Beds read the catalogue: a shared loader, eight beds converted, the rest declared
catalogueModule() in the harness reads a module's manifest from the catalogue and rewrites only what the lab must: the build section goes, each artifact becomes the image the machine holds, images are pinned, and a bed may declare a host-port remap or a lab-local address. confluence, gitlab, openai-consumer, audit-logger, ollama, local-model-consumer, model-usage, mosquitto, anthropic-manager and anthropic-consumer now install the catalogue's manifest. A unit test refuses any inline copy naming a catalogue module unless the bed is declared with its reason; the declared list is the debt (novox/hq 04-ISSUES/073).
This commit is contained in:
@@ -24,7 +24,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
|
||||
import { raise } from "../../src/lifecycle/raise.ts";
|
||||
import { destroy, exec } from "../../src/lifecycle/operate.ts";
|
||||
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine, catalogueModule, catalogueIsPresent } from "./harness.ts";
|
||||
import type { HeldImage } from "../../src/pinning.ts";
|
||||
|
||||
const capability = await labIsUsable();
|
||||
@@ -37,7 +37,7 @@ const skip = !capability.usable
|
||||
? "MESH_LAB_HOST_BINARY is not set to a built mesh-host"
|
||||
: !bundle || !existsSync(bundle)
|
||||
? "MESH_LAB_BUNDLE is not set to a foundation bundle (mesh-host examples/)"
|
||||
: false;
|
||||
: catalogueIsPresent();
|
||||
|
||||
const SCENARIO = "openai-bed";
|
||||
const MACHINE = "anchor";
|
||||
@@ -156,7 +156,6 @@ after(async () => {
|
||||
test("a static-key model-access licence delivers the operator's API key to the consumer, unchanged", {
|
||||
skip, timeout: 1_500_000,
|
||||
}, async () => {
|
||||
const consumerImage = pinned("mesh-runtime-openai-consumer");
|
||||
|
||||
// --- the licence, a record with vendor openai (static-key) -------------------------------------
|
||||
// No manager: a static-key licence has none (mesh-controller refuses `licence manager` on it). The
|
||||
@@ -172,33 +171,11 @@ test("a static-key model-access licence delivers the operator's API key to the c
|
||||
await mesh(`licence key personal --file /openai-key`);
|
||||
|
||||
// --- deploy the consumer -----------------------------------------------------------------------
|
||||
// Inline manifest mirroring the committed module.json: a model-access holder whose delivered key
|
||||
// The catalogue's own manifest (novox/hq 04-ISSUES/073): a model-access holder whose delivered key
|
||||
// arrives at its secret path. The scheduled apply container installs as present state (ADR 0053) and
|
||||
// its image is pulled at apply (schedule-pull); the test drives apply directly for a deterministic
|
||||
// flow rather than waiting on cron.
|
||||
const consumerManifest = JSON.stringify({
|
||||
module: "openai-consumer",
|
||||
version: "1",
|
||||
requires: ["model-access"],
|
||||
binds: { "model-access": "/var/lib/openai-consumer/model.json" },
|
||||
secrets: { "model-access": "/var/lib/openai-consumer/api-key" },
|
||||
resources: [
|
||||
{ id: "state", type: "directory", path: "/var/lib/openai-consumer", mode: "0700" },
|
||||
{ id: "config", type: "directory", path: "/var/lib/openai-consumer/config", mode: "0700" },
|
||||
{
|
||||
id: "apply", type: "container", name: "mesh-openai-consumer-apply",
|
||||
image: consumerImage, network: "host", schedule: "*/5 * * * *",
|
||||
args: ["run", "/app/modules/openai-consumer/dist/apply/index.js"],
|
||||
volumes: ["/var/lib/openai-consumer:/run/state"],
|
||||
env: {
|
||||
MESH_MODEL_ACCESS_SECRET_FILE: "/run/state/api-key",
|
||||
MESH_MODEL_ACCESS_BIND_FILE: "/run/state/model.json",
|
||||
MESH_OPENAI_ENV_FILE: "/run/state/config/openai.env",
|
||||
MESH_OPENAI_CREDENTIALS_FILE: "/run/state/config/auth.json",
|
||||
},
|
||||
},
|
||||
],
|
||||
});
|
||||
const consumerManifest = catalogueModule("openai-consumer", held);
|
||||
await must(`printf %s ${quote(consumerManifest)} > /tmp/openai-consumer.json && docker cp /tmp/openai-consumer.json mesh-controller:/openai-consumer.json`);
|
||||
await mesh(`module add /openai-consumer.json`);
|
||||
await mesh(`module issue openai-consumer --node ${MACHINE}`);
|
||||
|
||||
Reference in New Issue
Block a user