From d278edabe0df054a039d4a0b88cd34167ff6540d Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 2 Sep 2026 02:08:33 +0200 Subject: [PATCH] Three more: nodered, icecast, portainer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Node-RED and Icecast are the plain shapes — a data directory owned by the number inside, generated passwords in a host-written env file, one declared port each. Portainer mounts the container runtime's socket, which is the mount 04-ISSUES/026 is reopened about: a machine facility, not the module's data, spelled today exactly like a data directory. It is converted as it runs now rather than held hostage to that vocabulary — the same mount the builder already carries — and it will be the second citation when 026 gets its answer. Letta stays unconverted for now: the arrangement being replaced pins a year-old image of a fast-moving project, and converting a pin nobody would keep is not fidelity. It wants a fresh look at what version to run, which is a decision and not a translation. All pinned by real digests, resolved on this workstation today. --- examples/modules/icecast.json | 47 +++++++++++++++++++++++++++++++++ examples/modules/nodered.json | 39 +++++++++++++++++++++++++++ examples/modules/portainer.json | 36 +++++++++++++++++++++++++ 3 files changed, 122 insertions(+) create mode 100644 examples/modules/icecast.json create mode 100644 examples/modules/nodered.json create mode 100644 examples/modules/portainer.json diff --git a/examples/modules/icecast.json b/examples/modules/icecast.json new file mode 100644 index 0000000..77d208e --- /dev/null +++ b/examples/modules/icecast.json @@ -0,0 +1,47 @@ +{ + "module": "icecast", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "own-secrets": { + "source": "/var/lib/icecast-module/source.secret", + "admin": "/var/lib/icecast-module/admin.secret", + "relay": "/var/lib/icecast-module/relay.secret" + }, + "listens": [ + { + "port": 8000, + "protocol": "tcp", + "from": "mesh", + "why": "streams in from sources and out to listeners" + } + ], + "resources": [ + { + "id": "state", + "type": "directory", + "path": "/var/lib/icecast-module", + "mode": "0700" + }, + { + "id": "server-env", + "type": "file", + "path": "/var/lib/icecast-module/server.env", + "mode": "0600", + "content": "ICECAST_SOURCE_PASSWORD=${secret:source}\nICECAST_ADMIN_PASSWORD=${secret:admin}\nICECAST_RELAY_PASSWORD=${secret:relay}\nICECAST_ADMIN_USERNAME=admin\n" + }, + { + "id": "server", + "type": "container", + "name": "icecast", + "image": "infiniteproject/icecast@sha256:cd506cf3dfe31ce05fd37d7e672dbd1213e7255cc93d28ecf5a3b547af4e162c", + "env-file": [ + "/var/lib/icecast-module/server.env" + ], + "ports": [ + "8000" + ] + } + ] +} diff --git a/examples/modules/nodered.json b/examples/modules/nodered.json new file mode 100644 index 0000000..b5d90d9 --- /dev/null +++ b/examples/modules/nodered.json @@ -0,0 +1,39 @@ +{ + "module": "nodered", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "listens": [ + { + "port": 1880, + "protocol": "tcp", + "from": "mesh", + "why": "the flow editor and the endpoints flows expose" + } + ], + "resources": [ + { + "id": "data", + "type": "directory", + "path": "/services/nodered/data", + "mode": "0700", + "owner": "1000:1000" + }, + { + "id": "server", + "type": "container", + "name": "nodered", + "image": "nodered/node-red@sha256:02a2b92a41b73d2bc388238b86e4fcaab7fb5466373adb24e1df6aa5845265ff", + "env": { + "TZ": "Etc/UTC" + }, + "ports": [ + "1880" + ], + "volumes": [ + "/services/nodered/data:/data" + ] + } + ] +} diff --git a/examples/modules/portainer.json b/examples/modules/portainer.json new file mode 100644 index 0000000..0f0da7a --- /dev/null +++ b/examples/modules/portainer.json @@ -0,0 +1,36 @@ +{ + "module": "portainer", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "listens": [ + { + "port": 9443, + "protocol": "tcp", + "from": "mesh", + "why": "the container dashboard, over its own tls" + } + ], + "resources": [ + { + "id": "data", + "type": "directory", + "path": "/services/portainer/data", + "mode": "0700" + }, + { + "id": "server", + "type": "container", + "name": "portainer", + "image": "portainer/portainer-ce@sha256:511f3f06c96fe3b993ebeaafde311c1959cae73a7ef825dba6397d51b450dffa", + "ports": [ + "9443" + ], + "volumes": [ + "/services/portainer/data:/data", + "/var/run/docker.sock:/var/run/docker.sock" + ] + } + ] +}