lavinmq: the broker TLS directory is the operator's, read by whoever needs it
The controller now accesses /var/lib/mesh-broker-tls (mesh-controller #54) and the push refused whole: lavinmq declared the directory as an owned resource, and shared data is the operator's, owned by no module (ADR 0051). lavinmq only ever reads the certs — genesis laid them down — so it declares a read access like the controller does, and the directory belongs to nobody.
This commit is contained in:
@@ -81,12 +81,6 @@
|
|||||||
"path": "/var/lib/mesh-broker",
|
"path": "/var/lib/mesh-broker",
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "broker-tls",
|
|
||||||
"type": "directory",
|
|
||||||
"path": "/var/lib/mesh-broker-tls",
|
|
||||||
"mode": "0700"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
@@ -147,5 +141,11 @@
|
|||||||
"from": "Dockerfile"
|
"from": "Dockerfile"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
},
|
||||||
|
"accesses": [
|
||||||
|
{
|
||||||
|
"path": "/var/lib/mesh-broker-tls",
|
||||||
|
"mode": "read"
|
||||||
|
}
|
||||||
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user