Phase 3.1: the postgres module adopts mesh-store instead of raising its own

server is now the container the foundation raised — same name (mesh-store),
same env (POSTGRES_PASSWORD/PGDATA), ports (127.0.0.1:5432:5432), volume
(mesh-store-data) and the same pinned upstream postgres image the foundation
runs — so the applier adopts it in place rather than raising a second postgres.
The provisioner is host-networked to reach the loopback store at 127.0.0.1:5432.
The module's own network and bind-mounted data dir are gone; there is one
postgres now, holding the controller's contexts and every module's database.

Issue 051 (WBS 3.1).

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-16 21:04:06 +02:00
parent 41637befff
commit a63ef3d954
+7 -29
View File
@@ -60,56 +60,34 @@
"path": "/var/lib/postgres/grants", "path": "/var/lib/postgres/grants",
"mode": "0700" "mode": "0700"
}, },
{
"id": "superuser-env",
"type": "file",
"path": "/var/lib/postgres/superuser.env",
"mode": "0600",
"content": "POSTGRES_PASSWORD=${secret:superuser}\n"
},
{
"id": "data",
"type": "directory",
"path": "/services/postgres/db-data",
"mode": "0700"
},
{
"id": "net",
"type": "network",
"name": "postgres"
},
{ {
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "postgres", "name": "mesh-store",
"image": "postgres@sha256:7456ef82e5f5bc43d997f4781bbd7c0d6389bff397564649a356e206ba473aee", "image": "postgres@sha256:7456ef82e5f5bc43d997f4781bbd7c0d6389bff397564649a356e206ba473aee",
"network": "postgres",
"env": { "env": {
"POSTGRES_USER": "postgres", "POSTGRES_PASSWORD": "bootstrap",
"POSTGRES_DB": "postgres" "PGDATA": "/var/lib/postgresql/data/pgdata"
}, },
"env-file": [
"/var/lib/postgres/superuser.env"
],
"ports": [ "ports": [
"5432" "5432:5432"
], ],
"volumes": [ "volumes": [
"/services/postgres/db-data:/var/lib/postgresql/data" "mesh-store-data:/var/lib/postgresql/data"
] ]
}, },
{ {
"id": "runtime", "id": "runtime",
"type": "container", "type": "container",
"name": "mesh-postgres", "name": "mesh-postgres",
"network": "postgres", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/postgres/broker:/run/secrets/broker:ro", "/var/lib/mesh/postgres/broker:/run/secrets/broker:ro",
"/var/lib/postgres/grants:/var/lib/postgres/grants:ro", "/var/lib/postgres/grants:/var/lib/postgres/grants:ro",
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro" "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
], ],
"env": { "env": {
"MESH_PROVISION_POSTGRES": "postgres://postgres@postgres:5432/postgres?sslmode=disable", "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:5432/postgres?sslmode=disable",
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json" "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"