Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a734d427c0 | ||
|
|
f2d6ab3bf9 |
@@ -139,8 +139,15 @@ nothing. That is `novox/hq` 04-ISSUES/005 exactly, and it has now been rediscove
|
||||
is written down here rather than reconstructed a third time.
|
||||
|
||||
```sh
|
||||
# Built with `make SYSTEM=arch build`, NOT with a bare `go build`. The system a host was built for
|
||||
# is a link-time value, and one built without it refuses everything it is given with "this host was
|
||||
# built for \"\", which is not a system it knows" — which reads like a broken bundle and is not
|
||||
# (novox/hq 04-ISSUES/146).
|
||||
export MESH_LAB_HOST_BINARY=<mesh-host>/mesh-host
|
||||
export MESH_LAB_BUNDLE=<mesh-host>/examples/foundation-first-node.lock
|
||||
# The bundle that raises the bus the mesh runs on. The other one in that directory raises the
|
||||
# predecessor's broker and a control plane that crash-loops on a missing MESH_BUS_NATS — which
|
||||
# looks like a broken lab and is a bundle nobody moved (novox/hq 04-ISSUES/146).
|
||||
export MESH_LAB_BUNDLE=<mesh-host>/examples/foundation-first-node-nats.lock
|
||||
export MESH_LAB_MODULES=<mesh-controller>/examples/modules
|
||||
export MESH_LAB_BUILDER=<mesh-controller>/build/mesh-builder # build/, which is git-ignored
|
||||
|
||||
@@ -163,6 +170,22 @@ export MESH_LAB_OBJECTSTORE_PROVISIONER=<somewhere>/objectstore-provisioner
|
||||
export MESH_LAB_ROUTE_PROXY=<somewhere>/route-proxy
|
||||
```
|
||||
|
||||
### When a bed fails, before anything else
|
||||
|
||||
Three habits, each of which cost a run on 2026-09-29 before it was adopted (novox/hq
|
||||
04-ISSUES/146):
|
||||
|
||||
- **`MESH_LAB_KEEP=1` leaves the machine standing.** Every answer in that sequence came from
|
||||
shelling into it afterwards — the host's log, the bus's log, the file the bus was actually given,
|
||||
the identity the node actually stored. The test output said only that nothing had converged.
|
||||
- **`MESH_LAB_WARM=1` between attempts.** A fault found on the fifth run is a fault the first four
|
||||
runs paid full price for; warm restores a snapshot instead of raising a machine, and a commit
|
||||
invalidates it, so it is safe to leave on while iterating and off for the run that counts.
|
||||
- **Rebuild what the bed places, not just what you changed.** The host binary, the control-plane
|
||||
image and the bundle are three repositories, and a bed testing yesterday's binary reports on code
|
||||
nobody is looking at (04-ISSUES/005). `make image` in mesh-controller reads its base from the
|
||||
manifest, so it no longer needs a digest found by hand.
