus account (snapshot API only):
every stream one at a time, flow-controlled, into one tar with a manifest of
counts, sequences and checksums. Restore builds a new store beside the live
one with the bus's own server; a person swaps it in. Proven against
throwaway nats 2.11 servers being written to during the snapshot.
2026-10-06 18:20:51 +02:00

48 lines
2.7 KiB
Docker

# nats's server image: the upstream server, plus an entrypoint that reloads it in place when the
# mesh rewrites its configuration. See entrypoint.sh for why that belongs here and not in the host.
#
# **Pinned to the multi-architecture index digest, not a platform's.** `docker manifest inspect`
# reports a platform manifest per architecture and the index that lists them; pinning a platform's
# digest builds on this workstation and fails on any node of another architecture, with an error
# that names a manifest rather than the mistake. This is the index — `docker pull` reports the same
# one, and `RepoDigests` confirms it.
#
# **The release the digest is, said here because a digest does not say it:**
#
# upstream: nats 2.11.17-alpine
#
# Kept equal to the server version cmd/nats-tools tests against (its go.mod), and a test there fails
# when they differ: that test is what says the server delivers every message to a consumer with
# several filters. 2.10.29 did not — it moved such a consumer past a message now and then without
# handing it over, and the controller never heard of a merge (novox/hq issue 266).
#
# Unlike every other module's Dockerfile, this builds no TypeScript and uses no mesh base image:
# the module's code is the server, which upstream already built. There is no BUILD_BASE here on
# purpose — the server is not compiled; only the snapshot program below is. The upstream image is
# declared in the manifest under build.on and arrives as NATS_BASE, like every other base the mesh
# copies into its own store before a build (novox/hq ADR 0097); the digest above is the index one
# for the reason given. So does GO_BASE, the toolchain the snapshot program is built with.
#
# **One thing is compiled: the bus's snapshot program** (novox/hq ADR 0235). The machine's backup
# holder runs the module's declared dump — `docker exec` into this container — and the program asks
# the server for each stream through the snapshot API, writing a tar on stdout. It is here, beside
# the server, for two reasons: the dump runs where the server is without mounting anything into it,
# and a restore needs nats-server itself — the very binary this image already carries — to fill a new
# store. Its own Go module (snapshot/go.mod), so this build fetches only public modules.
ARG NATS_BASE
ARG GO_BASE
FROM ${GO_BASE} AS snapshot
WORKDIR /src
COPY snapshot/go.mod snapshot/go.sum ./
RUN go mod download
COPY snapshot/*.go ./
RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' -o /mesh-nats-snapshot .
FROM ${NATS_BASE}
COPY entrypoint.sh /usr/local/bin/mesh-nats-entrypoint
RUN chmod 0755 /usr/local/bin/mesh-nats-entrypoint
COPY --from=snapshot /mesh-nats-snapshot /usr/local/bin/mesh-nats-snapshot
ENTRYPOINT ["/usr/local/bin/mesh-nats-entrypoint"]