Reconcile: adopt initialization's consolidated HQ as canonical, re-home this session's new work #24
@@ -161,6 +161,19 @@ service between systems.
|
|||||||
**So there is a step before any of this: read the current environment out of the old system**, because
|
**So there is a step before any of this: read the current environment out of the old system**, because
|
||||||
adoption means supplying those values and they live in its files today.
|
adoption means supplying those values and they live in its files today.
|
||||||
|
|
||||||
|
**And there is a failure worse than losing data, which is likelier.** A database image consumes its
|
||||||
|
password environment variable **only when its data directory is empty**. Everything here keeps its
|
||||||
|
data on a persistent directory, so the role holds whatever password it was created with, for ever.
|
||||||
|
Regenerate that variable and the application moves on while the database does not — permanently,
|
||||||
|
because nothing reconciles it. Eight modules are in that state today, working only because nobody
|
||||||
|
has regenerated their credential since their data directory was created.
|
||||||
|
|
||||||
|
*Where the detail lives:* this is operational and names machines, so it is in the mesh's own
|
||||||
|
knowledge base rather than here — `migration/where-service-data-lives`, which surveys where every
|
||||||
|
service's data actually sits and what each stop or removal would cost, and
|
||||||
|
`troubleshooting/db-password-frozen-at-first-init` for the lockout itself. **This document says the
|
||||||
|
rule; those say the specifics.**
|
||||||
|
|
||||||
*Corrected 2026-08-31 — an earlier version of this paragraph made that sound more dangerous than it
|
*Corrected 2026-08-31 — an earlier version of this paragraph made that sound more dangerous than it
|
||||||
is.* A sealed secret is not unreadable; it is sealed **to the node**, which holds the private half
|
is.* A sealed secret is not unreadable; it is sealed **to the node**, which holds the private half
|
||||||
and writes the plaintext into the module's own file. The value is there, on the machine, as an
|
and writes the plaintext into the module's own file. The value is there, on the machine, as an
|
||||||
|
|||||||
Reference in New Issue
Block a user