From ef7750f8168e8f22ee3444feb36e737099afefb2 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 22:49:18 +0200 Subject: [PATCH] Three more: searxng, influxdb, verdaccio MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Converted from the arrangement being replaced. The search engine brings its own valkey on its own network — a sidecar is just a second container resource. The time-series database initialises itself from two generated secrets, and its data and config directories are declared with the owner the image runs as. The package registry's configuration is a declared file rather than a merged one, which is the position 16-module-coverage takes on config merging: the module knows its own format because it wrote the rest of the file. Two were read and deliberately not converted, which is worth recording where the next person will look: n8n builds a custom image, so it is a module with a repository rather than a manifest in this catalogue — where a module's own code lives is ADR 0037's question, and pretending otherwise here would prejudge it. mosquitto authenticates from a hashed password file that only mosquitto_passwd can write, and the mesh delivers plaintext sealed files — so an honest conversion needs a small provisioner, the same shape as the cache's. Without one, the manifest would compose a broker nobody can log in to, which is exactly the kind of module that parses, resolves, and stops on the machine. All images pinned by real digests, resolved on this workstation today. --- examples/modules/influxdb.json | 64 ++++++++++++++++++++++++++++++ examples/modules/searxng.json | 69 +++++++++++++++++++++++++++++++++ examples/modules/verdaccio.json | 50 ++++++++++++++++++++++++ 3 files changed, 183 insertions(+) create mode 100644 examples/modules/influxdb.json create mode 100644 examples/modules/searxng.json create mode 100644 examples/modules/verdaccio.json diff --git a/examples/modules/influxdb.json b/examples/modules/influxdb.json new file mode 100644 index 0000000..ad64e0c --- /dev/null +++ b/examples/modules/influxdb.json @@ -0,0 +1,64 @@ +{ + "module": "influxdb", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "own-secrets": { + "admin": "/var/lib/influxdb-module/admin.secret", + "admin-token": "/var/lib/influxdb-module/admin-token.secret" + }, + "listens": [ + { + "port": 8086, + "protocol": "tcp", + "from": "mesh", + "why": "queries and writes, over http" + } + ], + "resources": [ + { + "id": "state", + "type": "directory", + "path": "/var/lib/influxdb-module", + "mode": "0700" + }, + { + "id": "server-env", + "type": "file", + "path": "/var/lib/influxdb-module/server.env", + "mode": "0600", + "content": "DOCKER_INFLUXDB_INIT_MODE=setup\nDOCKER_INFLUXDB_INIT_USERNAME=admin\nDOCKER_INFLUXDB_INIT_PASSWORD=${secret:admin}\nDOCKER_INFLUXDB_INIT_ADMIN_TOKEN=${secret:admin-token}\nDOCKER_INFLUXDB_INIT_ORG=mesh\nDOCKER_INFLUXDB_INIT_BUCKET=default\n" + }, + { + "id": "data", + "type": "directory", + "path": "/services/influxdb/data", + "mode": "0700", + "owner": "1000:1000" + }, + { + "id": "config", + "type": "directory", + "path": "/services/influxdb/config", + "mode": "0700", + "owner": "1000:1000" + }, + { + "id": "server", + "type": "container", + "name": "influxdb", + "image": "influxdb@sha256:f75e48af0598e8aec7986e991a848d19a119101a7d563a2e5db1dfaac9c45daa", + "env-file": [ + "/var/lib/influxdb-module/server.env" + ], + "ports": [ + "8086" + ], + "volumes": [ + "/services/influxdb/data:/var/lib/influxdb2", + "/services/influxdb/config:/etc/influxdb2" + ] + } + ] +} diff --git a/examples/modules/searxng.json b/examples/modules/searxng.json new file mode 100644 index 0000000..8262a4b --- /dev/null +++ b/examples/modules/searxng.json @@ -0,0 +1,69 @@ +{ + "module": "searxng", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "own-secrets": { + "secret": "/var/lib/searxng-module/secret.secret" + }, + "listens": [ + { + "port": 8080, + "protocol": "tcp", + "from": "mesh", + "why": "the search pages" + } + ], + "resources": [ + { + "id": "state", + "type": "directory", + "path": "/var/lib/searxng-module", + "mode": "0700" + }, + { + "id": "server-env", + "type": "file", + "path": "/var/lib/searxng-module/server.env", + "mode": "0600", + "content": "SEARXNG_SECRET=${secret:secret}\nSEARXNG_VALKEY_URL=valkey://valkey:6379/0\n" + }, + { + "id": "net", + "type": "network", + "name": "searxng" + }, + { + "id": "cache", + "type": "container", + "name": "valkey", + "image": "valkey/valkey@sha256:b21fd94099dcd4bc6b2b9230daef69b6558b887ad4a2a1afe56ff6e745a88cdb", + "network": "searxng", + "args": [ + "valkey-server", + "--save", + "30", + "1", + "--loglevel", + "warning" + ], + "volumes": [ + "searxng-valkey-data:/data" + ] + }, + { + "id": "server", + "type": "container", + "name": "searxng", + "image": "searxng/searxng@sha256:c7cc75852051bf6254afda6ed1b920dd1677d8efe4ab141bf558f02e582f4371", + "network": "searxng", + "env-file": [ + "/var/lib/searxng-module/server.env" + ], + "ports": [ + "8080" + ] + } + ] +} diff --git a/examples/modules/verdaccio.json b/examples/modules/verdaccio.json new file mode 100644 index 0000000..2acf0df --- /dev/null +++ b/examples/modules/verdaccio.json @@ -0,0 +1,50 @@ +{ + "module": "verdaccio", + "version": "1", + "capabilities": [ + "container-runtime" + ], + "listens": [ + { + "port": 4873, + "protocol": "tcp", + "from": "mesh", + "why": "the package registry, for installs and publishes" + } + ], + "resources": [ + { + "id": "conf", + "type": "directory", + "path": "/services/verdaccio/conf", + "mode": "0755" + }, + { + "id": "storage", + "type": "directory", + "path": "/services/verdaccio/storage", + "mode": "0700", + "owner": "10001:10001" + }, + { + "id": "config", + "type": "file", + "path": "/services/verdaccio/conf/config.yaml", + "mode": "0644", + "content": "storage: /verdaccio/storage\nauth:\n htpasswd:\n file: /verdaccio/conf/htpasswd\n max_users: 10\nuplinks:\n npmjs:\n url: https://registry.npmjs.org/\npackages:\n \"**\":\n access: $all\n publish: $authenticated\n proxy: npmjs\nserver:\n keepAliveTimeout: 60\n maxBodySize: 10mb\nmiddlewares:\n audit:\n enabled: true\nlog:\n type: stdout\n format: pretty\n level: http\n" + }, + { + "id": "server", + "type": "container", + "name": "verdaccio", + "image": "verdaccio/verdaccio@sha256:fcb86134563534e2f634752e6c6c3edcdb78242ec16578c73ce39d1dadbaa801", + "ports": [ + "4873" + ], + "volumes": [ + "/services/verdaccio/storage:/verdaccio/storage", + "/services/verdaccio/conf:/verdaccio/conf" + ] + } + ] +}