Found by reading the manifests rather than by running them. Two of the provisioner images the examples name had no way to be produced: the object store's had a Dockerfile and no target, and Keycloak's did not exist at all — no image, no Dockerfile, no program. A module naming an image nothing produces resolves, plans, pushes and stops on the machine at `docker pull`, which is the fault arriving as far from its cause as it can get. The object store's target is added. Keycloak's provisioner is removed from its manifest, because writing a manifest for a program that does not exist is the same mistake as the .env files: it parses, it resolves, and it could never work. That makes keycloak's manifest true about today — a server the mesh runs, with its database and its admin credential — and it makes the gap loud. Keycloak no longer claims to provide oidc-client, so a consumer asking for one is refused at plan time by name, rather than resolving cleanly and never having a client created. The check covers only images beginning `mesh-`. Postgres and the rest come from a registry and are somebody else's to build; what this bounds is the set this repository is responsible for and might forget.
42 lines
1.6 KiB
JSON
42 lines
1.6 KiB
JSON
{
|
|
"module": "keycloak",
|
|
"version": "1",
|
|
|
|
"requires": ["postgres-database"],
|
|
"contributes": {
|
|
"postgres-database": {"name": "keycloak"}
|
|
},
|
|
"binds": {"postgres-database": "/var/lib/keycloak/database.json"},
|
|
"secrets": {"postgres-database": "/var/lib/keycloak/database.secret"},
|
|
|
|
"capabilities": ["container-runtime"],
|
|
|
|
"listens": [
|
|
{"port": 8080, "protocol": "tcp", "from": "mesh",
|
|
"why": "anything the mesh runs that authenticates a person"}
|
|
],
|
|
|
|
"own-secrets": {"admin": "/var/lib/keycloak/admin.secret"},
|
|
|
|
"resources": [
|
|
{"id": "state", "type": "directory", "path": "/var/lib/keycloak", "mode": "0700"},
|
|
|
|
{"id": "admin-env", "type": "file", "path": "/var/lib/keycloak/admin.env", "mode": "0600",
|
|
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"},
|
|
|
|
{"id": "database-env", "type": "file", "path": "/var/lib/keycloak/database.env", "mode": "0600",
|
|
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/keycloak\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"},
|
|
|
|
{"id": "net", "type": "network", "name": "keycloak"},
|
|
|
|
{"id": "server", "type": "container", "name": "keycloak",
|
|
"image": "keycloak@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "keycloak",
|
|
"args": ["start-dev"],
|
|
"env": {"KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true"},
|
|
"env-file": ["/var/lib/keycloak/admin.env", "/var/lib/keycloak/database.env"],
|
|
"ports": ["8080:8080"],
|
|
"restart-on": ["admin-env", "database-env"]}
|
|
]
|
|
}
|