The controller is a Go program and was the one piece of the mesh's own Go code still shipped and run as an image (novox/hq issue 213; ADR 0188 §1: a module's own code is bundles; §3: a service bundle is a process). The manifest now builds one Go bundle, `controller`, and runs it as the process `mesh-controller` (`./mesh-controller serve`) under an account the module declares. What the container gave it, replaced: - host network: a process is on the host's network; nothing it reads names a container network - user 65534: the account `mesh-controller`, which owns its secrets and its state directory - the eight mounts: the env names the host paths the mesh already places (the store, broker and bus files under the state directory, the broker's certificate under /var/lib/mesh-broker-tls); the `broker` mount was read by nothing and is gone with the others - `container-runtime` is no longer required on its machine Its preparation is the same binary with `prepare`, as a run-once process, and the process `replaces` the container `server`: the host keeps the container answering until the process is running (mesh-host). Needs the previous commit live in the running controller, and the host's `replaces` on the controller's machine, before it is registered. No image is built by the mesh any more. The Dockerfile stays for genesis and the lab (`make image`, its Go base now pinned in the Makefile).
142 lines
6.7 KiB
Makefile
142 lines
6.7 KiB
Makefile
# novox/hq ADR 0006 — the control plane, in Go.
|
|
#
|
|
# The image the bundle pins holds the program and nothing else, so the build is static and the
|
|
# container is built FROM scratch. That is not a size optimisation: this image is fetched by
|
|
# digest and run on a machine where no mesh exists to check anything, and everything in it is
|
|
# something a person would have to audit.
|
|
|
|
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo development)
|
|
LDFLAGS := -s -w -X main.version=$(VERSION)
|
|
|
|
# Where `make check` raises PostgreSQL. A high port and a throwaway container: nothing here
|
|
# touches a database anybody else is using. Override PG_PORT if this one is taken -- the first
|
|
# port chosen was already serving something that had been up for six days.
|
|
PG_PORT ?= 55532
|
|
PG_CONTAINER ?= mesh-controller-check
|
|
PG_IMAGE ?= postgres:17-alpine
|
|
export MESH_TEST_POSTGRES ?= postgres://postgres:check@127.0.0.1:$(PG_PORT)/postgres?sslmode=disable
|
|
|
|
.PHONY: build image check test vet fmt postgres postgres-stop clean
|
|
|
|
build:
|
|
CGO_ENABLED=0 go build -trimpath -ldflags '$(LDFLAGS)' -o build/mesh-controller ./cmd/mesh-controller
|
|
|
|
# Tagged 'development' as well as by version, because the lab places images by name and a
|
|
# scenario naming a version would have to be edited on every build. The version tag is what a
|
|
# real bundle pins.
|
|
IMAGE ?= mesh-controller:$(VERSION)
|
|
DEV_TAG ?= mesh-controller:development
|
|
|
|
# The Go base the image is built on.
|
|
#
|
|
# **`make image` was broken and stayed broken**, because the Dockerfile's fallback base was a Go
|
|
# older than go.mod asks for: every build died at `go mod download` with "go.mod requires go >=
|
|
# 1.26.0", and the pipeline never saw it because the pipeline passes the declared base in. Anybody
|
|
# building the image by hand hit it and had to find the digest themselves (novox/hq 04-ISSUES/146,
|
|
# what it cost).
|
|
#
|
|
# **Pinned here since the manifest stopped building an image** (novox/hq issue 213): the mesh builds
|
|
# the controller as a Go bundle with its own toolchain, and only `make image` — genesis and the lab —
|
|
# still needs a Go base. The digest is the one the manifest declared until then.
|
|
GO_BASE ?= golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c
|
|
|
|
image:
|
|
@test -n "$(GO_BASE)" || { echo "no GO_BASE; pass GO_BASE=<image>"; exit 1; }
|
|
docker build --build-arg GO_BASE=$(GO_BASE) --build-arg VERSION=$(VERSION) -t $(IMAGE) -t $(DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The builder ships as an image too, because it is a module the mesh assigns rather than a program
|
|
# somebody starts on a machine by hand.
|
|
BUILDER_IMAGE ?= mesh-builder:$(VERSION)
|
|
BUILDER_DEV_TAG ?= mesh-builder:development
|
|
|
|
builder-image:
|
|
@test -n "$(GO_BASE)" || { echo "no GO_BASE; pass GO_BASE=<image>"; exit 1; }
|
|
docker build --build-arg GO_BASE=$(GO_BASE) -f cmd/mesh-builder/Dockerfile -t $(BUILDER_IMAGE) -t $(BUILDER_DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(BUILDER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The provisioner ships as an image too, because it is the thing that makes a sealed credential
|
|
# true on a machine -- and the mesh cannot, having discarded the plaintext.
|
|
PROVISIONER_IMAGE ?= mesh-provision-postgres:$(VERSION)
|
|
PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development
|
|
|
|
provisioner-image:
|
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/postgres-provisioner/Dockerfile \
|
|
-t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The object store's provisioner, for the same reason: a bucket and a policy are not files, and
|
|
# the mesh cannot make them -- it discarded the credential it would have to use.
|
|
OBJECTSTORE_IMAGE ?= mesh-provision-objectstore:$(VERSION)
|
|
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
|
|
|
objectstore-image:
|
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/objectstore-provisioner/Dockerfile \
|
|
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The cache's provisioner, for the same reason as the database's: an ACL user is not a file,
|
|
# and the mesh cannot make one -- it discarded the credential it would have to use.
|
|
REDIS_PROVISIONER_IMAGE ?= mesh-provision-redis:$(VERSION)
|
|
REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development
|
|
|
|
redis-provisioner-image:
|
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/redis-provisioner/Dockerfile \
|
|
-t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The proxy that turns a route grant into traffic reaching a workload.
|
|
PROXY_IMAGE ?= mesh-route-proxy:$(VERSION)
|
|
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
|
|
|
proxy-image:
|
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) .
|
|
@echo
|
|
@docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
|
|
|
# The whole gate. Raises a database, runs everything against it, and takes it down again --
|
|
# including when the tests fail, which is why the teardown is not conditional.
|
|
#
|
|
# **One package at a time (-p 1), and it is not about speed.** The live tests reach one bus, and on
|
|
# it they assert, read and remove the mesh's own objects -- streams and consumers with fixed names,
|
|
# because those names are the mesh's and a test cannot choose others. Two packages doing that at once
|
|
# is one deleting a consumer the other is reading through, and the failure lands in whichever test
|
|
# was reading, as "no response from stream". That reads as a bug in the code under test.
|
|
check: fmt vet postgres
|
|
@go test -p 1 ./... ; status=$$? ; $(MAKE) postgres-stop ; exit $$status
|
|
|
|
# Without a database the live tests skip rather than fail, so this is the honest subset and not
|
|
# the gate. Serialised for the same reason check is: a bus may be configured even when a store is not.
|
|
test:
|
|
go test -p 1 ./...
|
|
|
|
vet:
|
|
go vet ./...
|
|
|
|
fmt:
|
|
@unformatted=$$(gofmt -l . 2>/dev/null) ; \
|
|
if [ -n "$$unformatted" ] ; then echo "not gofmt'd:" ; echo "$$unformatted" ; exit 1 ; fi
|
|
|
|
postgres:
|
|
@docker rm -f $(PG_CONTAINER) >/dev/null 2>&1 || true
|
|
@docker run -d --name $(PG_CONTAINER) -e POSTGRES_PASSWORD=check \
|
|
-p 127.0.0.1:$(PG_PORT):5432 $(PG_IMAGE) >/dev/null
|
|
@printf 'waiting for postgres'
|
|
@for i in $$(seq 1 60) ; do \
|
|
if docker exec $(PG_CONTAINER) pg_isready -U postgres >/dev/null 2>&1 ; then \
|
|
echo ' — ready' ; exit 0 ; fi ; \
|
|
printf '.' ; sleep 1 ; \
|
|
done ; \
|
|
echo ' — never came up' ; docker logs $(PG_CONTAINER) | tail -20 ; exit 1
|
|
|
|
postgres-stop:
|
|
@docker rm -f $(PG_CONTAINER) >/dev/null 2>&1 || true
|
|
|
|
clean:
|
|
rm -rf build/
|