|
||||
|
||||
`MESH_LAB_HOST_BINARY` and `MESH_LAB_MODULES` do double duty: the repository each sits in is what
|
||||
`suite` rebuilds and what the receipt claims. Point the run at a repository and it is built and
|
||||
claimed; leave it out and it is neither. `MESH_LAB_CATALOG` is claimed without being built as a
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
*
|
||||
* MESH_LAB_INCUS='sudo -n incus'
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host/mesh-host
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
*/
|
||||
import { test, before, after } from "node:test";
|
||||
|
||||
@@ -34,7 +34,7 @@
|
||||
*
|
||||
* MESH_LAB_INCUS='sudo -n incus'
|
||||
* MESH_LAB_HOST_BINARY=<mesh-host>/mesh-host MESH_LAB_BOOTSTRAP_BINARY=<mesh-host>/mesh-bootstrap
|
||||
* MESH_LAB_BUNDLE=<mesh-host>/examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=<mesh-host>/examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=<mesh-catalog>/modules MESH_LAB_MODULES=<mesh-controller>/examples/modules
|
||||
* MESH_TOOLS=<mesh-tools> MESH_SDK=<mesh-sdk> (default: the checkouts beside this one)
|
||||
* MESH_LAB_KEEP=1 leave it standing MESH_LAB_WARM=1 iterate from the adopted foundation
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
* in for the authenticated cross-node call a manager node would make). The node-private-key stub of
|
||||
* the earlier cut is GONE — the host uses its own real key.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* Build both runtime images into the local daemon first:
|
||||
* scripts/build-module-runtime.sh anthropic-manager /tmp/anthropic-manager.tar
|
||||
* scripts/build-module-runtime.sh anthropic-consumer /tmp/anthropic-consumer.tar
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
* It needs the host binary, the foundation bundle, and the runtime image the scenario loads:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-runtime-image.sh builds mesh-runtime-audit:development into the local daemon,
|
||||
* which scenarios/audit-node.yml stocks — so no MESH_LAB_RUNTIME here; the host pulls it.
|
||||
*/
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
* would say nothing at all about removal — which is the half issue 129 asked for by name.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
* step-ca's image is upstream, pinned by the catalogue, pulled by the machine over its uplink.
|
||||
* ca-trust carries no image: a script, a unit, and the machine's own systemd.
|
||||
@@ -118,6 +118,23 @@ async function register(module: string): Promise<void> {
|
||||
await mesh(`module add /${module}.json`);
|
||||
}
|
||||
|
||||
/**
|
||||
* Put the mesh's composed user list where this machine's bus reads it, and make it re-read.
|
||||
*
|
||||
* **What genesis has to do by hand, and only genesis** (novox/hq 04-ISSUES/146). Every account on
|
||||
* the bus reaches it in the declaration of the machine that runs it — which requires that machine
|
||||
* to be an enrolled node, and at genesis it is not. So until the bus is a module, the composition
|
||||
* is placed by whoever is raising the machine: the control plane says what it composed, and this
|
||||
* writes it beside the bus's configuration. Twice, because two accounts come into existence at
|
||||
* different moments — the enrolment when the token is issued, and the node's own when it enrols.
|
||||
*/
|
||||
async function composeTheBusUsers(): Promise<void> {
|
||||
await must(
|
||||
`docker exec mesh-controller /mesh-controller broker accounts > /var/lib/mesh-bus-conf/accounts.conf && ` +
|
||||
`docker kill -s HUP mesh-broker`,
|
||||
);
|
||||
}
|
||||
|
||||
/** Dial the authority the way anything on this machine would: verifying, with nothing handed to it. */
|
||||
async function verifying(): Promise<{ out: string; ok: boolean }> {
|
||||
return on(`curl --silent --show-error --max-time 10 ${AUTHORITY}`);
|
||||
@@ -155,11 +172,20 @@ before(async () => {
|
||||
|
||||
await mesh(`node add ${MACHINE}`);
|
||||
const token = tokenFrom(await mesh(`token issue --node ${MACHINE}`));
|
||||
// The account that token is the password of exists in the mesh's records now; this is what puts
|
||||
// it on the bus, because nothing else can until this machine is a node.
|
||||
await composeTheBusUsers();
|
||||
await must(`${HOST_PATH} enrol --token ${quote(token)}`);
|
||||
// And again for the credential enrolment just minted, which the machine's own link connects with.
