Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
127 lines
3.3 KiB
Plaintext
127 lines
3.3 KiB
Plaintext
{
|
|
"module": "umami",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"postgres-database",
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "umami"
|
|
},
|
|
"route": {
|
|
"label": "umami",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:state}/database.json",
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:state}/database.secret",
|
|
"secret": {
|
|
"app-secret": "${dir:state}/app.secret",
|
|
"admin": "${dir:state}/admin.secret"
|
|
}
|
|
},
|
|
"provides": [
|
|
{
|
|
"name": "analytics",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"serves": {
|
|
"analytics": {}
|
|
},
|
|
"receives": {
|
|
"analytics": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"analytics": "${dir:grants}"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 3000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "one port serves two surfaces — the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path"
|
|
}
|
|
],
|
|
"data": {
|
|
"consumers": {
|
|
"analytics": {
|
|
"class": "valuable",
|
|
"in": "postgres-database",
|
|
"why": "a site's page views are recorded nowhere else"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/server.env",
|
|
"mode": "0600",
|
|
"content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "umami"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "umami",
|
|
"image": "ghcr.io/umami-software/umami@sha256:85909afc45bdcda1917394594a087421fdbb05610fded0fa9f6fb861abb2f367",
|
|
"network": "umami",
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"ports": [
|
|
"3000"
|
|
],
|
|
"secrets-in-environment": "a Next.js/Prisma application: DATABASE_URL and APP_SECRET are read from the environment only; not convertible"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret",
|
|
"MESH_PROVISION_UMAMI_URL": "http://127.0.0.1:${port:3000}"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|