Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
150 lines
3.6 KiB
Plaintext
150 lines
3.6 KiB
Plaintext
{
|
|
"module": "mounts",
|
|
"version": "1",
|
|
"requires": [
|
|
"nfs-share"
|
|
],
|
|
"reads": [
|
|
"nfs-server.exports"
|
|
],
|
|
"invokes": [
|
|
"seat:mesh-controller.data"
|
|
],
|
|
"capabilities": [
|
|
"package-manager",
|
|
"service-manager"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-mounts",
|
|
"scope": "node",
|
|
"serves": [
|
|
"list",
|
|
"test",
|
|
"mount",
|
|
"unmount",
|
|
"adopt"
|
|
]
|
|
}
|
|
],
|
|
"tools": [
|
|
"mounts_list",
|
|
"mounts_exports",
|
|
"mounts_health"
|
|
],
|
|
"state": [
|
|
{
|
|
"name": "shares",
|
|
"per-machine": true
|
|
}
|
|
],
|
|
"settings": {
|
|
"shares": {
|
|
"kind": "preference",
|
|
"default": "none",
|
|
"why": "a machine mounts no share of another until its assignment names one: space-separated name=mountpoint, each optionally :ro (hq ADR 0263 rule 5)"
|
|
},
|
|
"sources": {
|
|
"kind": "preference",
|
|
"default": "none",
|
|
"why": "a machine has no occasional source until its assignment names one: space-separated name=smb://[<user>@]<host>/<share>@<mountpoint> or name=disk:<uuid>@<mountpoint>, each optionally :ro (hq ADR 0263 rule 6); an SMB source's username is in its entry, its password the secret smb-password-<name> (hq ADR 0283)"
|
|
}
|
|
},
|
|
"own-secrets": {
|
|
"smb-password-*": {
|
|
"path": "${dir:state}/smb-password-*.secret",
|
|
"issued-by": "outside"
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "nfs-utils",
|
|
"type": "package",
|
|
"package": "nfs-utils"
|
|
},
|
|
{
|
|
"id": "cifs-utils",
|
|
"type": "package",
|
|
"package": "cifs-utils"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config-dir",
|
|
"type": "directory",
|
|
"path": "/etc/mesh-mounts",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/etc/mesh-mounts/mounts.conf",
|
|
"mode": "0644",
|
|
"content": "# Written by the mesh (module mounts, novox/hq ADR 0263) from this machine's assignment: the settings\n# shares and sources, and the binding of nfs-share. Replaced on every push; change the settings, not this.\n# The module's process reads it as root every 30 seconds and writes one .mount and .automount per entry.\nshares=${setting:shares}\nsources=${setting:sources}\nserver=${bound:nfs-share:from}\nat=${bound:nfs-share:at}\naccount=${machine:account}\nnode=${machine:name}\npasswords=${dir:state}\nstate=${dir:state}\n"
|
|
},
|
|
{
|
|
"id": "bus-dir-parent",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-mounts",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "bus-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-mounts/from-bus",
|
|
"mode": "0755",
|
|
"owner": "${machine:account}"
|
|
},
|
|
{
|
|
"id": "apply",
|
|
"type": "process",
|
|
"name": "mesh-mounts-apply",
|
|
"artifact": "tools-go",
|
|
"run": [
|
|
"./mounts",
|
|
"apply"
|
|
],
|
|
"health": {
|
|
"kind": "unit"
|
|
}
|
|
},
|
|
{
|
|
"id": "watch",
|
|
"type": "process",
|
|
"name": "mesh-mounts-watch",
|
|
"artifact": "tools-go",
|
|
"run": [
|
|
"./mounts",
|
|
"watch"
|
|
],
|
|
"health": {
|
|
"kind": "tool",
|
|
"tool": "mounts_health",
|
|
"interval": "60s",
|
|
"timeout": "10s",
|
|
"looks": 2,
|
|
"grace": "90s"
|
|
}
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools-go",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/mounts",
|
|
"binary": "mounts",
|
|
"loads": [
|
|
"mounts"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|