|
||||
await composeTheBusUsers();
|
||||
await must(`nohup ${HOST_PATH} run > /var/log/mesh-host.log 2>&1 & sleep 3`);
|
||||
}, { timeout: 1_800_000 });
|
||||
|
||||
after(async () => {
|
||||
if (process.env["MESH_LAB_KEEP"]) {
|
||||
console.log(`MESH_LAB_KEEP set — leaving ${instanceId} standing`);
|
||||
return;
|
||||
}
|
||||
if (instanceId) await destroy(instanceId);
|
||||
await destroyAll(`${SCENARIO}-`);
|
||||
}, { timeout: 600_000 });
|
||||
@@ -167,9 +193,20 @@ after(async () => {
|
||||
test("the mesh's authority is verified on a machine holding ca-trust, and not on one that is not", {
|
||||
skip, timeout: 1_800_000,
|
||||
}, async () => {
|
||||
// The authority first, on its own. Nothing about trust yet.
|
||||
// The private network first. The authority certifies itself for the address it holds there
|
||||
// (`${machine:at}`), which a machine with no overlay has not got — so this is what the bed needs
|
||||
// it for, and nothing else.
|
||||
await mesh(`overlay place ${MACHINE} --hub --endpoint 192.0.2.10:51820 --site lab`);
|
||||
// The control plane ships this one — its resources are computed per node, so there is no
|
||||
// manifest to register.
|
||||
await mesh(`assign ${MACHINE} networking`);
|
||||
await mesh(`push ${MACHINE}`);
|
||||
await settled();
|
||||
|
||||
// The authority next, on its own. Nothing about trust yet.
|
||||
await register("step-ca");
|
||||
await mesh(`module issue step-ca --node ${MACHINE}`);
|
||||
// No `module issue`: that delivers a bus account, and the authority declares none — its own
|
||||
// secret is the password it initialises itself with, which the mesh mints at assignment.
|
||||
await mesh(`assign ${MACHINE} step-ca`);
|
||||
await mesh(`push ${MACHINE}`);
|
||||
await settled();
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
*
|
||||
* All are assigned to the one anchor, pushed ONCE, and the node converges ONCE with every one up.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh {mongodb,unifi,postgres} build the runtime images into the local
|
||||
* daemon; scenarios/catalogue-apps.yml stocks them. mongo:7, lscr.io/linuxserver/unifi-controller
|
||||
* and synesthesiam/marytts must be in the local daemon to be stocked.
|
||||
|
||||
@@ -23,7 +23,7 @@
|
||||
*
|
||||
* All is assigned to the one anchor, pushed ONCE, and the node converges ONCE with both modules up.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh {sonarr,radarr} build the runtime images into the local daemon;
|
||||
* scenarios/catalogue-media.yml stocks them. lscr.io/linuxserver/{sonarr,radarr} must be in the
|
||||
* local daemon; the service images are pulled from the internet. Each *arr runtime is given a lab
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
* the seed), and mosquitto's provisioner — running in the assigned runtime — creates a scoped client
|
||||
* for a contribution the mesh delivered, which then authenticates with the password the mesh minted.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh mosquitto builds mesh-runtime-mosquitto:development (carrying
|
||||
* mosquitto_ctrl and the compiled bootstrap entrypoint) into the local daemon, which
|
||||
* scenarios/catalogue-mqtt.yml stocks. eclipse-mosquitto:2 must be in the local daemon to be
|
||||
|
||||
@@ -18,7 +18,7 @@
|
||||
* path is fulfilled by creating the consumer's login with the mesh-minted password — it seals nothing
|
||||
* and needs no seal key (novox/hq ADR 0048, issue 032-provider-runtime-has-no-seal-key).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh {postgres,redis,minio,plex} build the four runtime images into the
|
||||
* local daemon; scenarios/catalogue-small.yml stocks them. postgres:17-alpine, redis:7-alpine and
|
||||
* minio/minio:latest is pulled from the internet by the node itself.
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
* It needs a host binary and the foundation bundle:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*
|
||||
* HELPER — stock the two runtimes into the local daemon before the run (some may already be there):
|
||||
* scripts/build-module-runtime.sh postgres /tmp/postgres.tar
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
* registry by digest; the host pulls and runs it on the cadence.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host (feat/apply-schedule — the scheduler that fires the step)
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_MODULES=.../mesh-controller/examples/modules (feat/schedule-container — the parser that
|
||||
* carries `schedule` through). scenarios/schedule-tick.yml stocks alpine:latest (which must be in
|
||||
* the local daemon) and serves it by digest; there is no runtime image — schedtest is a bare tick.
