influxdb: its admin password and operator token are its own secrets, so an existing instance's can be accepted
They came from `requires: secret`, minted by the vault — right for a fresh setup (the image's INIT_* variables read them once), wrong for an instance that already exists: setup is skipped, the minted values match nothing, and the provisioner holds a token the server never issued (issue 100). InfluxDB will not take a chosen token value, so the operator token must be accepted from the instance (`secret accept ace influxdb admin-token`); the password can be either. As own secrets both are minted for a fresh install exactly as before, and accepted where the data already knows them. Found migrating ace's influxdb.
This commit is contained in:
@@ -11,7 +11,9 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/influxdb/broker"
|
"broker": "/var/lib/mesh/influxdb/broker",
|
||||||
|
"admin": "${dir:state}/admin.secret",
|
||||||
|
"admin-token": "${dir:state}/admin-token.secret"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -124,8 +126,7 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
"route",
|
"route"
|
||||||
"secret"
|
|
||||||
],
|
],
|
||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
@@ -133,12 +134,6 @@
|
|||||||
"endpoint": "api"
|
"endpoint": "api"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"secrets": {
|
|
||||||
"secret": {
|
|
||||||
"admin": "${dir:state}/admin.secret",
|
|
||||||
"admin-token": "${dir:state}/admin-token.secret"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
"on": [
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user