mosquitto, influxdb: the provisioner sees its grants where the mesh writes them
The received grants file names each pair secret by its HOST path. A sidecar that mounts the placed grants directory at another path inside its container sees mesh.json and not the secrets beside it — mosquitto's provisioner reported ENOENT for a file that was there, and nodered's mqtt step failed against a login that was never created. Mounted at its own path now, as postgres does.
This commit is contained in:
@@ -131,12 +131,12 @@
|
||||
"network": "mosquitto",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro",
|
||||
"${dir:grants}:/var/lib/mosquitto-module/grants:ro",
|
||||
"${dir:grants}:${dir:grants}:ro",
|
||||
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "/var/lib/mosquitto-module/grants/mesh.json",
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||
"MESH_PROVISION_MQTT": "mosquitto:1883",
|
||||
"MESH_PROVISION_ADMIN_USER": "mesh-admin",
|
||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/admin"
|
||||
|
||||
Reference in New Issue
Block a user