mongodb names its secrets' owner: the image drops to its own user before it reads the password file

The official entrypoint re-executes itself as mongodb (uid 999) and only then reads
MONGO_INITDB_ROOT_PASSWORD_FILE, so a root-owned 0600 file is 'Permission denied' at line 83 and
the server never starts. secrets-owner is the mechanism ADR 0086 gives for exactly this.
This commit is contained in:
2026-09-21 13:43:41 +02:00
parent 50b639ff52
commit 1289510538
+1
View File
@@ -41,6 +41,7 @@
"root": "/var/lib/mongodb/root.secret", "root": "/var/lib/mongodb/root.secret",
"broker": "/var/lib/mesh/mongodb/broker" "broker": "/var/lib/mesh/mongodb/broker"
}, },
"secrets-owner": "999:999",
"resources": [ "resources": [
{ {
"id": "mesh-state", "id": "mesh-state",