From a5e21cb43874d7c8c13228ef5c6b573d6ab4c799 Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 23:43:00 +0200 Subject: [PATCH] grafana: its directories are placed, its admin password is a file, and it runs the build in use The module stated /var/lib/grafana-module and /services/grafana/data, a layout no definition may carry (ADR 0112). State and data are now placed directories; the admin secret lives beside the broker account under the mesh's own state. The admin password reached grafana through an env-file. Grafana honours GF_SECURITY_ADMIN_PASSWORD__FILE, so it is now a 0400 file owned by the image's user (472) and mounted, and "secrets-in-environment" is gone (ADR 0086). The runtime sidecar was given no credential at all - its config file was "{}", so GrafanaClient.fromEnv threw and the tools and the alert watcher did nothing. It now carries user/password from the same secret, and it calls grafana on the machine port the mesh assigned (${port:3000}) rather than a literal 3000. Image pinned to the 13.2.2 build ace's predecessor runs; the old pin was 13.2.1, older than the data it would open. Verified: catalogue tests with MESH_CATALOGUE pointing here; a throwaway container of the pinned image with the file-mounted secret answers /api/health and authenticates admin with the file's value (default admin/admin refused); restarted over the same data with a different file value, the original password still holds - so a migrated instance's password must be accepted, not minted; data owned by another uid fails to start, so a moved data directory must be chowned to 472. --- modules/grafana/module.json | 34 +++++++++++++++++----------------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/modules/grafana/module.json b/modules/grafana/module.json index 6911f08..b5a7458 100644 --- a/modules/grafana/module.json +++ b/modules/grafana/module.json @@ -5,7 +5,7 @@ "alert.firing" ], "own-secrets": { - "admin": "/var/lib/grafana-module/admin.secret", + "admin": "/var/lib/mesh/grafana/admin", "broker": "/var/lib/mesh/grafana/broker" }, "capabilities": [ @@ -30,45 +30,45 @@ { "id": "state", "type": "directory", - "path": "/var/lib/grafana-module", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "data", "type": "directory", - "path": "/services/grafana/data", "mode": "0700", "owner": "472:472" }, { - "id": "server-env", + "id": "admin-secret", "type": "file", - "path": "/var/lib/grafana-module/server.env", - "mode": "0600", - "content": "GF_SECURITY_ADMIN_PASSWORD=${secret:admin}\n" + "path": "${dir:state}/admin.secret", + "mode": "0400", + "owner": "472:472", + "content": "${secret:admin}" }, { "id": "server", "type": "container", "name": "grafana", - "image": "grafana/grafana@sha256:f772d434e8fab0049deb2b1b30abd43342bcfca1537614aa8d36080232cf4283", + "image": "grafana/grafana@sha256:ac461fb352abc50da10a51c7d02462e9c05488f11f53f14b3ad79a8145f638a0", "ports": [ "3000" ], "volumes": [ - "/services/grafana/data:/var/lib/grafana" + "${dir:data}:/var/lib/grafana", + "${dir:state}/admin.secret:/run/secrets/admin:ro" ], - "env-file": [ - "/var/lib/grafana-module/server.env" - ], - "secrets-in-environment": "grafana honours GF_SECURITY_ADMIN_PASSWORD__FILE; convertible, awaiting a bed that exercises the admin password (assigned-grafana serves tools only)" + "env": { + "GF_SECURITY_ADMIN_PASSWORD__FILE": "/run/secrets/admin" + } }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/grafana/config.json", "mode": "0600", - "content": "{}\n", + "content": "{\n \"user\": \"admin\",\n \"password\": \"${secret:admin}\"\n}\n", "merge": "json" }, { @@ -82,7 +82,7 @@ ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_GRAFANA_URL": "http://127.0.0.1:3000", + "MESH_GRAFANA_URL": "http://127.0.0.1:${port:3000}", "MESH_GRAFANA_CONFIG_FILE": "/run/config/config.json" }, "restart-on": [ @@ -101,7 +101,7 @@ } }, "binds": { - "route": "/var/lib/mesh/grafana/route.json" + "route": "${dir:state}/route.json" }, "build": { "on": [