Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9cb53cd022 | ||
|
|
3a59099c81 |
@@ -0,0 +1,71 @@
|
||||
---
|
||||
status: open
|
||||
opened: 2026-09-29
|
||||
located-in:
|
||||
- mesh-controller internal/catalogue/dir_into.go (dirsFor: a stated path or <data root>/<module>/<id>, nothing else)
|
||||
- mesh-controller (accesses: the path is the manifest's literal)
|
||||
fixed-by:
|
||||
amended-design:
|
||||
---
|
||||
|
||||
# 149 — An adopted machine's data cannot be placed where it is
|
||||
|
||||
## What was observed
|
||||
|
||||
Preparing ace's media modules (plex, sonarr, radarr, lidarr, bazarr, nzbget, qbittorrent, bookshelf)
|
||||
for migration. ace is adopted; its data is where the predecessor put it and **must stay there**:
|
||||
|
||||
- the library and download spool: `/storage/media/*`, `/storage/downloads` — a separate ZFS pool,
|
||||
~40 TB, the operator's shared data (ADR 0051);
|
||||
- plex's own state: `/mnt/plex/{config,data,temp}` — 133 GB on a second disk;
|
||||
- large configuration directories held in place: lidarr 46 GB, radarr 17 GB, sonarr 3.2 GB.
|
||||
|
||||
The catalogue's manifests name `/services/media/*` (as `accesses`) and `/services/<m>/config` (as
|
||||
owned directories), which is novox's layout, not ace's, and not a value a definition may carry.
|
||||
|
||||
## What was decided, and what exists
|
||||
|
||||
[ADR 0112](../../02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md) (accepted) says
|
||||
exactly what is needed:
|
||||
|
||||
> *Where* it is on the machine is the assignment's. A node has a default layout, and an assignment may
|
||||
> place a directory elsewhere: on a second disk, or where an adopted machine's data already is.
|
||||
|
||||
> [ADR 0051]: an access keeps its shape and its semantics; its path moves from the definition to the
|
||||
> assignment.
|
||||
|
||||
What the control plane implements (`dirsFor`): a directory is either a path the manifest states, or
|
||||
`<data root>/<module>/<id>` under the node's one data root. There is **no per-assignment placement of
|
||||
one directory**, and an `access` path is the manifest's literal — no setting reaches either.
|
||||
|
||||
## Consequence
|
||||
|
||||
Every module whose data an adopted machine already holds somewhere other than the default layout can
|
||||
only be migrated by (a) writing the machine's path into the manifest — which 0112 forbids and which
|
||||
is wrong on the next machine — or (b) moving the data into the placed layout in a window. (b) is
|
||||
acceptable for a 40 MB configuration and impossible for a 40 TB library the operator has ruled must
|
||||
never be moved, copied or re-owned.
|
||||
|
||||
The same gap covers ownership: the predecessor runs ace's media stack as `1001:2000`; a manifest's
|
||||
`owner` is one value for every machine.
|
||||
|
||||
## What would be right
|
||||
|
||||
The two assignment halves 0112 decided: a setting that places a declared directory (by id) at a given
|
||||
path on this node, and a setting that says where an access's data is — both validated like
|
||||
`endpoints` (unknown ids refused), and an access placed by the assignment still never created,
|
||||
chowned or removed.
|
||||
|
||||
## Addendum 2026-09-30 — whose the data is, not only where
|
||||
|
||||
The same modules need to run **as the owner of the data they access**: linuxserver images take
|
||||
`PUID`/`PGID`, and ace's library is `media:media` (`1001:2000`, group members `ace`, `n8n`, `media`).
|
||||
A manifest default is one value for every machine, and an assignment's settings do not reach a
|
||||
container's environment. Adding user and group management to the mesh would contradict ADR 0051 —
|
||||
the mesh owns nothing about the operator's data.
|
||||
|
||||
The data already says whose it is, and the host already looks at it when it confirms an access exists.
|
||||
Proposed: expose that as a fact the module can ask for, like `${port:…}` — e.g. `${access:<id>:uid}`
|
||||
and `${access:<id>:gid}`, read from the accessed path on the machine — so a media module declares
|
||||
`PUID=${access:media:uid}` and is right on every machine without the mesh creating, naming or
|
||||
chowning anyone.
|
||||
Reference in New Issue
Block a user