A tools bundle is given its words, composed per machine; what they name is the account's to read (hq ADR 0192)

build.artifacts[].env on a bundle: words and values written with ${dir:…} and ${port:…} only,
refused when a value carries any other reference (a secret's content, a binding) or names a word
the runtime sets for itself, and on any artifact that is not a bundle. Resolved per machine like a
container's environment and handed to the runtime as MESH_TOOL_ENV, module by module, in the unit
so a change restarts it. Every file and directory of the module a word names, or that holds one, is
owned by the account the runtime runs as where it says no owner, since a tool reads as that account.
This commit is contained in:
jochen
2026-10-03 15:32:03 +02:00
parent 62650cd48c
commit f27e31954f
5 changed files with 278 additions and 1 deletions
+10
View File
@@ -921,6 +921,16 @@ func (r Resolution) compose(with Rendering, owner map[string]string,
}
owner[fmt.Sprint(process["id"])] = RuntimeModule
out = append(out, process)
// What each module's bundles are given is read as the account the runtime runs as.
words := map[string]map[string]string{}
for _, m := range r.Modules {
w, err := bundleWords(m, with)
if err != nil {
return nil, err
}
words[m.Module] = w
}
givenTo(out, owner, words, r.Account)
}
if with.Adopted {
// First, before anything a module declares: what the mesh needs reachable, then its guard.