From 3a08789d3c5c3caed7d28c8ff5312ba2c8d3687d Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 03:27:10 +0200 Subject: [PATCH] The control plane's declaration lives with the control plane A module is a repository and a path within it, and the manifest sits at that path. This one sat in the catalogue instead, so the thing that says what the control plane is and the thing it is made of lived in different repositories and could drift apart with nothing to notice. It also names an artifact it builds rather than a placeholder digest somebody fills in, which is what lets the mesh build its own control plane. --- module.json | 68 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 68 insertions(+) create mode 100644 module.json diff --git a/module.json b/module.json new file mode 100644 index 0000000..a6b7c36 --- /dev/null +++ b/module.json @@ -0,0 +1,68 @@ +{ + "module": "mesh-control", + "version": "1", + "slug": "control", + "capabilities": [ + "container-runtime" + ], + "claims": [ + { + "name": "the-control-plane", + "scope": "mesh" + } + ], + "own-secrets": { + "inventory": "/var/lib/mesh/mesh-control/inventory", + "identity": "/var/lib/mesh/mesh-control/identity", + "licences": "/var/lib/mesh/mesh-control/licences", + "broker": "/var/lib/mesh/mesh-control/broker", + "broker-management": "/var/lib/mesh/mesh-control/broker-management", + "broker-address": "/var/lib/mesh/mesh-control/broker-address" + }, + "resources": [ + { + "id": "mesh-state", + "type": "directory", + "path": "/var/lib/mesh/mesh-control", + "mode": "0700" + }, + { + "id": "control-env", + "type": "file", + "path": "/var/lib/mesh/mesh-control/control.env", + "mode": "0600", + "content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${secret:broker-address}\n" + }, + { + "id": "server", + "type": "container", + "name": "mesh-control", + "network": "host", + "args": [ + "serve" + ], + "env-file": [ + "/var/lib/mesh/mesh-control/control.env" + ], + "env": { + "MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt" + }, + "volumes": [ + "mesh-broker-tls:/broker-tls:ro" + ], + "restart-on": [ + "control-env" + ], + "artifact": "server" + } + ], + "build": { + "artifacts": [ + { + "name": "server", + "kind": "image", + "from": "Dockerfile" + } + ] + } +}