Compose a process's environment as a container's
A module's own code moving out of its container (novox/hq to-be 38 WP4c)
becomes a process on the machine, and still has to be told what its
container was: the port this machine gave the module and where the
foundation's seats are. ${port:…} and ${seat:…} were filled only in a
file's content and a container's env, so in a process's env they reached
the machine as literals, and the modules that moved first (mesh-catalog
#245) wrote their run-once steps a 0600 env file instead. A process's env
now takes the same resolution and the same refusals; ${dir:…} and
${access:…} already did, and a bundle's env (ADR 0192) already resolves
${dir:…} and ${port:…}.
This commit is contained in:
@@ -31,7 +31,7 @@ import (
|
||||
//
|
||||
// So a module asks. `${port:8080}` is "the machine-side port you gave me for the 8080 I said I
|
||||
// listen on", and the module writes that where it would otherwise have written a literal — in a
|
||||
// file's content, or in a value of a container's `env`.
|
||||
// file's content, or in a value of a container's or a process's `env`.
|
||||
//
|
||||
// **The environment is filled by the control plane, exactly as a bound value is.** A port is not
|
||||
// secret — the mesh holds it in the clear — so there is nothing for the host to be the only
|
||||
@@ -64,7 +64,12 @@ func portsUsed(content string) []int {
|
||||
}
|
||||
|
||||
// portInto replaces a resource's ${port:…} placeholders with what this machine assigned — in a
|
||||
// file's content, and in a value of a container's environment.
|
||||
// file's content, and in a value of a container's or a process's environment.
|
||||
//
|
||||
// **A process's environment is a container's** (novox/hq to-be 38 WP4c). A module's code moving out
|
||||
// of its container becomes a process on the machine and still has to be told what the container
|
||||
// was told; filled for one kind and not the other, the literal reached the process and was read as
|
||||
// a port, and the modules that moved first wrote their run-once steps a 0600 env file instead.
|
||||
//
|
||||
// A port the module did not say it listens on is refused, for the same reason a binding's unknown
|
||||
// key is: the module is asking about something it never declared, and the answer would be a guess.
|
||||
@@ -84,7 +89,7 @@ func portInto(resource map[string]any, module string, listens []Listening, with
|
||||
}
|
||||
resource["content"] = filled
|
||||
|
||||
case "container":
|
||||
case "container", "process":
|
||||
env, ok := resource["env"].(map[string]any)
|
||||
if !ok {
|
||||
return nil
|
||||
@@ -106,8 +111,8 @@ func portInto(resource map[string]any, module string, listens []Listening, with
|
||||
continue
|
||||
}
|
||||
value, err := portsFilledInto(written,
|
||||
fmt.Sprintf("%s's container %s sets %s to something that",
|
||||
module, resource["name"], key), module, listens, with)
|
||||
fmt.Sprintf("%s's %s %s sets %s to something that",
|
||||
module, resource["type"], resource["name"], key), module, listens, with)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user