Step 1.1 and 1.2 of novox/hq ADR 0116. The server is a built artifact rather than the upstream image directly, because it needs an entrypoint of its own: the host can only recreate a container, and recreating the bus for every permission change drops every connection and every in-flight ack. nats-server reloads on SIGHUP by itself, so the config is mounted as a directory (not digest-tracked, hq issue 103) and the entrypoint watches the one file. Verified against the real server, not assumed: a user added to the config connects, a revoked one is refused, both within one poll interval, with the container's PID and restart count unchanged and "Reloaded: accounts" in its log. Two corrections found by checking rather than reading: - the seat delivers nothing now (hq ADR 0117), and the controller's parser refused the manifest until it did — "nats claims mesh-broker, whose holder answers for amqp, and nats does not provide amqp" - pinned to the multi-arch index digest; the first pin was the amd64 manifest, which builds here and fails on any other architecture
72 lines
1.3 KiB
JSON
72 lines
1.3 KiB
JSON
{
|
|
"module": "nats",
|
|
"version": "1",
|
|
"provides": [],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-broker",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [],
|
|
"consumes": [],
|
|
"listens": [
|
|
{
|
|
"port": 4222,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the mesh bus \u2014 every link the mesh has, over TLS, reached across the overlay"
|
|
}
|
|
],
|
|
"guards": [
|
|
8222
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "jetstream-data",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-broker-nats",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "conf-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/nats-module/conf",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-broker-nats",
|
|
"ports": [
|
|
"4222:4222",
|
|
"127.0.0.1:8222:8222"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-nats:/data",
|
|
"/var/lib/nats-module/conf:/etc/nats:ro",
|
|
"/var/lib/mesh-broker-nats-tls:/tls:ro"
|
|
],
|
|
"artifact": "server"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-nats-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|