Run the controller as a Go bundle the host starts as a process (hq issue 213)
The controller is a Go program and was the one piece of the mesh's own Go code still shipped and run as an image (novox/hq issue 213; ADR 0188 §1: a module's own code is bundles; §3: a service bundle is a process). The manifest now builds one Go bundle, `controller`, and runs it as the process `mesh-controller` (`./mesh-controller serve`) under an account the module declares. What the container gave it, replaced: - host network: a process is on the host's network; nothing it reads names a container network - user 65534: the account `mesh-controller`, which owns its secrets and its state directory - the eight mounts: the env names the host paths the mesh already places (the store, broker and bus files under the state directory, the broker's certificate under /var/lib/mesh-broker-tls); the `broker` mount was read by nothing and is gone with the others - `container-runtime` is no longer required on its machine Its preparation is the same binary with `prepare`, as a run-once process, and the process `replaces` the container `server`: the host keeps the container answering until the process is running (mesh-host). Needs the previous commit live in the running controller, and the host's `replaces` on the controller's machine, before it is registered. No image is built by the mesh any more. The Dockerfile stays for genesis and the lab (`make image`, its Go base now pinned in the Makefile).
This commit is contained in:
+31
-38
@@ -2,9 +2,6 @@
|
||||
"module": "mesh-controller",
|
||||
"version": "1",
|
||||
"slug": "control",
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
"claims": [
|
||||
{
|
||||
"name": "mesh-controller",
|
||||
@@ -26,7 +23,7 @@
|
||||
"broker-address": "${dir:mesh-state}/broker-address",
|
||||
"bus": "${dir:mesh-state}/bus"
|
||||
},
|
||||
"secrets-owner": "65534:65534",
|
||||
"secrets-owner": "mesh-controller",
|
||||
"prepares": true,
|
||||
"tools": [
|
||||
"tools",
|
||||
@@ -43,62 +40,58 @@
|
||||
"build"
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "account",
|
||||
"type": "user",
|
||||
"name": "mesh-controller",
|
||||
"shell": "/usr/bin/nologin",
|
||||
"home": "/var/lib/mesh-controller"
|
||||
},
|
||||
{
|
||||
"id": "mesh-state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "mesh"
|
||||
"place": "mesh",
|
||||
"owner": "mesh-controller"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"id": "controller",
|
||||
"type": "process",
|
||||
"name": "mesh-controller",
|
||||
"network": "host",
|
||||
"args": [
|
||||
"artifact": "controller",
|
||||
"run": [
|
||||
"./mesh-controller",
|
||||
"serve"
|
||||
],
|
||||
"user": "mesh-controller",
|
||||
"env": {
|
||||
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
|
||||
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
||||
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
||||
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
||||
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
||||
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
||||
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
|
||||
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
|
||||
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
|
||||
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
|
||||
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
|
||||
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
|
||||
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
||||
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
||||
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
||||
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
||||
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
||||
"MESH_BUS_NATS_FILE": "/run/secrets/bus"
|
||||
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus"
|
||||
},
|
||||
"volumes": [
|
||||
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
||||
"${dir:mesh-state}/inventory:/run/secrets/inventory:ro",
|
||||
"${dir:mesh-state}/identity:/run/secrets/identity:ro",
|
||||
"${dir:mesh-state}/licences:/run/secrets/licences:ro",
|
||||
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
||||
"${dir:mesh-state}/bus:/run/secrets/bus:ro",
|
||||
"${dir:mesh-state}/broker-management:/run/secrets/broker-management:ro",
|
||||
"${dir:mesh-state}/broker-address:/run/secrets/broker-address:ro"
|
||||
],
|
||||
"artifact": "server",
|
||||
"restart-on": [
|
||||
"control-env"
|
||||
"replaces": [
|
||||
"server"
|
||||
]
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
"artifacts": [
|
||||
{
|
||||
"name": "server",
|
||||
"kind": "image",
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
],
|
||||
"on": [
|
||||
{
|
||||
"arg": "GO_BASE",
|
||||
"image": "golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
|
||||
"name": "controller",
|
||||
"kind": "bundle",
|
||||
"language": "go",
|
||||
"system": "arch",
|
||||
"from": "cmd/mesh-controller",
|
||||
"binary": "mesh-controller"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user