A manifest word has to reach every parser before a manifest carries it. The builder refused mesh-controller's manifest with `unknown field "prepares"` until it was rebuilt; then the running control plane could not read the manifest in the build result either, so the build was recorded with no module and the version never moved. Strict parsing is deliberate (novox/hq 04-ISSUES/003), so the word ships first and a manifest uses it next: this takes `prepares` back out of the control plane's own manifest, leaving the code that understands it, and the manifest says it again once this is running everywhere.
91 lines
2.8 KiB
JSON
91 lines
2.8 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "/var/lib/mesh/mesh-controller/inventory",
|
|
"identity": "/var/lib/mesh/mesh-controller/identity",
|
|
"licences": "/var/lib/mesh/mesh-controller/licences",
|
|
"broker": "/var/lib/mesh/mesh-controller/broker",
|
|
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
|
|
"broker-address": "/var/lib/mesh/mesh-controller/broker-address",
|
|
"bus": "/var/lib/mesh/mesh-controller/bus"
|
|
},
|
|
"secrets-owner": "65534:65534",
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/mesh-controller",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-controller",
|
|
"network": "host",
|
|
"args": [
|
|
"serve"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
|
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "/run/secrets/bus"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
|
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro",
|
|
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
|
|
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
|
|
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/mesh-controller/bus:/run/secrets/bus:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
|
|
],
|
|
"artifact": "server",
|
|
"restart-on": [
|
|
"control-env"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
],
|
|
"on": [
|
|
{
|
|
"arg": "GO_BASE",
|
|
"image": "golang@sha256:8ac98ca534ac3f51e1f420a1dd2c15e74c75cfa0f23f3ad27eb5d7236c349a0c"
|
|
}
|
|
]
|
|
}
|
|
}
|