Files
mesh-lab/scenarios/audit-node.yml
T
jschoubben 37b16cd0e9 events: the assigned audit-logger, proven in the lab (ADR 0048)
test/integration/assigned-audit.test.ts raises a node into a mesh, assigns it
the audit-logger through the control plane, and asserts the mesh delivered a
scoped amqps account (not the broker's own), the host ran the container, and an
emitted event reached the trail — the delivered credential authenticating is
the proof. scenarios/audit-node.yml is the lean single-node bed that stocks the
runtime image. Passes 1/1 against the real lab.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-04 02:13:01 +02:00

31 lines
962 B
YAML

# One machine that becomes a mesh and then assigns itself the audit logger.
#
# The substrate is first-node's — a store, a broker, the control plane — and one module image on
# top: the tool runtime carrying the audit-logger (mesh-catalog). The node enrols itself and the
# mesh assigns it the audit logger, so its events account is one the mesh delivered, not the
# broker's own (novox/hq ADR 0048).
scenario: audit-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
inbound: allow
memory: 3GiB
cpus: 2
images:
- postgres:17-alpine
- cloudamqp/lavinmq:latest
- mesh-control:development
# The tool runtime with the audit-logger, built by scripts/build-runtime-image.sh into the local
# daemon and stocked into the scenario's own registry, which is where the host pulls it from.
- mesh-runtime-audit:development
place:
all: [host, runtime]