Found checking whether the named volumes mesh-catalog PR #54/#55 replaced are actually unused before considering them safe to remove -- this repo has its own independent volumes declaration for the same TLS material (mesh-controller reads it directly, not through lavinmq's own resource), and it still named the old mesh-broker-tls volume. Right now the content is identical -- copied once during the conversion. If the cert ever rotates, lavinmq writes the new directory and this would keep reading stale content from the volume nothing else updates. Checked both repos for any other reference to the four converted volume names (mesh-store-data, mesh-broker-data, mesh-broker-tls, mesh-registry-data): this was the only one.
84 lines
2.7 KiB
JSON
84 lines
2.7 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "/var/lib/mesh/mesh-controller/inventory",
|
|
"identity": "/var/lib/mesh/mesh-controller/identity",
|
|
"licences": "/var/lib/mesh/mesh-controller/licences",
|
|
"broker": "/var/lib/mesh/mesh-controller/broker",
|
|
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
|
|
"broker-address": "/var/lib/mesh/mesh-controller/broker-address"
|
|
},
|
|
"secrets-owner": "65534:65534",
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/mesh-controller",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "mesh-controller",
|
|
"network": "host",
|
|
"args": [
|
|
"serve"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
|
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
|
"MESH_BROKER_AMQP_FILE": "/run/secrets/broker",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_AMQP_PORT": "${seat:mesh-broker:5672}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
|
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro",
|
|
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
|
|
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
|
|
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
|
|
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
|
|
],
|
|
"artifact": "server",
|
|
"restart-on": [
|
|
"control-env"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
],
|
|
"on": [
|
|
{
|
|
"arg": "GO_BASE",
|
|
"image": "golang@sha256:1ae0735f00daffa3aaf1363a5184c0d2dc55c78e3db4ec70241cdac97bf84b59"
|
|
}
|
|
]
|
|
}
|
|
}
|