From 4329ca939209d7fb294c53cb8797235b8dc6562e Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 13:41:17 +0200 Subject: [PATCH] nextcloud: deliver the admin password to the sidecar too The sidecar's own client needs MESH_NEXTCLOUD_ADMIN_PASSWORD to list shares over the OCS API, but the runtime container's env/volumes never carried it -- only the server container did. Delivered the same way every other sealed value in this manifest already is: a generated env-file with the ${secret:admin} substitution, not a raw value in the container's env. --- modules/nextcloud/module.json | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index b667c20..9eb683e 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -98,6 +98,13 @@ "content": "{}\n", "merge": "json" }, + { + "id": "runtime-admin-env", + "type": "file", + "path": "/var/lib/mesh/nextcloud/admin.env", + "mode": "0600", + "content": "MESH_NEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\n" + }, { "id": "runtime", "type": "container", @@ -108,6 +115,9 @@ "/var/lib/mesh/nextcloud/config.json:/run/config/config.json:ro", "/var/run/docker.sock:/var/run/docker.sock" ], + "env-file": [ + "/var/lib/mesh/nextcloud/admin.env" + ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_NEXTCLOUD_URL": "http://127.0.0.1:80",