From 088022d63b8f0b09b9492a73515c461d7b411a89 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 15:24:07 +0200 Subject: [PATCH] postgres: the provisioner connects to mesh-store's actual port, not a hardcoded 5432 MESH_PROVISION_POSTGRES was a literal connection string naming port 5432 -- correct only when mesh-store happens to run on the mesh's own default. On novox, mesh-store was adopted in place at HAL's original port (6852), and the provisioner has been retrying-and-failing against 127.0.0.1:5432 ever since, for every consumer including ones that already exist (gitea, umami, mesh-catalog), not just a new grant. Fixed with the same ${seat:mesh-store:5432} template mesh-controller's own manifest already uses for the identical connection. No other module needed this fix checked -- lavinmq's MESH_PROVISION_LAVINMQ already used 127.0.0.1:15672 unconditionally, but the broker's management port is fixed by the module itself (127.0.0.1:15672 in lavinmq/module.json's own ports), not by adoption, so it isn't the same bug. --- modules/postgres/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 56dc81b..fcc2c2c 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -97,7 +97,7 @@ "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro" ], "env": { - "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:5432/postgres?sslmode=disable", + "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${seat:mesh-store:5432}/postgres?sslmode=disable", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"