- tc-telemetry: fmt subscriber always; with [telemetry] otlp_endpoint set, spans batch-export over OTLP/HTTP. Tested against a REAL OTLP receiver decoding the actual protobuf (official proto types): the emitted span and service.name arrive on the wire. No endpoint = no export = no network (air-gap stance). tower-http TraceLayer gives every API request a span - The broker finally has its own image (images/broker.Dockerfile, 9.5MB from scratch) — the Helm chart referenced one that never existed — and the compose deployment now RUNS the broker, sharing a socket volume with the server (the unix-socket equivalent of the K8s sidecar). Compose secret flows were silently dead before this - server.Dockerfile fixes surfaced by the rehearsal: the workspace build needs tools/ (bundler joined the workspace) and images/seccomp/ (include_str! profile) in the build context - scripts/rehearse-install.sh (plan: clean-VM rehearsal): assembles a REAL signed bundle from the built images (server/frontend/broker/ postgres/socket-proxy), runs the customer path — offline verify, docker load, compose up — and asserts /healthz plus the served login page before teardown. Passing locally; wired as a release.yml step, which also builds/ships the broker + socket-proxy images now 161 Rust tests + 29 journeys; clean-room rehearsal green. Co-Authored-By: Claude Fable 5 <[email protected]>
27 lines
997 B
Docker
27 lines
997 B
Docker
# The secret broker: its own minimal image, its own process boundary.
|
|
# Shares the builder pattern with the server image; ships ONLY the broker
|
|
# binary.
|
|
FROM rust:1-bookworm AS builder
|
|
RUN case "$(uname -m)" in \
|
|
aarch64) echo aarch64-unknown-linux-musl > /rust-target ;; \
|
|
*) echo x86_64-unknown-linux-musl > /rust-target ;; \
|
|
esac \
|
|
&& rustup target add "$(cat /rust-target)" \
|
|
&& apt-get update && apt-get install -y --no-install-recommends musl-tools \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
WORKDIR /src
|
|
COPY Cargo.toml rust-toolchain.toml ./
|
|
COPY crates ./crates
|
|
COPY tools ./tools
|
|
COPY images/seccomp ./images/seccomp
|
|
COPY migrations ./migrations
|
|
COPY .sqlx ./.sqlx
|
|
ENV SQLX_OFFLINE=true
|
|
RUN cargo build --release --target "$(cat /rust-target)" -p teamclaw-broker \
|
|
&& cp "target/$(cat /rust-target)/release/teamclaw-broker" /teamclaw-broker
|
|
|
|
FROM scratch
|
|
COPY --from=builder /teamclaw-broker /teamclaw-broker
|
|
USER 10001:10001
|
|
ENTRYPOINT ["/teamclaw-broker"]
|