From 61eb201f8af38f45f60a9bac2134b6c4f666045c Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 16:39:11 +0200 Subject: [PATCH] postgres: declare the data directory's real owner; keycloak: use the port template postgres: mesh-store's data directory has always had split ownership -- everything inside pgdata/ is owned by UID 999 (the pgvector image's real runtime user), while only the top-level mount point happened to be 70:70. Invisible while the directory's mode was 1777 (world-accessible, from the named volume this replaced); broke the moment mode: 0700 was enforced, locking out the actual owning process. mesh-store crash-looped on Permission denied twice before this was found -- once at container creation, once mid-session on a checkpoint, after ownership looked correct by every check that didn't look inside pgdata/ specifically. keycloak: MESH_KEYCLOAK_URL was hardcoded to :8080, but the module's own port override (settings set keycloak {ports:{8080:28080}} on novox) means the real published port is 28080. Same bug class as the postgres connection-string fix earlier tonight -- now using the mesh's own template instead, which is exactly the mechanism internal/catalogue/port_into.go describes for a sidecar dialling its own server over the machine's loopback. --- modules/keycloak/module.json | 2 +- modules/postgres/module.json | 3 ++- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 919be3c..04e6341 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -118,7 +118,7 @@ ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_KEYCLOAK_URL": "http://127.0.0.1:8080", + "MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}", "MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json" }, "restart-on": [ diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 3855f20..b543e5f 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -73,7 +73,8 @@ "id": "store-data", "type": "directory", "path": "/var/lib/mesh-store", - "mode": "0700" + "mode": "0700", + "owner": "999:70" }, { "id": "server",