A path inside a container is not a fact about the machine./run/secrets/…, or the directory a server keeps its data in, is the software's own contract — true in any mesh that runs that image. Only the host side of a mount names where it landed on one particular machine.
The first sweep matched path-shaped strings, so it counted both halves of every mount and every in-container location any value mentioned: 798. Counted by role instead — directory and file resources, the host side of mounts, accesses, and the targets of binds, grants, receives and own-secrets — it is 698 across 70 definitions, with a clean 236 container-side mount paths excluded as the software's own.
Issue 119's figure was already role-counted and host-side, which is why it is close: it additionally counts paths written into environment values, a few of which are container-side.
The distinction matters beyond arithmetic, because it is the test the whole issue turns on: a value belongs in a definition when it would still be right in a different mesh. An in-container path passes that test. A host path does not.
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.
Corrects the census row I added an hour ago.
**A path inside a container is not a fact about the machine.** `/run/secrets/…`, or the directory a server keeps its data in, is the software's own contract — true in any mesh that runs that image. Only the **host** side of a mount names where it landed on one particular machine.
The first sweep matched path-shaped strings, so it counted both halves of every mount and every in-container location any value mentioned: 798. Counted by role instead — directory and file resources, the host side of mounts, `accesses`, and the targets of `binds`, `grants`, `receives` and `own-secrets` — it is **698 across 70 definitions**, with a clean 236 container-side mount paths excluded as the software's own.
Issue 119's figure was already role-counted and host-side, which is why it is close: it additionally counts paths written into environment values, a few of which are container-side.
The distinction matters beyond arithmetic, because it is the test the whole issue turns on: a value belongs in a definition when it would still be right in a different mesh. An in-container path passes that test. A host path does not.
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.
A path inside a container is not a fact about the machine — /run/secrets and the directory a server
keeps its data in are the software's own contract, true in any mesh that runs it. Only the host side
of a mount names where it landed.
The first sweep matched path-shaped strings, so it counted both halves of every mount and every
in-container location a value mentioned: 798. Counted by role — directory and file resources, the
host side of mounts, accesses, and the targets of binds, grants, receives and secrets — it is 698
across 70 definitions.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Corrects the census row I added an hour ago.
A path inside a container is not a fact about the machine.
/run/secrets/…, or the directory a server keeps its data in, is the software's own contract — true in any mesh that runs that image. Only the host side of a mount names where it landed on one particular machine.The first sweep matched path-shaped strings, so it counted both halves of every mount and every in-container location any value mentioned: 798. Counted by role instead — directory and file resources, the host side of mounts,
accesses, and the targets ofbinds,grants,receivesandown-secrets— it is 698 across 70 definitions, with a clean 236 container-side mount paths excluded as the software's own.Issue 119's figure was already role-counted and host-side, which is why it is close: it additionally counts paths written into environment values, a few of which are container-side.
The distinction matters beyond arithmetic, because it is the test the whole issue turns on: a value belongs in a definition when it would still be right in a different mesh. An in-container path passes that test. A host path does not.
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.