// substrate-arch.lock — what an Arch machine must be before a mesh exists. // // The first three steps of the bootstrap (novox/hq 03-DESIGN/01-to-be/07-the-substrate.md). // Steps four and five — load the control plane's schema, start the control plane — are absent // because the control plane does not exist yet. A bundle that named it would be a bundle that // cannot be applied. // // PINNED BY DIGEST, and the digest is not decoration: a tag can be made to point at a different // image, and this file is applied on a machine with no mesh to ask about anything. // // The store's data is a NAMED VOLUME rather than a directory on the machine. A directory the // host creates is owned by root, and the database runs as somebody else inside the container — // so it could not write, and the container crash-looped. A named volume lets the image set up // its own ownership, which is what it is for. It also outlives the container, which is what you // want for the thing holding the mesh's state. { "declaration": 1, "resources": [ { "id": "container-runtime", "type": "package", "package": "docker" }, { "id": "container-runtime-running", "type": "service", "unit": "docker.service", "state": "running", "boot": "enabled" }, { "id": "store", "type": "container", "name": "mesh-store", "image": "REGISTRY/postgres@DIGEST", "env": { "POSTGRES_PASSWORD": "bootstrap", "PGDATA": "/var/lib/postgresql/data/pgdata" }, "volumes": ["mesh-store-data:/var/lib/postgresql/data"] }, { "id": "store-ready", "type": "action", "in": "mesh-store", "command": ["sh", "-c", "for i in $(seq 1 60); do pg_isready -U postgres >/dev/null 2>&1 && exit 0; sleep 1; done; exit 1"], "verify": ["pg_isready", "-U", "postgres"] }, { "id": "control-plane-database", "type": "action", "in": "mesh-store", "command": ["sh", "-c", "psql -U postgres -c 'CREATE DATABASE mesh'"], "verify": ["sh", "-c", "psql -U postgres -lqt | cut -d'|' -f1 | grep -qw mesh"] } ] }