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
* A tool would only fail if it were actually invoked without real creds — which this bed does not do,
|
||||
* because the point is exactly that serving does not require them.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh confluence builds mesh-runtime-confluence:development into the
|
||||
* local daemon; scenarios/tools-confluence.yml stocks it. There is no service image.
|
||||
*/
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
* A tool would only fail if it were actually invoked without real creds — which this bed does not do,
|
||||
* because the point is exactly that serving does not require them.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh gitlab builds mesh-runtime-gitlab:development into the local
|
||||
* daemon; scenarios/tools-gitlab.yml stocks it. There is no service image — gitlab is tools-only.
|
||||
*/
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
* It needs a host binary and the foundation bundle:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*
|
||||
* HELPER — stock the three runtimes into the local daemon before the run (some may already be there):
|
||||
* scripts/build-module-runtime.sh postgres /tmp/postgres.tar
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
* The manifests are the catalogue's own (../mesh-catalog/modules/{mesh-vault,redis}/module.json), with
|
||||
* the runtime artifact named as the image the lab built, exactly as the other assigned-* beds do.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh mesh-vault / redis build the two runtime images into the local
|
||||
* daemon; scenarios/vault-node.yml stocks them.
|
||||
*/
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
* by the firewall the nftables module derives (issues 055/056/057 in one bed).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BOOTSTRAP_BINARY=.../mesh-bootstrap
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock (the TEMPLATE)
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock (the TEMPLATE)
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
* MESH_LAB_SOURCE=git://<forge>/mesh-controller.git MESH_LAB_SOURCE_REF=<commit>
|
||||
* MESH_LAB_BUILD_REF=<branch or commit for module builds, default main>
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
* It needs the host binary and the foundation bundle, like the mesh walk, plus a runtime image:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_RUNTIME=.../mesh-runtime-audit.tar (docker save of the runtime+audit-logger image;
|
||||
* built by scripts/build-runtime-image.sh)
|
||||
*
|
||||
|
||||
@@ -31,7 +31,7 @@
|
||||
* MESH_LAB_INCUS='sudo -n incus'
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host/mesh-host
|
||||
* MESH_LAB_BOOTSTRAP_BINARY=.../mesh-host/mesh-bootstrap
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
* MESH_LAB_SOURCE=<forge>/mesh-controller.git MESH_LAB_SOURCE_REF=<commit>
|
||||
* MESH_LAB_KEEP=1 to leave it standing afterwards
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
* MESH_LAB_INCUS='sudo -n incus'
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host/mesh-host
|
||||
* MESH_LAB_BOOTSTRAP_BINARY=.../mesh-host/mesh-bootstrap
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
* MESH_LAB_KEEP=1 to leave it standing afterwards
|
||||
*/
|
||||
|
||||
@@ -23,7 +23,7 @@ import { mustBeHandedOver, pinnedInto, referenceFor, repositoryOf, type HeldImag
|
||||
/**
|
||||
* The example bundle in mesh-host names a registry that no longer exists.
|
||||
*
|
||||
* `examples/foundation-first-node.lock` was written **for a target**, and the target was the lab: it
|
||||
* `examples/foundation-first-node-nats.lock` was written **for a target**, and the target was the lab: it
|
||||
* pins `192.0.2.250:5000/…` because that is where the registry the lab used to raise served from.
|
||||
* That registry is gone, so those three references name nothing.
