Reconcile: adopt initialization's consolidated HQ as canonical, re-home this session's new work #24

Merged
jschoubben merged 177 commits from reconcile-init-into-main into main 2026-09-05 10:27:11 +00:00
Showing only changes of commit ecfc2c215e - Show all commits
+13
View File
@@ -161,6 +161,19 @@ service between systems.
**So there is a step before any of this: read the current environment out of the old system**, because **So there is a step before any of this: read the current environment out of the old system**, because
adoption means supplying those values and they live in its files today. adoption means supplying those values and they live in its files today.
**And there is a failure worse than losing data, which is likelier.** A database image consumes its
password environment variable **only when its data directory is empty**. Everything here keeps its
data on a persistent directory, so the role holds whatever password it was created with, for ever.
Regenerate that variable and the application moves on while the database does not — permanently,
because nothing reconciles it. Eight modules are in that state today, working only because nobody
has regenerated their credential since their data directory was created.
*Where the detail lives:* this is operational and names machines, so it is in the mesh's own
knowledge base rather than here — `migration/where-service-data-lives`, which surveys where every
service's data actually sits and what each stop or removal would cost, and
`troubleshooting/db-password-frozen-at-first-init` for the lockout itself. **This document says the
rule; those say the specifics.**
*Corrected 2026-08-31 — an earlier version of this paragraph made that sound more dangerous than it *Corrected 2026-08-31 — an earlier version of this paragraph made that sound more dangerous than it
is.* A sealed secret is not unreadable; it is sealed **to the node**, which holds the private half is.* A sealed secret is not unreadable; it is sealed **to the node**, which holds the private half
and writes the plaintext into the module's own file. The value is there, on the machine, as an and writes the plaintext into the module's own file. The value is there, on the machine, as an