From 50ae89e71839a001aede5afd0e15802919f74ee9 Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 16:18:59 +0200 Subject: [PATCH] influxdb: its admin password and operator token are its own secrets, so an existing instance's can be accepted MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit They came from `requires: secret`, minted by the vault — right for a fresh setup (the image's INIT_* variables read them once), wrong for an instance that already exists: setup is skipped, the minted values match nothing, and the provisioner holds a token the server never issued (issue 100). InfluxDB will not take a chosen token value, so the operator token must be accepted from the instance (`secret accept ace influxdb admin-token`); the password can be either. As own secrets both are minted for a fresh install exactly as before, and accepted where the data already knows them. Found migrating ace's influxdb. --- modules/influxdb/module.json | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/modules/influxdb/module.json b/modules/influxdb/module.json index 75fb2a7..5d3ac68 100644 --- a/modules/influxdb/module.json +++ b/modules/influxdb/module.json @@ -11,7 +11,9 @@ "container-runtime" ], "own-secrets": { - "broker": "/var/lib/mesh/influxdb/broker" + "broker": "/var/lib/mesh/influxdb/broker", + "admin": "${dir:state}/admin.secret", + "admin-token": "${dir:state}/admin-token.secret" }, "listens": [ { @@ -124,8 +126,7 @@ } ], "requires": [ - "route", - "secret" + "route" ], "contributes": { "route": { @@ -133,12 +134,6 @@ "endpoint": "api" } }, - "secrets": { - "secret": { - "admin": "${dir:state}/admin.secret", - "admin-token": "${dir:state}/admin-token.secret" - } - }, "build": { "on": [ {