|
||||
*
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
* its vhost — the provider named the vhost after the login — and nothing is hardcoded; the provider's
|
||||
* `serves` carries the port so the consumer references `${bound:amqp:port}`.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*
|
||||
* HELPER — stock the two runtimes into the local daemon before the run (some may already be there):
|
||||
* scripts/build-module-runtime.sh lavinmq /tmp/lavinmq.tar
|
||||
|
||||
@@ -15,7 +15,7 @@
|
||||
* asserts the templated URL and that a request to it reaches the running server (ollama answers
|
||||
* /v1/models even with no model pulled — the wiring is what is proven, not a model's output).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* No module runtime image is built — both modules are pure declaration.
|
||||
*/
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
* Mint on one side and create on the other agreeing, with no shared key and nothing placed by the
|
||||
* test, is the entire provider/consumer contract working as one thing.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh redis builds mesh-runtime-redis:development, which
|
||||
* scenarios/redis-node.yml stocks.
|
||||
*/
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
* It needs a host binary and the foundation bundle:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*
|
||||
* The bundle's image references are rewritten to the ones this scenario's own registry serves.
|
||||
* A digest belongs to whatever registry serves it, so a committed bundle names a registry that is
|
||||
|
||||
@@ -31,7 +31,7 @@
|
||||
* MESH_LAB_INCUS='sudo -n incus'
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host/mesh-host
|
||||
* MESH_LAB_BOOTSTRAP_BINARY=.../mesh-host/mesh-bootstrap
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../mesh-host/examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
* MESH_LAB_SOURCE=<forge>/mesh-controller.git MESH_LAB_SOURCE_REF=<commit>
|
||||
* MESH_LAB_KEEP=1 to leave it standing afterwards
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
* ordinary sealed-delivery path — with NO manager, NO refresh, NO access/refresh split, NO usage. The
|
||||
* whole of OpenAI's integration in the control plane is one registry line (vendor -> static-key).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* Build the consumer runtime image into the local daemon first:
|
||||
* scripts/build-module-runtime.sh openai-consumer /tmp/openai-consumer.tar
|
||||
*/
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
* publicly-trusted certificate and answering an HTTP-01 challenge at the name — is proven separately
|
||||
* by certificates.test.ts, which drives the same proxy binary against a real ACME server (Pebble).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-route-proxy-image.sh builds mesh-route-proxy:development into the local daemon;
|
||||
* scenarios/route-forwarding.yml stocks it and alpine:latest, and serves both by digest.
|
||||
*/
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
* the container was replaced (a new container id) and the config on disk carries the new value.
|
||||
* It builds the host from source (no --no-build), because the behaviour under test is the host's.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh grafana builds mesh-runtime-grafana:development, which
|
||||
* scenarios/grafana-node.yml stocks.
|
||||
*/
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
* It needs a host binary and the foundation bundle:
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*/
|
||||
import { test, before, after } from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
|
||||
@@ -20,7 +20,7 @@
|
||||
* references of OURS are rewritten to the IDs the machine holds, and the co-located
|
||||
* host-port collisions are remapped at load time (see REMAP).
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
*/
|
||||
|
||||
import { test, before, after } from "node:test";
|
||||
|
||||
@@ -50,7 +50,7 @@
|
||||
* (whole-mesh-full-live) and NOT torn down — it is left standing and browsable. Without it the bed
|
||||
* behaves like every other: raise in before(), destroy in after().
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* MESH_LAB_BOOTSTRAP_BINARY=.../mesh-bootstrap MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
*/
|
||||
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
* host ports here (container ports unchanged); the provider ports the consumers actually connect to
|
||||
* (postgres 5432, minio 9000, mongodb 27017, mssql 1433) are left as-is. See REMAP below.
|
||||
*
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
* MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node-nats.lock
|
||||
* scripts/build-module-runtime.sh builds one runtime per module that has code; the route-proxy image
|
||||
* is built by scripts/build-route-proxy-image.sh; scenarios/whole-mesh-novox.yml stocks them all
|
||||
* alongside every server image.
|
||||
|
||||
Reference in New Issue
Block a user