From a32394ec2209aa7b56553dae319a49b5d626eb0d Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 23:05:41 +0200 Subject: [PATCH] mosquitto: its directories are placed, not stated, and it runs the build in use MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The module stated /var/lib/mosquitto-module and /services/mosquitto/data — novox's layout, a path no definition may carry (ADR 0112). State, grants and data are now placed directories (${dir:state}, ${dir:grants}, ${dir:data}), the admin secret lives beside the broker account under the mesh's own state, and the receives/grants maps follow the grants directory. Paths inside the sidecar are its own view and are unchanged. Image pinned to the 2.1.2 build ace's predecessor runs (2026-09-17); the old pin was the same version, built in June. Found preparing ace, whose broker carries a password-file user (an IoT switch and home-assistant). Carrying it is a data step, not a manifest one: the migration repo has scripts/mosquitto-pwdfile-to-dynsec.py, which moves $7$ PBKDF2 entries into the dynsec store hash-for-hash (tested end to end). --- modules/mosquitto/module.json | 30 ++++++++++++++---------------- 1 file changed, 14 insertions(+), 16 deletions(-) diff --git a/modules/mosquitto/module.json b/modules/mosquitto/module.json index 83c0476..7d85124 100644 --- a/modules/mosquitto/module.json +++ b/modules/mosquitto/module.json @@ -23,13 +23,13 @@ "mqtt-topic": {} }, "receives": { - "mqtt-topic": "/var/lib/mosquitto-module/grants/mesh.json" + "mqtt-topic": "${dir:grants}/mesh.json" }, "grants": { - "mqtt-topic": "/var/lib/mosquitto-module/grants" + "mqtt-topic": "${dir:grants}" }, "own-secrets": { - "admin": "/var/lib/mosquitto-module/admin.secret", + "admin": "/var/lib/mesh/mosquitto/admin", "broker": "/var/lib/mesh/mosquitto/broker" }, "listens": [ @@ -58,26 +58,24 @@ { "id": "state", "type": "directory", - "path": "/var/lib/mosquitto-module", - "mode": "0700" + "mode": "0700", + "place": "." }, { - "id": "grants-dir", + "id": "grants", "type": "directory", - "path": "/var/lib/mosquitto-module/grants", "mode": "0700" }, { "id": "data", "type": "directory", - "path": "/services/mosquitto/data", "mode": "0700", "owner": "1883:1883" }, { "id": "server-conf", "type": "file", - "path": "/var/lib/mosquitto-module/mosquitto.conf", + "path": "${dir:state}/mosquitto.conf", "mode": "0600", "owner": "1883:1883", "content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n" @@ -93,8 +91,8 @@ "name": "mosquitto-bootstrap", "run-once": true, "volumes": [ - "/services/mosquitto/data:/mosquitto/data", - "/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro" + "${dir:data}:/mosquitto/data", + "/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro" ], "env": { "MESH_PROVISION_MQTT": "mosquitto:1883", @@ -112,15 +110,15 @@ "id": "server", "type": "container", "name": "mosquitto", - "image": "eclipse-mosquitto@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797", + "image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408", "network": "mosquitto", "ports": [ "1883", "8081" ], "volumes": [ - "/services/mosquitto/data:/mosquitto/data", - "/var/lib/mosquitto-module/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro" + "${dir:data}:/mosquitto/data", + "${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro" ] }, { @@ -130,8 +128,8 @@ "network": "mosquitto", "volumes": [ "/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro", - "/var/lib/mosquitto-module/grants:/var/lib/mosquitto-module/grants:ro", - "/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro" + "${dir:grants}:/var/lib/mosquitto-module/grants:ro", + "/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker",