runtime: a run subcommand to run a module entrypoint to completion (ADR 0052) #6

Merged
jschoubben merged 7 commits from feat/run-once-entry into main 2026-09-13 09:16:12 +00:00
3 changed files with 65 additions and 12 deletions
+52 -10
View File
@@ -1,15 +1,57 @@
# The tool runtime, as the container a node runs. It is handed the broker URL and the assigned # The tool runtime: the base every module written in this toolchain is compiled on top of, and the
# modules' tool entrypoints at deploy time (MESH_BROKER_URL, MESH_TOOL_MODULES) and serves them. # container a node runs to serve them. It is handed the broker credential and the assigned modules'
FROM node:22-alpine AS build # entrypoints at deploy time and serves them.
#
# **Built from this repository alone.** It used to copy in a compiled output directory that is not
# in source control, and resolve the mesh's own toolkit to a sibling checkout on the same disk — so
# it could only be produced on a workstation with two repositories laid out side by side, and its
# fingerprint was then typed into every module's recipe by hand. That put the one artifact the whole
# toolchain stands on outside the toolchain: nothing could rebuild it, so nothing could check it,
# and the rule that catches a base moving had no version on the far end of its edge and could never
# fire (novox/hq issue 044).
#
# Debian rather than Alpine, and root rather than an unprivileged user, because that is what the
# image actually in service is — and modules have already been built against it, one of which
# installs a package with Debian's package manager. This recipe said Alpine while serving Debian for
# as long as nobody could rebuild it to notice. Changing the operating system under every module is
# a separate decision from making this buildable, and is not being taken here.
FROM node:22-bookworm-slim AS build
# git, because a dependency named by a git URL is fetched by git and this image does not carry it.
# Only in the build stage: what it is needed for happens here, and a runtime that can clone is a
# runtime that can be made to clone.
RUN apt-get update \
&& apt-get install -y --no-install-recommends git ca-certificates \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY package.json package-lock.json ./
# Development dependencies included: the compiler is one of them, and so is the toolkit's own — it
# builds itself on install, which is what lets it be named by a git URL rather than fetched from a
# package registry this mesh does not yet run.
RUN npm install --no-audit --no-fund
# **And then compile the toolkit, because npm did not.** It declares a `prepare` script, which is
# the hook npm is supposed to run after installing a package from git — and this npm does not run
# it, so the package arrives as sources with every one of its entry points pointing at a compiled
# directory that is not there. The compile is therefore done here, explicitly: install the toolkit's
# own build dependencies inside it, build it, then drop them again so they do not travel into the
# image. Doing it by hand rather than relying on the hook is also the honest arrangement — a build
# that silently depended on a hook firing would break the day it stopped, in the same invisible way.
RUN npm --prefix node_modules/@novox/mesh-sdk install --no-audit --no-fund \
&& npm --prefix node_modules/@novox/mesh-sdk run build \
&& npm --prefix node_modules/@novox/mesh-sdk prune --omit=dev
COPY tsconfig.json ./
COPY src ./src
RUN npm run build
# Everything the modules compile against and run on.
#
# **The build dependencies stay, and that is deliberate.** This image is not only what a module runs
# in — it is also what every module is *compiled* in: a module's recipe starts from this and invokes
# the compiler out of these same directories. Dropping them would halve the image and break every
# module that builds on it, which is the sort of tidy-looking change that only fails somewhere else.
# If the two roles are ever separated, they should be separated deliberately and named separately.
FROM node:22-bookworm-slim
WORKDIR /app WORKDIR /app
COPY package.json ./ COPY package.json ./
RUN npm install --omit=dev --no-audit --no-fund
COPY dist ./dist
FROM node:22-alpine
WORKDIR /app
COPY --from=build /app/node_modules ./node_modules COPY --from=build /app/node_modules ./node_modules
COPY --from=build /app/dist ./dist COPY --from=build /app/dist ./dist
COPY package.json ./
USER node
ENTRYPOINT ["node", "dist/main.js"] ENTRYPOINT ["node", "dist/main.js"]
+11
View File
@@ -0,0 +1,11 @@
{
"module": "mesh-tools",
"version": "1",
"slug": "tools",
"build": {
"artifacts": [
{ "name": "runtime", "kind": "image", "from": "Dockerfile" }
]
},
"resources": []
}
+2 -2
View File
@@ -1,7 +1,7 @@
{ {
"name": "@novox/mesh-tools", "name": "@novox/mesh-tools",
"version": "0.1.0", "version": "0.1.0",
"description": "The Novox Mesh tool runtime — binds the mesh broker and serves the assigned modules' tools.", "description": "The Novox Mesh tool runtime \u2014 binds the mesh broker and serves the assigned modules' tools.",
"type": "module", "type": "module",
"bin": { "bin": {
"mesh-tools": "./dist/main.js" "mesh-tools": "./dist/main.js"
@@ -11,7 +11,7 @@
"test": "node --test --experimental-strip-types 'test/*.test.ts'" "test": "node --test --experimental-strip-types 'test/*.test.ts'"
}, },
"dependencies": { "dependencies": {
"@novox/mesh-sdk": "^0.1.0", "@novox/mesh-sdk": "git+https://git.novox.be/novox/mesh-sdk.git#a1ed33b",
"amqplib": "^0.10.9" "amqplib": "^0.10.9"
}, },
"devDependencies": { "devDependencies": {