influxdb: its admin password and operator token are its own secrets, so an existing instance's can be accepted
They came from `requires: secret`, minted by the vault — right for a fresh setup (the image's INIT_* variables read them once), wrong for an instance that already exists: setup is skipped, the minted values match nothing, and the provisioner holds a token the server never issued (issue 100). InfluxDB will not take a chosen token value, so the operator token must be accepted from the instance (`secret accept ace influxdb admin-token`); the password can be either. As own secrets both are minted for a fresh install exactly as before, and accepted where the data already knows them. Found migrating ace's influxdb.
This commit is contained in:
@@ -11,7 +11,9 @@
|
||||
"container-runtime"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/influxdb/broker"
|
||||
"broker": "/var/lib/mesh/influxdb/broker",
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"admin-token": "${dir:state}/admin-token.secret"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -124,8 +126,7 @@
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route",
|
||||
"secret"
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
@@ -133,12 +134,6 @@
|
||||
"endpoint": "api"
|
||||
}
|
||||
},
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"admin-token": "${dir:state}/admin-token.secret"
|
||||
}
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user