step-ca: mount the directory, not each secret file
A file bind mount tracks the inode. The host writes atomically — new file, rename over — so the container keeps reading the file that was there when it started, and a rotated or newly-delivered secret never reaches it. Mounting the parent directory resolves the path on each open instead. This is a known shape (hal KB troubleshooting/docker-bind-mounts), and it cost an hour here before it was looked up: the CA crash-looped on a root key it had already been given, because the container still held the inode from before the key arrived. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -96,16 +96,13 @@
|
|||||||
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
|
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
|
||||||
"DOCKER_STEPCA_INIT_ACME": "true",
|
"DOCKER_STEPCA_INIT_ACME": "true",
|
||||||
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
|
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
|
||||||
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt",
|
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/mesh/root-cert.pem",
|
||||||
"DOCKER_STEPCA_INIT_KEY_FILE": "/run/secrets/root_ca_key",
|
"DOCKER_STEPCA_INIT_KEY_FILE": "/run/mesh/root-key.pem",
|
||||||
"DOCKER_STEPCA_INIT_KEY_PASSWORD_FILE": "/run/secrets/root_ca_key_password"
|
"DOCKER_STEPCA_INIT_KEY_PASSWORD_FILE": "/run/mesh/root-key-password.txt"
|
||||||
},
|
},
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/step-ca:/home/step",
|
"/var/lib/step-ca:/home/step",
|
||||||
"/var/lib/mesh/step-ca/root-cert.pem:/run/secrets/root_ca.crt:ro",
|
"/var/lib/mesh/step-ca:/run/mesh:ro"
|
||||||
"/var/lib/mesh/step-ca/root-key.pem:/run/secrets/root_ca_key:ro",
|
|
||||||
"/var/lib/mesh/step-ca/root-key-password.txt:/run/secrets/root_ca_key_password:ro",
|
|
||||||
"/var/lib/mesh/step-ca/config.json:/run/config/config.json:ro"
|
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
Reference in New Issue
Block a user