Converted from the arrangement being replaced, in its shapes rather than theirs. The registry is the manifest the lab already proved, promoted: names its image by digest and is never built (04-ISSUES/029), provides the artifact store, claims it once per machine. Redis is the third provision after a database and a bucket, and the first whose tenancy is a pattern in a shared keyspace rather than a namespace something else enforces. Its provisioner mirrors the postgres one's contract line for line — the manifest, the sealed per-consumer files, the mark, the withdrawal of orphans — and speaks RESP directly: five commands are needed, and a client library large enough to hide them would be most of the program's size. A prefix Redis would read as a pattern is refused, because the grant must mean what the manifest said; grants are persisted with ACL SAVE, or said loudly, because a cache that forgets its tenants on restart reports success until then. Umami asks the mesh for its database and a generated app secret, and carries no state of its own — the arrangement being replaced ran a bundled second postgres beside it. Grafana keeps its dashboards in a declared directory with the image's own owner. Both listen on 3000, as does the forge — which is the mesh's port assignment earning its keep. Traefik is deliberately not converted: the mesh's route provider is mesh-route-proxy, which speaks route grants natively, and a traefik that consumed them would be an adapter nobody has written pretending to be a conversion. All images pinned by real digests, resolved on this workstation today.
56 lines
1.2 KiB
JSON
56 lines
1.2 KiB
JSON
{
|
|
"module": "grafana",
|
|
"version": "1",
|
|
"own-secrets": {
|
|
"admin": "/var/lib/grafana-module/admin.secret"
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"listens": [
|
|
{
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the dashboards. Also 3000 inside, like the forge - which is the mesh's port assignment earning its keep"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/grafana-module",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/grafana-module/server.env",
|
|
"mode": "0600",
|
|
"content": "GF_SECURITY_ADMIN_PASSWORD=${secret:admin}\n"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/services/grafana/data",
|
|
"mode": "0700",
|
|
"owner": "472:472"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "grafana",
|
|
"image": "grafana/grafana@sha256:f772d434e8fab0049deb2b1b30abd43342bcfca1537614aa8d36080232cf4283",
|
|
"env-file": [
|
|
"/var/lib/grafana-module/server.env"
|
|
],
|
|
"ports": [
|
|
"3000"
|
|
],
|
|
"volumes": [
|
|
"/services/grafana/data:/var/lib/grafana"
|
|
]
|
|
}
|
|
]
|
|
}
|