test/integration/assigned-audit.test.ts raises a node into a mesh, assigns it the audit-logger through the control plane, and asserts the mesh delivered a scoped amqps account (not the broker's own), the host ran the container, and an emitted event reached the trail — the delivered credential authenticating is the proof. scenarios/audit-node.yml is the lean single-node bed that stocks the runtime image. Passes 1/1 against the real lab. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
58 lines
2.2 KiB
Bash
Executable File
58 lines
2.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Build the runtime+audit-logger image the events test runs, and save it to a tar.
|
|
#
|
|
# The image is the tier-3 tool runtime (mesh-tools) carrying one tier-4 module (audit-logger) and
|
|
# the sdk it imports. It is what MESH_LAB_RUNTIME points at:
|
|
#
|
|
# scripts/build-runtime-image.sh /tmp/mesh-runtime-audit.tar
|
|
# MESH_LAB_RUNTIME=/tmp/mesh-runtime-audit.tar node --test test/integration/events.test.ts
|
|
#
|
|
# The sdk is vendored (dereferenced), not npm-installed: the sdk is not published, and the lab
|
|
# machine has no route out anyway — the image must be self-contained. Sibling repositories are
|
|
# assumed alongside this one; override with MESH_TOOLS / MESH_SDK / MESH_CATALOG.
|
|
set -euo pipefail
|
|
|
|
OUT="${1:?usage: build-runtime-image.sh <output.tar>}"
|
|
HERE="$(cd "$(dirname "$0")/.." && pwd)"
|
|
ROOT="$(cd "$HERE/.." && pwd)"
|
|
MESH_TOOLS="${MESH_TOOLS:-$ROOT/mesh-tools}"
|
|
MESH_SDK="${MESH_SDK:-$ROOT/mesh-sdk}"
|
|
MESH_CATALOG="${MESH_CATALOG:-$ROOT/mesh-catalog}"
|
|
AUDIT="$MESH_CATALOG/modules/audit-logger"
|
|
TAG="${RUNTIME_TAG:-mesh-runtime-audit:development}"
|
|
BASE="${RUNTIME_BASE:-node:22-bookworm-slim}"
|
|
|
|
echo "building $TAG from:"
|
|
echo " runtime $MESH_TOOLS"
|
|
echo " sdk $MESH_SDK"
|
|
echo " module $AUDIT"
|
|
|
|
# Compile the three, so the image carries current dist. The sdk first — the others import it.
|
|
( cd "$MESH_SDK" && npm run build >/dev/null )
|
|
( cd "$MESH_TOOLS" && npm run build >/dev/null )
|
|
( cd "$AUDIT" && npx tsc audit.ts index.ts --module NodeNext --moduleResolution NodeNext \
|
|
--target ES2022 --outDir dist >/dev/null )
|
|
|
|
STAGE="$(mktemp -d)"
|
|
trap 'rm -rf "$STAGE"' EXIT
|
|
cp -r "$MESH_TOOLS/dist" "$STAGE/dist"
|
|
cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules" # -L materialises the @novox/mesh-sdk symlink
|
|
mkdir -p "$STAGE/modules/audit-logger"
|
|
cp -r "$AUDIT/dist" "$STAGE/modules/audit-logger/dist"
|
|
cp "$MESH_TOOLS/package.json" "$STAGE/package.json"
|
|
|
|
cat > "$STAGE/Dockerfile" <<DOCKER
|
|
FROM $BASE
|
|
WORKDIR /app
|
|
COPY package.json ./
|
|
COPY node_modules ./node_modules
|
|
COPY dist ./dist
|
|
COPY modules ./modules
|
|
ENV MESH_TOOL_MODULES=/app/modules/audit-logger/dist/index.js
|
|
ENTRYPOINT ["node", "dist/main.js"]
|
|
DOCKER
|
|
|
|
docker build -t "$TAG" "$STAGE"
|
|
docker save -o "$OUT" "$TAG"
|
|
echo "saved $TAG -> $OUT"
|