Files
mesh-controller/module.json
T
jochen 557b23d43f
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer delivery to the same trunk took over its walk
Answer what the records keep, collect on a person's word, and name a machine's images (hq ADR 0251)
The store's tools and a machine's image pruning decide from the records, so
the controller says them: artifacts (every recorded artifact, kept and why,
eligible, collected on request), collect (the after-build sweep on demand,
a dry run unless confirmed with a why, recorded as a hand act) and images
(what a machine's declaration names, now and as last sent). The sweep is one
implementation with two sets of bounds.
2026-10-08 12:04:42 +02:00

137 lines
3.0 KiB
JSON

{
"module": "mesh-controller",
"version": "1",
"slug": "control",
"claims": [
{
"name": "mesh-controller",
"scope": "mesh"
}
],
"accesses": [
{
"path": "/var/lib/mesh-broker-tls",
"mode": "read"
}
],
"own-secrets": {
"inventory": "${dir:mesh-state}/inventory",
"identity": "${dir:mesh-state}/identity",
"licences": "${dir:mesh-state}/licences",
"broker": "${dir:mesh-state}/broker",
"broker-management": "${dir:mesh-state}/broker-management",
"broker-address": "${dir:mesh-state}/broker-address",
"bus": "${dir:mesh-state}/bus"
},
"secrets-owner": "mesh-controller",
"prepares": true,
"tools": [
"tools",
"calls",
"status",
"nodes",
"node",
"modules",
"seats",
"builds",
"plans",
"delivery-plan",
"delivery-order",
"delivery-check",
"deliver",
"delivery-stop",
"delivery-walks",
"plan",
"assign",
"unassign",
"pin",
"unpin",
"push",
"rotate",
"issue",
"token",
"settings",
"command",
"queue",
"cancel",
"clear",
"rebuild",
"replay",
"kill",
"pause",
"resume",
"hand-act",
"drill",
"hand-acts",
"durations",
"conditions",
"healers",
"doctor",
"upgrade",
"bus",
"retire",
"cleanup",
"data",
"build",
"artifacts",
"collect",
"images"
],
"resources": [
{
"id": "account",
"type": "user",
"name": "mesh-controller",
"shell": "/usr/bin/nologin",
"home": "/var/lib/mesh-controller"
},
{
"id": "mesh-state",
"type": "directory",
"mode": "0700",
"place": "mesh",
"owner": "mesh-controller"
},
{
"id": "controller",
"type": "process",
"name": "mesh-controller",
"artifact": "controller",
"run": [
"./mesh-controller",
"serve"
],
"user": "mesh-controller",
"env": {
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus"
},
"replaces": [
"server"
]
}
],
"build": {
"artifacts": [
{
"name": "controller",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/mesh-controller",
"binary": "mesh-controller"
}
]
}
}