ADR 0107: persistent data is a directory bind, never a named volume
Records the rule the operator gave directly, mid-session, after checking that HAL's own postgres and lavinmq both used a directory bind and the mesh's adoption of them three weeks ago switched to a named volume without a reason recorded anywhere. Already built and rolled out on novox (mesh-catalog PR #54) before this record -- urgent enough to fix first and write down after. Includes the incident: the new host directories needed the container's own UID, which a named volume gets for free and a directory bind does not; mesh-store crash-looped on Permission denied until ownership was matched to what the original volume already had. Closes issue 115. Checks pass.
This commit is contained in:
@@ -172,6 +172,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0086** — [A secret reaches a process as a file, and an exception is declared](0086-a-secret-reaches-a-process-as-a-file.md)
|
||||
- **0096** — [An upstream image is copied between registries, never through a machine's image store](0096-an-upstream-image-is-copied-between-registries.md)
|
||||
- **0097** — [A vendor image is a declared build input, and a recipe fetches nothing undeclared](0097-a-vendor-image-is-a-declared-build-input.md)
|
||||
- **0107** — [Persistent data is a directory bind, never a named volume](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md)
|
||||
|
||||
### How it is checked
|
||||
|
||||
|
||||
Reference in New Issue
Block a user