# One machine that becomes a mesh and then assigns itself mosquitto — the bed that proves the # run-once primitive (novox/hq ADR 0052) end to end. # # mosquitto is the sharp case ADR 0052 was written for: its Dynamic Security plugin loads at broker # start and refuses to come up unless `dynamic-security.json` already holds an admin client. That # file is not state a reconcile loop can carry — it is a step that must run once, after the data # directory exists and BEFORE the broker container starts. mosquitto's manifest declares that step # as a `run-once: true` init container, placed before the `server` (broker) container: the same # runtime image, carrying mosquitto's own `bootstrap/` entrypoint and `mosquitto_ctrl`, run to # completion under the module's own account. The host runs it, requires exit 0, and only then reaches # the broker — so "the broker came up" is itself the proof the seed ran, because an unseeded store # crash-loops the broker. # # MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock # scripts/build-module-runtime.sh mosquitto builds mesh-runtime-mosquitto:development (carrying # mosquitto_ctrl and the compiled bootstrap entrypoint) into the local daemon, which this scenario # pulls from the internet over its uplink. eclipse-mosquitto:2 must be in the local # daemon to be stocked. scenario: catalogue-mqtt segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow memory: 3GiB cpus: 2 images: - mesh-control:development - mesh-runtime-mosquitto:development place: all: [host, runtime]