Part 2 of novox/hq issue 213; genesis per issue 223 (option b). Rebased onto main, which already has #252. Merge only after mesh-host's genesis PR is merged (see "Genesis" below). mesh-host #86 is already merged and live on the control machine.
Manifest
Build: one Go bundle, controller (system: arch, from: cmd/mesh-controller, binary: mesh-controller). No image artifact.
Process:controller, unit name mesh-controller, running ./mesh-controller serve as user: mesh-controller, with replaces: ["server"].
Account: a user resource, mesh-controller. It is also the secrets-owner and the owner of mesh-state.
Env: host paths only. The eight container mounts are gone, along with container-runtime and the dangling restart-on.
Preparation: a run-once process, controller-prepare, runs ./mesh-controller prepare.
Genesis (issue 223). Genesis raises this controller as a container built from this repository's own Dockerfile, with no build arguments. The first push then hands that container over to the process. So the Dockerfile's default GO_BASE is now the pinned digest; it was a tag older than go.mod requires. The Makefile pins the same digest, and TestGenesisCanBuildTheControllersImageAsItStands holds the two equal.
Tests
controller_is_a_process_test.go composes the real module.json. Among other checks, the process's replaces composes to mesh-controller.server, which is the id the host records for the genesis container.
The genesis form of this exact module.json (built by mesh-host's bootstrap) was checked by hand: this controller accepts it, it has no installation problems, it composes to mesh-controller.server as a container, and the host's parser accepts the result.
Full go test -p 1 ./... against Postgres and NATS passes, except the known TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves.
Part 2 of novox/hq issue 213; genesis per issue 223 (option b). Rebased onto main, which already has #252. Merge only after mesh-host's genesis PR is merged (see "Genesis" below). mesh-host #86 is already merged and live on the control machine.
**Manifest**
- **Build:** one Go bundle, `controller` (`system: arch`, `from: cmd/mesh-controller`, `binary: mesh-controller`). No image artifact.
- **Process:** `controller`, unit name `mesh-controller`, running `./mesh-controller serve` as `user: mesh-controller`, with `replaces: ["server"]`.
- **Account:** a `user` resource, `mesh-controller`. It is also the `secrets-owner` and the owner of `mesh-state`.
- **Env:** host paths only. The eight container mounts are gone, along with `container-runtime` and the dangling `restart-on`.
- **Preparation:** a run-once process, `controller-prepare`, runs `./mesh-controller prepare`.
**Genesis (issue 223).** Genesis raises this controller as a container built from this repository's own Dockerfile, with no build arguments. The first push then hands that container over to the process. So the Dockerfile's default `GO_BASE` is now the pinned digest; it was a tag older than go.mod requires. The Makefile pins the same digest, and `TestGenesisCanBuildTheControllersImageAsItStands` holds the two equal.
**Tests**
- `controller_is_a_process_test.go` composes the real `module.json`. Among other checks, the process's `replaces` composes to `mesh-controller.server`, which is the id the host records for the genesis container.
- The genesis form of this exact `module.json` (built by mesh-host's bootstrap) was checked by hand: this controller accepts it, it has no installation problems, it composes to `mesh-controller.server` as a container, and the host's parser accepts the result.
- Full `go test -p 1 ./...` against Postgres and NATS passes, except the known `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves`.
The controller is a Go program and was the one piece of the mesh's own Go
code still shipped and run as an image (novox/hq issue 213; ADR 0188 §1:
a module's own code is bundles; §3: a service bundle is a process).
The manifest now builds one Go bundle, `controller`, and runs it as the
process `mesh-controller` (`./mesh-controller serve`) under an account
the module declares. What the container gave it, replaced:
- host network: a process is on the host's network; nothing it reads
names a container network
- user 65534: the account `mesh-controller`, which owns its secrets and
its state directory
- the eight mounts: the env names the host paths the mesh already places
(the store, broker and bus files under the state directory, the
broker's certificate under /var/lib/mesh-broker-tls); the `broker`
mount was read by nothing and is gone with the others
- `container-runtime` is no longer required on its machine
Its preparation is the same binary with `prepare`, as a run-once process,
and the process `replaces` the container `server`: the host keeps the
container answering until the process is running (mesh-host). Needs the
previous commit live in the running controller, and the host's
`replaces` on the controller's machine, before it is registered.
No image is built by the mesh any more. The Dockerfile stays for genesis
and the lab (`make image`, its Go base now pinned in the Makefile).
Genesis now raises a process-form controller as a container built from
this repository's Dockerfile with no build arguments (mesh-host
bootstrap, novox/hq issue 223); the manifest builds no image, so nothing
passes the base in. The default was a tag older than go.mod asks for.
It is now the digest the Makefile pins, and a test holds the two equal.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part 2 of novox/hq issue 213; genesis per issue 223 (option b). Rebased onto main, which already has #252. Merge only after mesh-host's genesis PR is merged (see "Genesis" below). mesh-host #86 is already merged and live on the control machine.
Manifest
controller(system: arch,from: cmd/mesh-controller,binary: mesh-controller). No image artifact.controller, unit namemesh-controller, running./mesh-controller serveasuser: mesh-controller, withreplaces: ["server"].userresource,mesh-controller. It is also thesecrets-ownerand the owner ofmesh-state.container-runtimeand the danglingrestart-on.controller-prepare, runs./mesh-controller prepare.Genesis (issue 223). Genesis raises this controller as a container built from this repository's own Dockerfile, with no build arguments. The first push then hands that container over to the process. So the Dockerfile's default
GO_BASEis now the pinned digest; it was a tag older than go.mod requires. The Makefile pins the same digest, andTestGenesisCanBuildTheControllersImageAsItStandsholds the two equal.Tests
controller_is_a_process_test.gocomposes the realmodule.json. Among other checks, the process'sreplacescomposes tomesh-controller.server, which is the id the host records for the genesis container.module.json(built by mesh-host's bootstrap) was checked by hand: this controller accepts it, it has no installation problems, it composes tomesh-controller.serveras a container, and the host's parser accepts the result.go test -p 1 ./...against Postgres and NATS passes, except the knownTestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves.635363adbdtob5438bb331