Both image scripts copied the runtime's installed tree and relied on the sdk inside it being a link into the sibling repository. That is true only where somebody linked them by hand, and false as soon as the dependencies are installed the ordinary way — which fetches the sdk as sources with nothing compiled. The image still built, and every entry point in it pointed at nothing.
68 lines
2.9 KiB
Bash
Executable File
68 lines
2.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Build the runtime+audit-logger image the events test runs, and save it to a tar.
|
|
#
|
|
# The image is the tier-3 tool runtime (mesh-tools) carrying one tier-4 module (audit-logger) and
|
|
# the sdk it imports. It is what MESH_LAB_RUNTIME points at:
|
|
#
|
|
# scripts/build-runtime-image.sh /tmp/mesh-runtime-audit.tar
|
|
# MESH_LAB_RUNTIME=/tmp/mesh-runtime-audit.tar node --test test/integration/events.test.ts
|
|
#
|
|
# The sdk is vendored (dereferenced), not npm-installed: the sdk is not published, and the lab
|
|
# machine has no route out anyway — the image must be self-contained. Sibling repositories are
|
|
# assumed alongside this one; override with MESH_TOOLS / MESH_SDK / MESH_CATALOG.
|
|
set -euo pipefail
|
|
|
|
OUT="${1:?usage: build-runtime-image.sh <output.tar>}"
|
|
HERE="$(cd "$(dirname "$0")/.." && pwd)"
|
|
ROOT="$(cd "$HERE/.." && pwd)"
|
|
MESH_TOOLS="${MESH_TOOLS:-$ROOT/mesh-tools}"
|
|
MESH_SDK="${MESH_SDK:-$ROOT/mesh-sdk}"
|
|
MESH_CATALOG="${MESH_CATALOG:-$ROOT/mesh-catalog}"
|
|
AUDIT="$MESH_CATALOG/modules/audit-logger"
|
|
TAG="${RUNTIME_TAG:-mesh-runtime-audit:development}"
|
|
BASE="${RUNTIME_BASE:-node:22-bookworm-slim}"
|
|
|
|
echo "building $TAG from:"
|
|
echo " runtime $MESH_TOOLS"
|
|
echo " sdk $MESH_SDK"
|
|
echo " module $AUDIT"
|
|
|
|
# Compile the three, so the image carries current dist. The sdk first — the others import it.
|
|
( cd "$MESH_SDK" && npm run build >/dev/null )
|
|
( cd "$MESH_TOOLS" && npm run build >/dev/null )
|
|
( cd "$AUDIT" && npx tsc audit.ts index.ts --module NodeNext --moduleResolution NodeNext \
|
|
--target ES2022 --outDir dist >/dev/null )
|
|
|
|
STAGE="$(mktemp -d)"
|
|
trap 'rm -rf "$STAGE"' EXIT
|
|
cp -r "$MESH_TOOLS/dist" "$STAGE/dist"
|
|
cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules"
|
|
# And the sdk, from the sibling this script just built, whatever form the installed tree holds it
|
|
# in. It used to be relied on being a symlink into that sibling, which `-L` above materialised —
|
|
# true only on a workstation where somebody had linked them, and false the moment the runtime's
|
|
# dependencies are installed the ordinary way, which now fetches the sdk as sources with nothing
|
|
# compiled in it. The image built then looked fine and every entry point inside it pointed at
|
|
# nothing.
|
|
rm -rf "$STAGE/node_modules/@novox/mesh-sdk"
|
|
mkdir -p "$STAGE/node_modules/@novox"
|
|
cp -rL "$MESH_SDK" "$STAGE/node_modules/@novox/mesh-sdk"
|
|
rm -rf "$STAGE/node_modules/@novox/mesh-sdk/node_modules" # -L materialises the @novox/mesh-sdk symlink
|
|
mkdir -p "$STAGE/modules/audit-logger"
|
|
cp -r "$AUDIT/dist" "$STAGE/modules/audit-logger/dist"
|
|
cp "$MESH_TOOLS/package.json" "$STAGE/package.json"
|
|
|
|
cat > "$STAGE/Dockerfile" <<DOCKER
|
|
FROM $BASE
|
|
WORKDIR /app
|
|
COPY package.json ./
|
|
COPY node_modules ./node_modules
|
|
COPY dist ./dist
|
|
COPY modules ./modules
|
|
ENV MESH_TOOL_MODULES=/app/modules/audit-logger/dist/index.js
|
|
ENTRYPOINT ["node", "dist/main.js"]
|
|
DOCKER
|
|
|
|
docker build -t "$TAG" "$STAGE"
|
|
docker save -o "$OUT" "$TAG"
|
|
echo "saved $TAG -> $OUT"
|