anthropic bed: package a module's own npm deps, stage grant files readably

Two harness fixes the green end-to-end run needed:

- build-module-runtime.sh installs a module's non-@novox runtime deps under
  /app/modules/<module>/node_modules, so a module can carry a private dependency
  (the anthropic-manager seals with tweetnacl-sealedbox-js). The shared tree still
  answers @novox/* and common packages. A no-op for modules that declare none.

- stageIntoControl chmods the manager's 0600 adopt/refresh outputs to 0644 on the
  anchor host before docker cp, so the distroless mesh-control (non-root, no chmod)
  can read the staged file. What is staged is a sealed box or the access token,
  never a cleartext refresh token.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-07 02:47:50 +02:00
parent 71bea08f3b
commit 87c4820130
2 changed files with 26 additions and 3 deletions
+12
View File
@@ -38,6 +38,18 @@ cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules"
mkdir -p "$STAGE/modules/$MODULE"; cp -r "$MOD/dist" "$STAGE/modules/$MODULE/dist"
cp "$MESH_TOOLS/package.json" "$STAGE/package.json"
# A module may declare its own third-party runtime deps (the anthropic-manager seals with
# tweetnacl-sealedbox-js). The shared node_modules copied above carries the common packages and
# @novox/* — but not a module's private deps. Install those under the module itself, so Node
# resolves them from /app/modules/<module>/node_modules and still falls back to the shared tree
# at /app/node_modules for @novox/* and everything common. Modules with no non-@novox deps are a
# no-op. (@novox/* are workspace deps with no registry to fetch from, so they are excluded here.)
MOD_DEPS="$(node -e 'const d=(require("'"$MOD"'/package.json").dependencies)||{};process.stdout.write(Object.keys(d).filter(k=>!k.startsWith("@novox/")).map(k=>k+"@"+d[k]).join(" "))')"
if [ -n "$MOD_DEPS" ]; then
# shellcheck disable=SC2086
npm install --prefix "$STAGE/modules/$MODULE" --omit=dev --no-save --no-package-lock --ignore-scripts $MOD_DEPS >/dev/null
fi
# The entrypoints the runtime loads: tools, events and (a provider's) provisioner, whichever exist.
ENTRIES=""; for e in tools/index.js index.js provisioner/index.js; do
[ -f "$STAGE/modules/$MODULE/dist/$e" ] && ENTRIES="${ENTRIES:+$ENTRIES,}/app/modules/$MODULE/dist/$e"