From 0ba52d03a3513f1dbf4a15c6d9f3fdc2bb1677fc Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 23:09:40 +0200 Subject: [PATCH] Two more: nextcloud and home-assistant MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nextcloud is the first consumer of two provisions at once: a database from the mesh's postgres and primary storage in a bucket from the mesh's own object store — which is how the arrangement being replaced ran it, minus the bundled MariaDB it no longer needs. Every credential in one env file the host writes; the manifest holds placeholders and the mesh holds nothing readable. Home automation runs on the machine's own network, because discovering devices is the point and a bridge would hide them — so nothing is published, the declared port is the bound port, and the rule set opens exactly it. The case MachineSide was corrected for, in the catalogue. Both pinned by real digests, resolved on this workstation today. --- examples/modules/home-assistant.json | 37 ++++++++++++++ examples/modules/nextcloud.json | 75 ++++++++++++++++++++++++++++ 2 files changed, 112 insertions(+) create mode 100644 examples/modules/home-assistant.json create mode 100644 examples/modules/nextcloud.json diff --git a/examples/modules/home-assistant.json b/examples/modules/home-assistant.json new file mode 100644 index 0000000..6003229 --- /dev/null +++ b/examples/modules/home-assistant.json @@ -0,0 +1,37 @@ +{ + "module": "home-assistant", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "listens": [ + { + "port": 8123, + "protocol": "tcp", + "from": "mesh", + "why": "the dashboard and the API" + } + ], + "resources": [ + { + "id": "config", + "type": "directory", + "path": "/services/home-assistant/config", + "mode": "0700", + "owner": "1000:1000" + }, + { + "id": "server", + "type": "container", + "name": "home-assistant", + "image": "ghcr.io/home-assistant/home-assistant@sha256:14931c6b13756317849f46da1d01b45937a1150db66c081cfe529d48215943fe", + "network": "host", + "env": { + "TZ": "Etc/UTC" + }, + "volumes": [ + "/services/home-assistant/config:/config" + ] + } + ] +} diff --git a/examples/modules/nextcloud.json b/examples/modules/nextcloud.json new file mode 100644 index 0000000..20faa8d --- /dev/null +++ b/examples/modules/nextcloud.json @@ -0,0 +1,75 @@ +{ + "module": "nextcloud", + "version": "1", + "requires": [ + "postgres-database", + "s3-bucket" + ], + "contributes": { + "postgres-database": { + "name": "nextcloud" + }, + "s3-bucket": { + "bucket": "nextcloud" + } + }, + "binds": { + "postgres-database": "/var/lib/nextcloud-module/database.json", + "s3-bucket": "/var/lib/nextcloud-module/store.json" + }, + "secrets": { + "postgres-database": "/var/lib/nextcloud-module/database.secret", + "s3-bucket": "/var/lib/nextcloud-module/store.secret" + }, + "own-secrets": { + "admin": "/var/lib/nextcloud-module/admin.secret" + }, + "capabilities": [ + "container-runtime" + ], + "listens": [ + { + "port": 80, + "protocol": "tcp", + "from": "mesh", + "why": "files and sync, over http; a public name is a route grant later" + } + ], + "resources": [ + { + "id": "state", + "type": "directory", + "path": "/var/lib/nextcloud-module", + "mode": "0700" + }, + { + "id": "server-env", + "type": "file", + "path": "/var/lib/nextcloud-module/server.env", + "mode": "0600", + "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=nextcloud\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=nextcloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\n" + }, + { + "id": "html", + "type": "directory", + "path": "/services/nextcloud/html", + "mode": "0750", + "owner": "33:33" + }, + { + "id": "server", + "type": "container", + "name": "nextcloud", + "image": "nextcloud@sha256:0b8261f6335af6b95264ce893b4d645857638e0fa151b5ba620f25f377318ae1", + "env-file": [ + "/var/lib/nextcloud-module/server.env" + ], + "ports": [ + "80" + ], + "volumes": [ + "/services/nextcloud/html:/var/www/html" + ] + } + ] +}