From 0fce3ebf5dc524e977e6eaee19d7bd81fd993701 Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 11:57:45 +0200 Subject: [PATCH] mssql: place its directories and name the software's port, not a machine's The manifest stated /var/lib/mssql, its grants and its SA file by path, and declared it listens on 4848 - the port one machine's predecessor published, which is an assignment's fact (ADR 0112, 0138). ace is moving its own SQL Server (80 GB of work databases) onto the mesh, so the module has to be the same on every machine. - state is the assignment's root (place "."), grants is placed, and every reference (sa.env, the env-file, the SA and grants mounts, receives, grants, own-secrets) names them as ${dir:...}. - the database endpoint listens on 1433, the port SQL Server uses; a machine that must keep an older number pins it in its assignment. - the image pin is unchanged: it is the digest ace runs today (CU27, 16.0.4295), the same as novox. novox is untouched: rendered with novox's own setting ({"ports":{"1433":4848}}) through the controller's Declaration and Rules, every resource - paths, container names, volumes, env-file, the 4848:1433 mapping, owners, modes - is byte-identical to what main renders; the only difference is the firewall rule's comment text (still port 4848, from the mesh). Verified: catalogue tests pass with MESH_CATALOGUE on this tree. The pinned image ran as a throwaway on a 0700 10001:0 data dir with a root-owned 0600 env-file (dummy SA), answered sqlcmd as sa; a scratch database stopped, copied with cp -a, checksummed and started on the copy kept its rows and CHECKSUM_AGG. --- modules/mssql/module.json | 23 +++++++++++------------ 1 file changed, 11 insertions(+), 12 deletions(-) diff --git a/modules/mssql/module.json b/modules/mssql/module.json index 20fca53..b362154 100644 --- a/modules/mssql/module.json +++ b/modules/mssql/module.json @@ -21,23 +21,23 @@ "listens": [ { "name": "database", - "port": 4848, + "port": 1433, "protocol": "tcp", "from": "mesh", - "why": "modules on any machine that were granted a database. 4848, not 1433: the machine this replaces has served it there since it was installed, and every consumer was handed that number" + "why": "modules on any machine that were granted a database, and the people who were given its address; the machine port is the assignment's to pin" } ], "serves": { "mssql-database": {} }, "receives": { - "mssql-database": "/var/lib/mssql/grants/mesh.json" + "mssql-database": "${dir:grants}/mesh.json" }, "grants": { - "mssql-database": "/var/lib/mssql/grants" + "mssql-database": "${dir:grants}" }, "own-secrets": { - "sa": "/var/lib/mssql/sa.secret", + "sa": "${dir:state}/sa.secret", "broker": "/var/lib/mesh/mssql/broker" }, "resources": [ @@ -50,19 +50,18 @@ { "id": "state", "type": "directory", - "path": "/var/lib/mssql", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/mssql/grants", "mode": "0700" }, { "id": "sa-env", "type": "file", - "path": "/var/lib/mssql/sa.env", + "path": "${dir:state}/sa.env", "mode": "0600", "content": "ACCEPT_EULA=Y\nMSSQL_SA_PASSWORD=${secret:sa}\n" }, @@ -84,7 +83,7 @@ "image": "mcr.microsoft.com/mssql/server@sha256:4402d880dd4c34bfa7d8705e56a86cd6c88da80a1f6bbbe741f999e76264a090", "network": "mssql", "env-file": [ - "/var/lib/mssql/sa.env" + "${dir:state}/sa.env" ], "ports": [ "1433" @@ -101,8 +100,8 @@ "network": "mssql", "volumes": [ "/var/lib/mesh/mssql/broker:/run/secrets/broker:ro", - "/var/lib/mssql/grants:/var/lib/mssql/grants:ro", - "/var/lib/mssql/sa.secret:/run/secrets/sa:ro" + "${dir:grants}:/var/lib/mssql/grants:ro", + "${dir:state}/sa.secret:/run/secrets/sa:ro" ], "env": { "MESH_PROVISION_MSSQL": "mssql://sa@mssql:1433/master",