Backup lines are derived from each module's data section instead of written by hand; the holder measures declared items, reads the array under them, and deletes a retired item only after a last restore point; the Go providers say each held consumer's size so an empty replacement is seen.
177 lines
3.7 KiB
JSON
177 lines
3.7 KiB
JSON
{
|
|
"module": "minio",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "s3-bucket",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 20,
|
|
"in": "an S3 access key"
|
|
}
|
|
}
|
|
],
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"api": {
|
|
"label": "files-api",
|
|
"endpoint": "s3"
|
|
},
|
|
"console": {
|
|
"label": "files",
|
|
"endpoint": "console"
|
|
}
|
|
}
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"bucket.created",
|
|
"bucket.removed"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "s3",
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the S3 endpoint"
|
|
},
|
|
{
|
|
"name": "console",
|
|
"port": 9001,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the admin console"
|
|
}
|
|
],
|
|
"serves": {
|
|
"s3-bucket": {
|
|
"scheme": "http",
|
|
"region": "eu-west",
|
|
"port": 9000,
|
|
"bucket": "${consumer:as:dns}"
|
|
}
|
|
},
|
|
"receives": {
|
|
"s3-bucket": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"s3-bucket": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"root": "${dir:state}/root.secret"
|
|
},
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "data",
|
|
"path": "${dir:data}",
|
|
"class": "valuable",
|
|
"why": "every consumer's bucket and its objects"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"s3-bucket": {
|
|
"class": "valuable",
|
|
"in": "data",
|
|
"why": "a consumer's objects are the only copy of what it stored; a consumer that keeps something irreplaceable here says so (kept-by)"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "root-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/root.env",
|
|
"mode": "0600",
|
|
"content": "MINIO_ROOT_USER=meshroot\nMINIO_BROWSER_REDIRECT_URL=https://${bound:route:name-console}\n"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/var/lib/minio-store",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "minio-net"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "minio",
|
|
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372",
|
|
"network": "minio-net",
|
|
"args": [
|
|
"server",
|
|
"/data",
|
|
"--console-address",
|
|
":9001"
|
|
],
|
|
"env-file": [
|
|
"${dir:state}/root.env"
|
|
],
|
|
"ports": [
|
|
"9000",
|
|
"9001"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/minio-store:/data",
|
|
"${dir:state}/root.secret:/run/secrets/root:ro"
|
|
],
|
|
"env": {
|
|
"MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
|
"MINIO_REGION": "eu-west"
|
|
}
|
|
},
|
|
{
|
|
"id": "client",
|
|
"type": "package",
|
|
"package": "minio-client"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_MINIO_ENDPOINT": "http://127.0.0.1:${port:9000}",
|
|
"MESH_MINIO_ROOT_USER": "meshroot",
|
|
"MESH_MINIO_ROOT_PASSWORD_FILE": "${dir:state}/root.secret",
|
|
"MESH_MINIO_REGION": "eu-west",
|
|
"MESH_MINIO_MC_BIN": "mcli",
|
|
"MESH_MINIO_MC_CONFIG": "${dir:state}/mc",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|