{ "module": "nfs-server", "version": "1", "upgrade": { "policy": "record", "why": "the folders other machines mount: a build that breaks the exports leaves every client's mount hanging or refused, and the gate on this one machine does not see the clients (hq ADR 0236, ADR 0263)" }, "capabilities": [ "package-manager", "service-manager" ], "provides": [ { "name": "nfs-share", "scope": "mesh", "identity": false } ], "data": { "consumers": { "nfs-share": { "class": "none", "why": "the shared folders are the operator's data (hq ADR 0051): what a client writes lands in them, and they are protected where the operator declares them, never by this module, which keeps nothing of a consumer's" } } }, "claims": [ { "name": "node-nfs-server", "scope": "node", "serves": [ "exports", "clients", "test", "reload", "adopt" ] } ], "state": [ { "name": "exports", "ttl-seconds": 120, "per-machine": true } ], "reads": [ "mounts.shares" ], "invokes": [ "seat:mesh-controller.seats", "seat:mesh-controller.data" ], "settings": { "grants": { "kind": "preference", "default": "none", "why": "which nodes may mount which share, and how, is this machine's to say (hq ADR 0263, review of mesh-catalog #136): share=node:rw|ro[,node:rw|ro], entries separated by spaces; none exports to no node, whatever a node wants" } }, "facts": { "machines": { "path": "/etc/nfs-server/machines", "template": "# Written by the mesh (module nfs-server, novox/hq ADR 0263): every machine of the mesh and its private\n# address, from which the module takes a node's address. Replaced on every push.\n{{range .Machines}}{{.Name}} {{.Address}}\n{{end}}" } }, "tools": [ "nfs_health" ], "listens": [ { "name": "nfs", "port": 2049, "protocol": "tcp", "from": "mesh", "fixed": true, "why": "the shares, to the mesh's machines only (hq ADR 0263): NFS version 4 alone, which needs no other port, and never the home network, where a device that is not a node could claim any user id" } ], "resources": [ { "id": "package", "type": "package", "package": "nfs-utils" }, { "id": "nfs-conf", "type": "file", "path": "/etc/nfs.conf.d/50-mesh.conf", "mode": "0644", "content": "# Written by the mesh (module nfs-server, novox/hq ADR 0263). Replaced on every push; a drop-in of\n# the operator's that sorts after this one overrides it, and is theirs.\n#\n# NFS version 4 only: a client needs port 2049 and nothing else, so the module opens nothing more\n# than that, to the private network. Version 3 needs rpcbind and mountd, on ports the mesh does not open.\n[nfsd]\nvers2=n\nvers3=n\nvers4=y\nvers4.0=n\nvers4.1=y\nvers4.2=y\n" }, { "id": "run-dir", "type": "directory", "path": "/run/nfs-server", "mode": "0755" }, { "id": "server", "type": "service", "unit": "nfs-server.service", "state": "running", "boot": "enabled", "restart-on": [ "nfs-conf" ], "health": { "kind": "unit" } }, { "id": "wants-dir-parent", "type": "directory", "path": "/var/lib/nfs-server", "mode": "0755" }, { "id": "wants-dir", "type": "directory", "path": "/var/lib/nfs-server/from-bus", "mode": "0755", "owner": "${machine:account}" }, { "id": "exports", "type": "process", "name": "nfs-server-exports", "artifact": "tools", "run": [ "./nfs-server", "exports" ], "restart-on": [ "config" ], "health": { "kind": "tool", "tool": "nfs_health", "interval": "60s", "timeout": "10s", "looks": 2, "grace": "90s" } }, { "id": "config-dir", "type": "directory", "path": "/etc/nfs-server", "mode": "0755" }, { "id": "config", "type": "file", "path": "/etc/nfs-server/shares.conf", "mode": "0644", "content": "# Written by the mesh (module nfs-server, novox/hq ADR 0263) from this machine's assignment.\n# Replaced on every push; change the `shares` setting, never this file.\n#\n# The shares: name=folder, or name=folder:ro, one share per folder. The grants: share=node:rw|ro[,…],\n# which nodes may mount each and how. The module's process exports a share to a node's private address\n# only when it is granted here and that node's mounts module wants it, every client mapped to the\n# folder's owner, and only to addresses inside the range below.\nshares=${setting:shares}\ngrants=${setting:grants}\nrange=${machine:mesh-range}\n" } ], "build": { "artifacts": [ { "name": "tools", "kind": "bundle", "language": "go", "system": "arch", "from": "cmd/nfs-server", "binary": "nfs-server", "loads": [ "nfs-server" ] } ] } }