step-ca: mount the directory, not each secret file

A file bind mount tracks the inode. The host writes atomically — new file, rename
over — so the container keeps reading the file that was there when it started,
and a rotated or newly-delivered secret never reaches it. Mounting the parent
directory resolves the path on each open instead.

This is a known shape (hal KB troubleshooting/docker-bind-mounts), and it cost an
hour here before it was looked up: the CA crash-looped on a root key it had
already been given, because the container still held the inode from before the
key arrived.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-11 08:49:55 +02:00
parent 0d2c2dd989
commit 290be37a93
+4 -7
View File
@@ -96,16 +96,13 @@
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
"DOCKER_STEPCA_INIT_ACME": "true",
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt",
"DOCKER_STEPCA_INIT_KEY_FILE": "/run/secrets/root_ca_key",
"DOCKER_STEPCA_INIT_KEY_PASSWORD_FILE": "/run/secrets/root_ca_key_password"
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/mesh/root-cert.pem",
"DOCKER_STEPCA_INIT_KEY_FILE": "/run/mesh/root-key.pem",
"DOCKER_STEPCA_INIT_KEY_PASSWORD_FILE": "/run/mesh/root-key-password.txt"
},
"volumes": [
"/var/lib/step-ca:/home/step",
"/var/lib/mesh/step-ca/root-cert.pem:/run/secrets/root_ca.crt:ro",
"/var/lib/mesh/step-ca/root-key.pem:/run/secrets/root_ca_key:ro",
"/var/lib/mesh/step-ca/root-key-password.txt:/run/secrets/root_ca_key_password:ro",
"/var/lib/mesh/step-ca/config.json:/run/config/config.json:ro"
"/var/lib/mesh/step-ca:/run/mesh:ro"
]
}
]