diff --git a/modules/postgres/client.ts b/modules/postgres/client.ts index 7582494..fa60b1b 100644 --- a/modules/postgres/client.ts +++ b/modules/postgres/client.ts @@ -39,7 +39,16 @@ export class PostgresClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): PostgresClient { const url = env.MESH_PROVISION_POSTGRES ? safeUrl(env.MESH_PROVISION_POSTGRES) : undefined; const host = env.MESH_POSTGRES_HOST ?? url?.hostname; - const port = Number(env.MESH_POSTGRES_PORT ?? url?.port ?? "5432") || 5432; + // MESH_PROVISION_POSTGRES_PORT is the seat's twin (mesh-controller's own + // internal/envfile.Placed pattern): which port this machine actually put mesh-store at, when + // that differs from what the connection string above already says — e.g. adopted in place at + // a predecessor's port. Empty means the mesh has nothing to add and the string's own port + // stands; a placeholder the mesh never filled (a manifest ahead of the running controller) + // is treated the same way, not as a fault. + const seatPort = (env.MESH_PROVISION_POSTGRES_PORT ?? "").trim(); + const filledSeatPort = seatPort && !/^\$\{[^}]*\}$/.test(seatPort) ? seatPort : undefined; + const portSource = env.MESH_POSTGRES_PORT ?? filledSeatPort ?? url?.port ?? "5432"; + const port = Number(portSource) || 5432; const user = env.MESH_POSTGRES_USER ?? url?.username ?? "postgres"; const password = env.MESH_POSTGRES_PASSWORD ?? readSecretFile(env.MESH_PROVISION_PASSWORD_FILE); if (!host || !password) { diff --git a/modules/postgres/module.json b/modules/postgres/module.json index fcc2c2c..2b65929 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -97,7 +97,8 @@ "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro" ], "env": { - "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${seat:mesh-store:5432}/postgres?sslmode=disable", + "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:5432/postgres?sslmode=disable", + "MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"