The mesh derives the preparation from the module's own resource instead of each module hand-writing a step beside it (novox/hq ADR 0135). A manifest says one word — `prepares` — and the mesh runs that module's own program in its preparation mode, in the module's own context: the same image, the same environment, the same mounts, because it is the same code. A published port and a fixed address are taken away rather than copied, since the version being replaced still holds them. One word for every kind of module: a Go binary receives `prepare` as its argument, a bundle receives it through the runtime whose entry takes the same word. The control plane answers it like anything else — its own schema stops being a special case, and its hand-written step is gone.
92 lines
2.8 KiB
JSON
92 lines
2.8 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "/var/lib/mesh/mesh-controller/inventory",
|
|
"identity": "/var/lib/mesh/mesh-controller/identity",
|
|
"licences": "/var/lib/mesh/mesh-controller/licences",
|
|
"broker": "/var/lib/mesh/mesh-controller/broker",
|
|
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
|
|
"broker-address": "/var/lib/mesh/mesh-controller/broker-address",
|
|
"bus": "/var/lib/mesh/mesh-controller/bus"
|
|
},
|
|
"secrets-owner": "65534:65534",
|
|
"prepares": true,
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/mesh-controller",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-controller",
|
|
"network": "host",
|
|
"args": [
|
|
"serve"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
|
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "/run/secrets/bus"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
|
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro",
|
|
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
|
|
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
|
|
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/mesh-controller/bus:/run/secrets/bus:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
|
|
],
|
|
"artifact": "server",
|
|
"restart-on": [
|
|
"control-env"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
],
|
|
"on": [
|
|
{
|
|
"arg": "GO_BASE",
|
|
"image": "golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
|
|
}
|
|
]
|
|
}
|
|
}
|