lab: provider runtime images carry their CLI; prove the private-network shape

build-module-runtime.sh adds psql to the postgres image and mc to the minio image
(their clients shell out to those). provider-on-backend-network asserts redis's
runtime, on the backend's private network, binds the broker via NAT and provisions
a consumer with the mesh's credential — the shape the committed provider manifests use.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 00:52:17 +02:00
parent aafa11756a
commit 33b991b6e0
2 changed files with 241 additions and 0 deletions
+9
View File
@@ -35,9 +35,18 @@ ENTRIES=""; for e in tools/index.js index.js provisioner/index.js; do
[ -f "$STAGE/modules/$MODULE/dist/$e" ] && ENTRIES="${ENTRIES:+$ENTRIES,}/app/modules/$MODULE/dist/$e"
done
# A module whose code drives a CLI needs that CLI in the image — postgres shells out to `psql`, minio
# to `mc`. Everything else speaks a wire protocol or HTTP and needs nothing added.
EXTRA=""
case "$MODULE" in
postgres) EXTRA='RUN apt-get update && apt-get install -y --no-install-recommends postgresql-client && rm -rf /var/lib/apt/lists/*' ;;
minio) EXTRA='COPY --from=minio/mc:latest /usr/bin/mc /usr/bin/mc' ;;
esac
cat > "$STAGE/Dockerfile" <<DOCKER
FROM $BASE
WORKDIR /app
$EXTRA
COPY package.json ./
COPY node_modules ./node_modules
COPY dist ./dist