postgres: declare the data directory's real owner; keycloak: use the port template

postgres: mesh-store's data directory has always had split ownership --
everything inside pgdata/ is owned by UID 999 (the pgvector image's real
runtime user), while only the top-level mount point happened to be 70:70.
Invisible while the directory's mode was 1777 (world-accessible, from the
named volume this replaced); broke the moment mode: 0700 was enforced,
locking out the actual owning process. mesh-store crash-looped on
Permission denied twice before this was found -- once at container
creation, once mid-session on a checkpoint, after ownership looked correct
by every check that didn't look inside pgdata/ specifically.

keycloak: MESH_KEYCLOAK_URL was hardcoded to :8080, but the module's own
port override (settings set keycloak {ports:{8080:28080}} on novox) means
the real published port is 28080. Same bug class as the postgres
connection-string fix earlier tonight -- now using the mesh's own
 template instead, which is exactly the mechanism
internal/catalogue/port_into.go describes for a sidecar dialling its own
server over the machine's loopback.
This commit is contained in:
2026-09-24 16:39:11 +02:00
parent 5c3781d8c2
commit 61eb201f8a
2 changed files with 3 additions and 2 deletions
+2 -1
View File
@@ -73,7 +73,8 @@
"id": "store-data",
"type": "directory",
"path": "/var/lib/mesh-store",
"mode": "0700"
"mode": "0700",
"owner": "999:70"
},
{
"id": "server",