Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
176 lines
5.1 KiB
Plaintext
176 lines
5.1 KiB
Plaintext
{
|
|
"module": "nfs-server",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "the folders other machines mount: a build that breaks the exports leaves every client's mount hanging or refused, and the gate on this one machine does not see the clients (hq ADR 0236, ADR 0263)"
|
|
},
|
|
"capabilities": [
|
|
"package-manager",
|
|
"service-manager"
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "nfs-share",
|
|
"scope": "mesh",
|
|
"identity": false
|
|
}
|
|
],
|
|
"data": {
|
|
"consumers": {
|
|
"nfs-share": {
|
|
"class": "none",
|
|
"why": "the shared folders are the operator's data (hq ADR 0051): what a client writes lands in them, and they are protected where the operator declares them, never by this module, which keeps nothing of a consumer's"
|
|
}
|
|
}
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "node-nfs-server",
|
|
"scope": "node",
|
|
"serves": [
|
|
"exports",
|
|
"clients",
|
|
"test",
|
|
"reload",
|
|
"adopt"
|
|
]
|
|
}
|
|
],
|
|
"state": [
|
|
{
|
|
"name": "exports",
|
|
"ttl-seconds": 120,
|
|
"per-machine": true
|
|
}
|
|
],
|
|
"reads": [
|
|
"mounts.shares"
|
|
],
|
|
"invokes": [
|
|
"seat:mesh-controller.seats",
|
|
"seat:mesh-controller.data"
|
|
],
|
|
"settings": {
|
|
"grants": {
|
|
"kind": "preference",
|
|
"default": "none",
|
|
"why": "which nodes may mount which share, and how, is this machine's to say (hq ADR 0263, review of mesh-catalog #136): share=node:rw|ro[,node:rw|ro], entries separated by spaces; none exports to no node, whatever a node wants"
|
|
}
|
|
},
|
|
"facts": {
|
|
"machines": {
|
|
"path": "/etc/nfs-server/machines",
|
|
"template": "# Written by the mesh (module nfs-server, novox/hq ADR 0263): every machine of the mesh and its private\n# address, from which the module takes a node's address. Replaced on every push.\n{{range .Machines}}{{.Name}} {{.Address}}\n{{end}}"
|
|
}
|
|
},
|
|
"tools": [
|
|
"nfs_health"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "nfs",
|
|
"port": 2049,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"fixed": true,
|
|
"why": "the shares, to the mesh's machines only (hq ADR 0263): NFS version 4 alone, which needs no other port, and never the home network, where a device that is not a node could claim any user id"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "nfs-utils"
|
|
},
|
|
{
|
|
"id": "nfs-conf",
|
|
"type": "file",
|
|
"path": "/etc/nfs.conf.d/50-mesh.conf",
|
|
"mode": "0644",
|
|
"content": "# Written by the mesh (module nfs-server, novox/hq ADR 0263). Replaced on every push; a drop-in of\n# the operator's that sorts after this one overrides it, and is theirs.\n#\n# NFS version 4 only: a client needs port 2049 and nothing else, so the module opens nothing more\n# than that, to the private network. Version 3 needs rpcbind and mountd, on ports the mesh does not open.\n[nfsd]\nvers2=n\nvers3=n\nvers4=y\nvers4.0=n\nvers4.1=y\nvers4.2=y\n"
|
|
},
|
|
{
|
|
"id": "run-dir",
|
|
"type": "directory",
|
|
"path": "/run/nfs-server",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "service",
|
|
"unit": "nfs-server.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"nfs-conf"
|
|
],
|
|
"health": {
|
|
"kind": "unit"
|
|
}
|
|
},
|
|
{
|
|
"id": "wants-dir-parent",
|
|
"type": "directory",
|
|
"path": "/var/lib/nfs-server",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "wants-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/nfs-server/from-bus",
|
|
"mode": "0755",
|
|
"owner": "${machine:account}"
|
|
},
|
|
{
|
|
"id": "exports",
|
|
"type": "process",
|
|
"name": "nfs-server-exports",
|
|
"artifact": "tools",
|
|
"run": [
|
|
"./nfs-server",
|
|
"exports"
|
|
],
|
|
"restart-on": [
|
|
"config"
|
|
],
|
|
"health": {
|
|
"kind": "tool",
|
|
"tool": "nfs_health",
|
|
"interval": "60s",
|
|
"timeout": "10s",
|
|
"looks": 2,
|
|
"grace": "90s"
|
|
}
|
|
},
|
|
{
|
|
"id": "config-dir",
|
|
"type": "directory",
|
|
"path": "/etc/nfs-server",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/etc/nfs-server/shares.conf",
|
|
"mode": "0644",
|
|
"content": "# Written by the mesh (module nfs-server, novox/hq ADR 0263) from this machine's assignment.\n# Replaced on every push; change the `shares` setting, never this file.\n#\n# The shares: name=folder, or name=folder:ro, one share per folder. The grants: share=node:rw|ro[,…],\n# which nodes may mount each and how. The module's process exports a share to a node's private address\n# only when it is granted here and that node's mounts module wants it, every client mapped to the\n# folder's owner, and only to addresses inside the range below.\nshares=${setting:shares}\ngrants=${setting:grants}\nrange=${machine:mesh-range}\n"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/nfs-server",
|
|
"binary": "nfs-server",
|
|
"loads": [
|
|
"nfs-server"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|