A module's name is its tool namespace and its broker scope, so a fixture running the module's runtime cannot carry another name (novox/hq ADR 0093). The grant and backend-network beds now read the catalogue's redis and install mesh-vault, which provides the secret it requires; the redis-node scenario stocks the vault's runtime. The remaining declared copies say why they stand (novox/hq 04-ISSUES/074).
33 lines
1.1 KiB
YAML
33 lines
1.1 KiB
YAML
# One machine that becomes a mesh and then assigns itself redis — a *provider* module.
|
|
#
|
|
# plex-node proves an assigned module that serves tools (novox/hq ADR 0052). This proves the same
|
|
# for a provider: redis's runtime runs its provisioner AND its tools as one process under one scoped
|
|
# broker account. The provisioner emitting a lifecycle event is the thing 0052 fixes — before it,
|
|
# the provisioner ran in a container with no broker and its emit could not fire.
|
|
scenario: redis-node
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24]
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10] }
|
|
egress: true
|
|
inbound: allow
|
|
memory: 3GiB
|
|
cpus: 2
|
|
|
|
images:
|
|
- mesh-controller:development
|
|
# Redis's tool+provisioner runtime, built by scripts/build-module-runtime.sh redis into the local
|
|
# daemon and loaded onto the machine, which holds it by its own image ID.
|
|
- mesh-runtime-redis:development
|
|
# The vault's, for the beds that install the catalogue's redis: its own password is a secret the
|
|
# vault provides (novox/hq ADR 0085).
|
|
- mesh-runtime-mesh-vault:development
|
|
|
|
place:
|
|
all: [host, runtime]
|