mesh/merge-gate pass: builds baserow, grafana, mailu, matrix, mongodb, mosquitto, nodered, postgres, redis, step-ca, supabase, website → ace, novox; no bus…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-first-declarations delivered: every member is delivered
Seven modules' images ship a check the mesh never read. Adopted by name where it says healthy on the live mesh today: nine of mail's containers (not its antivirus, whose six-minute start is past the five-minute bound, nor its cache, whose image ships none), the certificate authority, the spreadsheet app, four of the database suite's (the studio among them, with the address it binds fixed), the flow editor and the chat client. And the endpoints four services already declare, looked at from the machine: tcp on the database, the cache, the document store and the broker; http on the website and the dashboards. The count of undeclared falls from 93 to 70.
181 lines
5.7 KiB
JSON
181 lines
5.7 KiB
JSON
{
|
|
"module": "grafana",
|
|
"version": "1",
|
|
"emits": [
|
|
"alert.firing"
|
|
],
|
|
"own-secrets": {
|
|
"admin": "${dir:mesh-state}/admin"
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the dashboards. Also 3000 inside, like the forge - which is the mesh's port assignment earning its keep"
|
|
}
|
|
],
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "data",
|
|
"path": "${dir:data}",
|
|
"class": "valuable",
|
|
"why": "dashboards, users and alert rules"
|
|
}
|
|
]
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "472:472"
|
|
},
|
|
{
|
|
"id": "admin-secret",
|
|
"type": "file",
|
|
"path": "${dir:state}/admin.secret",
|
|
"mode": "0400",
|
|
"owner": "472:472",
|
|
"content": "${secret:admin}"
|
|
},
|
|
{
|
|
"id": "oidc-secret",
|
|
"type": "file",
|
|
"path": "${dir:state}/oidc-client.secret",
|
|
"mode": "0400",
|
|
"owner": "472:472",
|
|
"content": "${secret:oidc-client}"
|
|
},
|
|
{
|
|
"id": "oidc-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/oidc.env",
|
|
"mode": "0644",
|
|
"content": "GF_SERVER_ROOT_URL=https://${bound:route:name}\nGF_AUTH_GENERIC_OAUTH_ENABLED=true\nGF_AUTH_GENERIC_OAUTH_NAME=Keycloak\nGF_AUTH_GENERIC_OAUTH_CLIENT_ID=${bound:oidc-client:as}\nGF_AUTH_GENERIC_OAUTH_CLIENT_SECRET__FILE=/run/secrets/oidc-client\nGF_AUTH_GENERIC_OAUTH_SCOPES=openid email profile roles\nGF_AUTH_GENERIC_OAUTH_AUTH_URL=${bound:oidc-client:issuer}${bound:oidc-client:authorization-path}\nGF_AUTH_GENERIC_OAUTH_TOKEN_URL=${bound:oidc-client:issuer}${bound:oidc-client:token-path}\nGF_AUTH_GENERIC_OAUTH_API_URL=${bound:oidc-client:issuer}${bound:oidc-client:userinfo-path}\nGF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=contains(roles[*], 'admin') && 'Admin' || contains(realm_access.roles[*], 'admin') && 'Admin' || 'Viewer'\nGF_AUTH_GENERIC_OAUTH_USE_PKCE=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true\n"
|
|
},
|
|
{
|
|
"id": "influxdb-secret",
|
|
"type": "file",
|
|
"path": "${dir:state}/influxdb-api.secret",
|
|
"mode": "0400",
|
|
"owner": "472:472",
|
|
"content": "${secret:influxdb-api}"
|
|
},
|
|
{
|
|
"id": "influxdb-datasource",
|
|
"type": "file",
|
|
"path": "${dir:state}/datasource-influxdb.yaml",
|
|
"mode": "0644",
|
|
"content": "apiVersion: 1\n# Written by the mesh from grafana's influxdb-api binding; grafana reads it at start. Its own name and\n# uid, so a data source somebody made in the UI is never overwritten, and read-only in the UI because\n# the mesh resets it. The password is read from the file the mesh delivers, never written here.\ndatasources:\n - name: InfluxDB (mesh)\n uid: mesh-influxdb-api\n type: influxdb\n access: proxy\n url: ${bound:influxdb-api:scheme}://${bound:influxdb-api:at}:${bound:influxdb-api:port}\n user: ${bound:influxdb-api:as}\n isDefault: false\n editable: false\n jsonData:\n dbName: ${bound:influxdb-api:bucket}\n httpMode: POST\n secureJsonData:\n password: $__file{/run/secrets/influxdb-api}\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "grafana",
|
|
"image": "grafana/grafana@sha256:ac461fb352abc50da10a51c7d02462e9c05488f11f53f14b3ad79a8145f638a0",
|
|
"health": {
|
|
"kind": "http",
|
|
"endpoint": "web",
|
|
"path": "/"
|
|
},
|
|
"ports": [
|
|
"3000"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/var/lib/grafana",
|
|
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
|
"${dir:state}/oidc-client.secret:/run/secrets/oidc-client:ro",
|
|
"${dir:state}/influxdb-api.secret:/run/secrets/influxdb-api:ro",
|
|
"${dir:state}/datasource-influxdb.yaml:/etc/grafana/provisioning/datasources/mesh-influxdb.yaml:ro"
|
|
],
|
|
"env": {
|
|
"GF_SECURITY_ADMIN_PASSWORD__FILE": "/run/secrets/admin"
|
|
},
|
|
"env-file": [
|
|
"${dir:state}/oidc.env"
|
|
],
|
|
"restart-on": [
|
|
"oidc-env",
|
|
"oidc-secret",
|
|
"influxdb-datasource",
|
|
"influxdb-secret"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{\n \"user\": \"admin\",\n \"password\": \"${secret:admin}\"\n}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"requires": [
|
|
"route",
|
|
"oidc-client",
|
|
"influxdb-api"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "grafana",
|
|
"endpoint": "web"
|
|
},
|
|
"oidc-client": {
|
|
"label": "grafana",
|
|
"endpoint": "web",
|
|
"callback": "/login/generic_oauth"
|
|
},
|
|
"influxdb-api": {
|
|
"access": "read"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json",
|
|
"oidc-client": "${dir:state}/oidc.json",
|
|
"influxdb-api": "${dir:state}/influxdb.json"
|
|
},
|
|
"secrets": {
|
|
"oidc-client": "${dir:mesh-state}/oidc-client",
|
|
"influxdb-api": "${dir:mesh-state}/influxdb-api"
|
|
},
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_GRAFANA_URL": "http://127.0.0.1:${port:3000}",
|
|
"MESH_GRAFANA_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|