# One machine that becomes a mesh and then assigns itself mosquitto — the bed that proves the # run-once primitive (novox/hq ADR 0052) end to end. # # mosquitto is the sharp case ADR 0052 was written for: its Dynamic Security plugin loads at broker # start and refuses to come up unless `dynamic-security.json` already holds an admin client. That # file is not state a reconcile loop can carry — it is a step that must run once, after the data # directory exists and BEFORE the broker container starts. mosquitto's manifest declares that step # as a `run-once: true` init container, placed before the `server` (broker) container: the same # runtime image, carrying mosquitto's own `bootstrap/` entrypoint and `mosquitto_ctrl`, run to # completion under the module's own account. The host runs it, requires exit 0, and only then reaches # the broker — so "the broker came up" is itself the proof the seed ran, because an unseeded store # crash-loops the broker. # # MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock # scripts/build-module-runtime.sh mosquitto builds mesh-runtime-mosquitto:development (carrying # mosquitto_ctrl and the compiled bootstrap entrypoint) into the local daemon, which this scenario # stocks and serves by digest from its own registry. eclipse-mosquitto:2 must be in the local # daemon to be stocked. scenario: catalogue-mqtt segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } inbound: allow memory: 3GiB cpus: 2 images: # The first-node substrate: store, broker, control. - postgres:17-alpine - cloudamqp/lavinmq:latest - mesh-control:development # mosquitto's broker (the service image) and its runtime, the latter built by # scripts/build-module-runtime.sh mosquitto into the local daemon and stocked into the scenario's # own registry, which is where the host pulls it from. The runtime image is reused for the # run-once bootstrap step and for the serve container. - eclipse-mosquitto:2 - mesh-runtime-mosquitto:development place: all: [host, runtime]