Files
mesh-controller/module.json
T
jschoubben e6e1e3bc89
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
A gate judges its own send and the build it sent, and never puts the controller back behind its store (hq issue 352)
On 2026-10-09 a release's gate on the control node read the machine's
report against a newer send another plan had just made there, failed
three builds the machine had reported healthy, and put them back on
every machine to a controller older than the store's schema; that
controller then passed the newer plan's gate from its own health.

- A gate keeps what its send carried (digest, sequence) and reads the
  report against it; a report on the last send is on it too.
- A gate judges only the build the machine was last sent: another build
  there supersedes the judging — no verdict, nothing put back.
- A controller is told its build (MESH_CONTROLLER_VERSION, ${version}
  in a process's env) and records how far it reads the store's schema;
  a put-back to a build that reaches less, or never said, is refused
  and the current build kept, said as urgent.
- A release's open gate holds other sends of its modules there, and a
  plan's own first send waits on it.
2026-10-09 17:15:40 +02:00

142 lines
3.1 KiB
JSON

{
"module": "mesh-controller",
"version": "1",
"slug": "control",
"claims": [
{
"name": "mesh-controller",
"scope": "mesh"
}
],
"accesses": [
{
"path": "/var/lib/mesh-broker-tls",
"mode": "read"
}
],
"own-secrets": {
"inventory": "${dir:mesh-state}/inventory",
"identity": "${dir:mesh-state}/identity",
"licences": "${dir:mesh-state}/licences",
"broker": "${dir:mesh-state}/broker",
"broker-management": "${dir:mesh-state}/broker-management",
"broker-address": "${dir:mesh-state}/broker-address",
"bus": "${dir:mesh-state}/bus"
},
"secrets-owner": "mesh-controller",
"prepares": true,
"tools": [
"tools",
"calls",
"status",
"nodes",
"node",
"modules",
"seats",
"builds",
"plans",
"delivery-plan",
"delivery-order",
"delivery-check",
"deliver",
"delivery-stop",
"delivery-walks",
"plan",
"assign",
"unassign",
"pin",
"unpin",
"push",
"rotate",
"give",
"issue",
"token",
"settings",
"command",
"queue",
"cancel",
"clear",
"rebuild",
"replay",
"kill",
"pause",
"resume",
"hand-act",
"drill",
"hand-acts",
"durations",
"conditions",
"healers",
"doctor",
"upgrade",
"bus",
"retire",
"cleanup",
"dead-letters",
"root-free",
"data",
"build",
"artifacts",
"collect",
"images",
"mirrors"
],
"resources": [
{
"id": "account",
"type": "user",
"name": "mesh-controller",
"shell": "/usr/bin/nologin",
"home": "/var/lib/mesh-controller"
},
{
"id": "mesh-state",
"type": "directory",
"mode": "0700",
"place": "mesh",
"owner": "mesh-controller"
},
{
"id": "controller",
"type": "process",
"name": "mesh-controller",
"artifact": "controller",
"run": [
"./mesh-controller",
"serve"
],
"user": "mesh-controller",
"env": {
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus",
"MESH_CONTROLLER_VERSION": "${version}"
},
"replaces": [
"server"
]
}
],
"build": {
"artifacts": [
{
"name": "controller",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/mesh-controller",
"binary": "mesh-controller"
}
]
}
}