influxdb: its admin password and operator token are its own secrets, so an existing instance's can be accepted

They came from `requires: secret`, minted by the vault — right for a fresh
setup (the image's INIT_* variables read them once), wrong for an instance
that already exists: setup is skipped, the minted values match nothing,
and the provisioner holds a token the server never issued (issue 100).
InfluxDB will not take a chosen token value, so the operator token must be
accepted from the instance (`secret accept ace influxdb admin-token`); the
password can be either. As own secrets both are minted for a fresh install
exactly as before, and accepted where the data already knows them.
Found migrating ace's influxdb.
This commit is contained in:
2026-09-30 16:18:59 +02:00
parent 3ae63f10c5
commit 50ae89e718
+4 -9
View File
@@ -11,7 +11,9 @@
"container-runtime" "container-runtime"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/influxdb/broker" "broker": "/var/lib/mesh/influxdb/broker",
"admin": "${dir:state}/admin.secret",
"admin-token": "${dir:state}/admin-token.secret"
}, },
"listens": [ "listens": [
{ {
@@ -124,8 +126,7 @@
} }
], ],
"requires": [ "requires": [
"route", "route"
"secret"
], ],
"contributes": { "contributes": {
"route": { "route": {
@@ -133,12 +134,6 @@
"endpoint": "api" "endpoint": "api"
} }
}, },
"secrets": {
"secret": {
"admin": "${dir:state}/admin.secret",
"admin-token": "${dir:state}/admin-token.secret"
}
},
"build": { "build": {
"on": [ "on": [
{ {