minio: install mc in the runtime image — the provisioner needs it to run
mesh-minio's s3-bucket provisioner shells out to mc to create buckets and service accounts on the live server, but mc was never in this module's own runtime image, only in minio's own. It's been silently retrying 'spawn mc ENOENT' forever, so every s3-bucket grant reached the control-plane layer (store.json, sealed secret) without the credential ever actually existing on minio — nextcloud's live instance just hit this as InvalidAccessKeyId on a real user session. Copies mc from minio's own image (docker.io/pgsty/minio, already pinned and pulled as this module's server container) rather than introducing a new base — mc there is a working, already-verified binary. /usr/bin/mc is a symlink to mcli; both are copied so it resolves.
This commit is contained in:
@@ -9,6 +9,11 @@
|
|||||||
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
|
||||||
ARG BUILD_BASE
|
ARG BUILD_BASE
|
||||||
ARG RUNTIME_BASE
|
ARG RUNTIME_BASE
|
||||||
|
ARG MC_CLI
|
||||||
|
|
||||||
|
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
|
||||||
|
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
|
||||||
|
FROM ${MC_CLI} AS mccli
|
||||||
|
|
||||||
FROM ${BUILD_BASE} AS build
|
FROM ${BUILD_BASE} AS build
|
||||||
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
|
||||||
@@ -22,6 +27,13 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts provision
|
|||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
FROM ${RUNTIME_BASE}
|
||||||
COPY --from=build /app/modules/minio/dist /app/modules/minio/dist
|
COPY --from=build /app/modules/minio/dist /app/modules/minio/dist
|
||||||
|
# The provisioner shells out to mc to actually create buckets and service accounts on the running
|
||||||
|
# minio server — mc itself was never in this runtime image, only in minio's own. Silently retried
|
||||||
|
# "spawn mc ENOENT" forever: a requirement was granted at the control-plane level without ever
|
||||||
|
# materializing the credential on minio. /usr/bin/mc there is a symlink to the real binary, mcli —
|
||||||
|
# both copied so the symlink resolves.
|
||||||
|
COPY --from=mccli /usr/bin/mcli /usr/bin/mcli
|
||||||
|
COPY --from=mccli /usr/bin/mc /usr/bin/mc
|
||||||
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
|
||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||||
# the convention novox/hq issues 060/061 settled.
|
# the convention novox/hq issues 060/061 settled.
|
||||||
|
|||||||
@@ -133,6 +133,10 @@
|
|||||||
"arg": "RUNTIME_BASE",
|
"arg": "RUNTIME_BASE",
|
||||||
"module": "mesh-tools",
|
"module": "mesh-tools",
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"arg": "MC_CLI",
|
||||||
|
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"artifacts": [
|
"artifacts": [
|
||||||
|
|||||||
Reference in New Issue
Block a user