Files
mesh-lab/scenarios/catalogue-small.yml
T
jschoubben ab04dd814f Add catalogue-small co-residence bed (four modules, one push)
Raises the first-node substrate and assigns postgres, minio, redis and
plex to one anchor in a single push, proving they resolve and come up
together on one node. postgres and minio each get a consumer that
connects with a real granted credential.

redis follows the corrected provider contract (ADR 0048, issue 032): its
runtime reconciles the contributions the mesh delivers at MESH_RECEIVES
and creates each consumer's ACL user with the mesh-minted password,
sealing nothing — no MESH_SEAL_KEY, no *.grant.json/*.credential path.
The provisioning proof authenticates as the consumer with the mesh's
password (PONG), matching the green provider-uses-mesh-credential bed.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-05 14:14:56 +02:00

51 lines
2.2 KiB
YAML

# One machine that becomes a mesh and is then assigned FOUR modules at once — the first bed that
# proves multi-module co-residence (the migration-rehearsal shape, novox/hq 04-ISSUES/012 context).
#
# The per-backend beds each assign one module: postgres (a database provider), minio (an object-store
# provider), redis (a cache provider + tools), plex (a tools module). This raises the same first-node
# substrate and then assigns all four to the one anchor in a single push, so the proof is that they
# resolve and come up TOGETHER on one node — nothing new about any single module, everything new about
# their co-residence.
#
# The four are chosen because none of them share a directory, so the shared-workspace refusal
# (novox/hq 04-ISSUES/012 — the media stack) does not bite here; that class stays for a later bed.
#
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock
# scripts/build-module-runtime.sh {postgres,redis,minio,plex} build the four runtime images into the
# local daemon (postgres carries psql, minio carries mc), which this scenario stocks and serves by
# digest from its own registry. The service images must be in the local daemon to be stocked.
scenario: catalogue-small
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
inbound: allow
# Sized up: this anchor runs the substrate (store, broker, control) plus four modules — three of
# which are a server container and a runtime container each — so a dozen containers at once. The
# single-module beds run at 3GiB; co-residence needs the headroom.
memory: 6GiB
cpus: 4
images:
# The first-node substrate: store, broker, control.
- postgres:17-alpine
- cloudamqp/lavinmq:latest
- mesh-control:development
# The module server images.
- redis:7-alpine
- minio/minio:latest
# The four per-module runtimes, built by scripts/build-module-runtime.sh and stocked here. plex
# needs no server image in the lab — its runtime serves tools with no Plex to reach.
- mesh-runtime-postgres:development
- mesh-runtime-redis:development
- mesh-runtime-minio:development
- mesh-runtime-plex:development
place:
all: [host, runtime]