From 1247b8c27e0226914ee528448150075cdcec7b77 Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 11:57:46 +0200 Subject: [PATCH] redis: place its directories and run the build in use The manifest stated /services/redis/data and /var/lib/redis-module - novox's old layout, paths no definition may carry (ADR 0112). State is now the assignment's root, grants and data are placed, and the config file, the secret file, receives and grants all name them as ${dir:...}. Paths inside the sidecar are its own view and are unchanged. The data directory and config are owned 999:1000: the image's redis user is uid 999 in gid 1000 (checked in both builds), which is who owns ace's data today; 999:999 named a group the image does not use. Image pinned to the 7.4.11-alpine build ace runs (2026-09-17); the old pin was the same version, built in August. Older-than-running is never the pin. Nothing is assigned it anywhere today, so no machine changes. Verified: catalogue tests pass with MESH_CATALOGUE on this tree; the declaration composes for ace with every path under /var/lib/redis. The pinned image ran as a throwaway with a 0600 999:1000 config and a 0700 data dir: unauthenticated PING is refused (NOAUTH), authenticated SET/GET works, appendonly is on, the server runs as redis. --- modules/redis/module.json | 30 ++++++++++++++---------------- 1 file changed, 14 insertions(+), 16 deletions(-) diff --git a/modules/redis/module.json b/modules/redis/module.json index f976dd6..324ca9a 100644 --- a/modules/redis/module.json +++ b/modules/redis/module.json @@ -27,13 +27,13 @@ } }, "receives": { - "redis-cache": "/var/lib/redis-module/grants/mesh.json" + "redis-cache": "${dir:grants}/mesh.json" }, "grants": { - "redis-cache": "/var/lib/redis-module/grants" + "redis-cache": "${dir:grants}" }, "secrets": { - "secret": "/var/lib/redis-module/default.secret" + "secret": "${dir:state}/default.secret" }, "own-secrets": { "broker": "/var/lib/mesh/redis/broker" @@ -57,29 +57,27 @@ { "id": "state", "type": "directory", - "path": "/var/lib/redis-module", - "mode": "0700" + "mode": "0700", + "place": "." }, { - "id": "grants-dir", + "id": "grants", "type": "directory", - "path": "/var/lib/redis-module/grants", "mode": "0700" }, { "id": "data", "type": "directory", - "path": "/services/redis/data", "mode": "0700", - "owner": "999:999" + "owner": "999:1000" }, { "id": "server-conf", "type": "file", - "path": "/var/lib/redis-module/redis.conf", + "path": "${dir:state}/redis.conf", "mode": "0600", "content": "requirepass ${secret:secret}\nappendonly yes\ndir /data\n", - "owner": "999:999" + "owner": "999:1000" }, { "id": "net", @@ -90,14 +88,14 @@ "id": "server", "type": "container", "name": "redis", - "image": "redis@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf", + "image": "redis@sha256:520775a41a63e77e06c73e35d2fd9cc15921a609516818796b4ecbb813078bc7", "network": "redis", "ports": [ "6379" ], "volumes": [ - "/services/redis/data:/data", - "/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro" + "${dir:data}:/data", + "${dir:state}/redis.conf:/etc/redis/redis.conf:ro" ], "args": [ "/etc/redis/redis.conf" @@ -113,8 +111,8 @@ "network": "redis", "volumes": [ "/var/lib/mesh/redis/broker:/run/secrets/broker:ro", - "/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro", - "/var/lib/redis-module/default.secret:/run/secrets/default:ro" + "${dir:grants}:/var/lib/redis-module/grants:ro", + "${dir:state}/default.secret:/run/secrets/default:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker",