The controller is a Go program and was the one piece of the mesh's own Go code still shipped and run as an image (novox/hq issue 213; ADR 0188 §1: a module's own code is bundles; §3: a service bundle is a process). The manifest now builds one Go bundle, `controller`, and runs it as the process `mesh-controller` (`./mesh-controller serve`) under an account the module declares. What the container gave it, replaced: - host network: a process is on the host's network; nothing it reads names a container network - user 65534: the account `mesh-controller`, which owns its secrets and its state directory - the eight mounts: the env names the host paths the mesh already places (the store, broker and bus files under the state directory, the broker's certificate under /var/lib/mesh-broker-tls); the `broker` mount was read by nothing and is gone with the others - `container-runtime` is no longer required on its machine Its preparation is the same binary with `prepare`, as a run-once process, and the process `replaces` the container `server`: the host keeps the container answering until the process is running (mesh-host). Needs the previous commit live in the running controller, and the host's `replaces` on the controller's machine, before it is registered. No image is built by the mesh any more. The Dockerfile stays for genesis and the lab (`make image`, its Go base now pinned in the Makefile).
99 lines
2.5 KiB
JSON
99 lines
2.5 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "${dir:mesh-state}/inventory",
|
|
"identity": "${dir:mesh-state}/identity",
|
|
"licences": "${dir:mesh-state}/licences",
|
|
"broker": "${dir:mesh-state}/broker",
|
|
"broker-management": "${dir:mesh-state}/broker-management",
|
|
"broker-address": "${dir:mesh-state}/broker-address",
|
|
"bus": "${dir:mesh-state}/bus"
|
|
},
|
|
"secrets-owner": "mesh-controller",
|
|
"prepares": true,
|
|
"tools": [
|
|
"tools",
|
|
"status",
|
|
"nodes",
|
|
"node",
|
|
"modules",
|
|
"seats",
|
|
"builds",
|
|
"plan",
|
|
"assign",
|
|
"unassign",
|
|
"push",
|
|
"build"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "account",
|
|
"type": "user",
|
|
"name": "mesh-controller",
|
|
"shell": "/usr/bin/nologin",
|
|
"home": "/var/lib/mesh-controller"
|
|
},
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh",
|
|
"owner": "mesh-controller"
|
|
},
|
|
{
|
|
"id": "controller",
|
|
"type": "process",
|
|
"name": "mesh-controller",
|
|
"artifact": "controller",
|
|
"run": [
|
|
"./mesh-controller",
|
|
"serve"
|
|
],
|
|
"user": "mesh-controller",
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
|
|
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus"
|
|
},
|
|
"replaces": [
|
|
"server"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "controller",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/mesh-controller",
|
|
"binary": "mesh-controller"
|
|
}
|
|
]
|
|
}
|
|
}
|