Beds read the catalogue: a shared loader, eight beds converted, the rest declared
catalogueModule() in the harness reads a module's manifest from the catalogue and rewrites only what the lab must: the build section goes, each artifact becomes the image the machine holds, images are pinned, and a bed may declare a host-port remap or a lab-local address. confluence, gitlab, openai-consumer, audit-logger, ollama, local-model-consumer, model-usage, mosquitto, anthropic-manager and anthropic-consumer now install the catalogue's manifest. A unit test refuses any inline copy naming a catalogue module unless the bed is declared with its reason; the declared list is the debt (novox/hq 04-ISSUES/073).
This commit is contained in:
@@ -22,7 +22,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
|
||||
import { raise } from "../../src/lifecycle/raise.ts";
|
||||
import { destroy, exec } from "../../src/lifecycle/operate.ts";
|
||||
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine, catalogueModule, catalogueIsPresent } from "./harness.ts";
|
||||
import type { HeldImage } from "../../src/pinning.ts";
|
||||
|
||||
const capability = await labIsUsable();
|
||||
@@ -35,7 +35,7 @@ const skip = !capability.usable
|
||||
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
|
||||
: !bundle || !existsSync(bundle)
|
||||
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
|
||||
: false;
|
||||
: catalogueIsPresent();
|
||||
|
||||
const SCENARIO = "audit-node";
|
||||
const MACHINE = "anchor";
|
||||
@@ -145,26 +145,10 @@ after(async () => {
|
||||
test("the mesh assigns the audit logger, and it consumes over the account the mesh delivered", {
|
||||
skip, timeout: 900_000,
|
||||
}, async () => {
|
||||
// The assigned-module manifest (mesh-catalog), its runtime image the ID the machine holds.
|
||||
const manifest = JSON.stringify({
|
||||
module: "audit-logger",
|
||||
version: "1",
|
||||
consumes: ["#"],
|
||||
"own-secrets": { broker: "/var/lib/audit-logger/broker" },
|
||||
resources: [
|
||||
{ id: "state", type: "directory", path: "/var/lib/audit-logger", mode: "0700" },
|
||||
{ id: "trail", type: "directory", path: "/var/lib/audit-logger/trail", mode: "0700" },
|
||||
{
|
||||
id: "run", type: "container", name: "mesh-audit-logger", image: pinned("mesh-runtime-audit"),
|
||||
network: "host",
|
||||
volumes: [
|
||||
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/audit-logger/trail:/trail",
|
||||
],
|
||||
env: { MESH_BROKER_FILE: "/run/secrets/broker", AUDIT_LOG: "/trail/audit.log" },
|
||||
},
|
||||
],
|
||||
});
|
||||
// The catalogue's manifest (novox/hq 04-ISSUES/073). Its runtime artifact is the image this
|
||||
// scenario stocks under the module's slug, `mesh-runtime-audit` — built by scripts/build-runtime-image.sh
|
||||
// before build-module-runtime.sh generalised it, and named as it was.
|
||||
const manifest = catalogueModule("audit-logger", held, { artifacts: { runtime: "mesh-runtime-audit" } });
|
||||
await must(`printf %s ${quote(manifest)} > /tmp/audit.json && docker cp /tmp/audit.json mesh-controller:/audit.json`);
|
||||
await mesh("module add /audit.json");
|
||||
|
||||
|
||||
Reference in New Issue
Block a user