From 1289510538e8c20664a3b5676f89fe05dd150eaf Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 13:43:41 +0200 Subject: [PATCH] mongodb names its secrets' owner: the image drops to its own user before it reads the password file The official entrypoint re-executes itself as mongodb (uid 999) and only then reads MONGO_INITDB_ROOT_PASSWORD_FILE, so a root-owned 0600 file is 'Permission denied' at line 83 and the server never starts. secrets-owner is the mechanism ADR 0086 gives for exactly this. --- modules/mongodb/module.json | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/mongodb/module.json b/modules/mongodb/module.json index a8eb25b..73b7263 100644 --- a/modules/mongodb/module.json +++ b/modules/mongodb/module.json @@ -41,6 +41,7 @@ "root": "/var/lib/mongodb/root.secret", "broker": "/var/lib/mesh/mongodb/broker" }, + "secrets-owner": "999:999", "resources": [ { "id": "mesh-state",