Three of novox/hq's group-4 leftovers, one branch.
Issue 173: a module's settings reached every route it contributed, every database it asked for and
every served fact its consumers read — a mail server's site name arrived at the proxy as a route
fact. A setting now overrides a key a contribution or served fact declares and adds none; a file
still merges any key, and a key nothing takes is named as stray instead of dropped silently.
Issue 174: the mesh's own files for a module — its bus credential, its merged config, its bindings —
were placed by the definition under /var/lib/mesh/<module>, 232 host paths in 50 definitions. A
directory may now say `place: "mesh"` and resolves to <root>/mesh/<module>; a directory beneath a
placed one may state its path as `${dir:<id>}/<rest>` and moves with it. The proof test resolves
both catalogues and compares: 48 definitions, no path moved. The controller's own manifest is
converted here; the catalogue in mesh-catalog.
ADR 0155: the installation check moves to registration. `module add` and a build's result both
refuse a definition that names an installation, in the check's words, with the way out; the build
stays recorded.
106 lines
2.8 KiB
JSON
106 lines
2.8 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "${dir:mesh-state}/inventory",
|
|
"identity": "${dir:mesh-state}/identity",
|
|
"licences": "${dir:mesh-state}/licences",
|
|
"broker": "${dir:mesh-state}/broker",
|
|
"broker-management": "${dir:mesh-state}/broker-management",
|
|
"broker-address": "${dir:mesh-state}/broker-address",
|
|
"bus": "${dir:mesh-state}/bus"
|
|
},
|
|
"secrets-owner": "65534:65534",
|
|
"prepares": true,
|
|
"tools": [
|
|
"tools",
|
|
"status",
|
|
"nodes",
|
|
"node",
|
|
"modules",
|
|
"seats",
|
|
"builds",
|
|
"plan",
|
|
"assign",
|
|
"unassign",
|
|
"push",
|
|
"build"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-controller",
|
|
"network": "host",
|
|
"args": [
|
|
"serve"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
|
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "/run/secrets/bus"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
|
"${dir:mesh-state}/inventory:/run/secrets/inventory:ro",
|
|
"${dir:mesh-state}/identity:/run/secrets/identity:ro",
|
|
"${dir:mesh-state}/licences:/run/secrets/licences:ro",
|
|
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
"${dir:mesh-state}/bus:/run/secrets/bus:ro",
|
|
"${dir:mesh-state}/broker-management:/run/secrets/broker-management:ro",
|
|
"${dir:mesh-state}/broker-address:/run/secrets/broker-address:ro"
|
|
],
|
|
"artifact": "server",
|
|
"restart-on": [
|
|
"control-env"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
],
|
|
"on": [
|
|
{
|
|
"arg": "GO_BASE",
|
|
"image": "golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
|
|
}
|
|
]
|
|
}
|
|
}
|