diff --git a/modules/amqp-email-forwarder/module.json b/modules/amqp-email-forwarder/module.json index 81163b4..175fadb 100644 --- a/modules/amqp-email-forwarder/module.json +++ b/modules/amqp-email-forwarder/module.json @@ -49,7 +49,8 @@ ], "restart-on": [ "app-env" - ] + ], + "secrets-in-environment": "the runtime reads its SMTP and AMQP settings from the environment; a file twin in the SDK is the per-module work of issue 041" } ] } diff --git a/modules/amqp-ping/module.json b/modules/amqp-ping/module.json index 2f09f84..c78b31d 100644 --- a/modules/amqp-ping/module.json +++ b/modules/amqp-ping/module.json @@ -60,7 +60,8 @@ "restart-on": [ "amqp-env" ], - "artifact": "runtime" + "artifact": "runtime", + "secrets-in-environment": "the runtime reads MESH_AMQP_* from the environment; a file twin in the SDK is the per-module work of issue 041" } ], "build": { diff --git a/modules/baserow/module.json b/modules/baserow/module.json index e004c57..e44b6c2 100644 --- a/modules/baserow/module.json +++ b/modules/baserow/module.json @@ -85,7 +85,8 @@ ], "volumes": [ "/services/baserow/data:/baserow/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/de-spiegel/module.json b/modules/de-spiegel/module.json index 97804a3..600a819 100644 --- a/modules/de-spiegel/module.json +++ b/modules/de-spiegel/module.json @@ -59,7 +59,8 @@ ], "ports": [ "35621:35621" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" } ] } diff --git a/modules/gitea/module.json b/modules/gitea/module.json index 31e7ade..a7ba184 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -113,7 +113,8 @@ ], "volumes": [ "/services/gitea/gitea:/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "admin-bootstrap", @@ -137,7 +138,8 @@ "/bin/sh", "-c", "su-exec git gitea admin user create --admin --username \"$MESH_GITEA_ADMIN_USER\" --email mesh-admin@localhost --password \"$(cat /run/secrets/admin)\" --must-change-password=false || true" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/grafana/module.json b/modules/grafana/module.json index 5e35aff..b46c8a6 100644 --- a/modules/grafana/module.json +++ b/modules/grafana/module.json @@ -59,7 +59,8 @@ ], "volumes": [ "/services/grafana/data:/var/lib/grafana" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/icecast/module.json b/modules/icecast/module.json index ec765ec..54c2d01 100644 --- a/modules/icecast/module.json +++ b/modules/icecast/module.json @@ -52,7 +52,8 @@ ], "ports": [ "8000" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/influxdb/module.json b/modules/influxdb/module.json index b51328a..8017f21 100644 --- a/modules/influxdb/module.json +++ b/modules/influxdb/module.json @@ -65,7 +65,8 @@ "volumes": [ "/services/influxdb/data:/var/lib/influxdb2", "/services/influxdb/config:/etc/influxdb2" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/invoicing/module.json b/modules/invoicing/module.json index 0cbf319..fb6d870 100644 --- a/modules/invoicing/module.json +++ b/modules/invoicing/module.json @@ -99,7 +99,8 @@ ], "ports": [ "9000" - ] + ], + "secrets-in-environment": "the API reads its settings from the environment; converting is the per-module work of issue 041" } ] } diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index b14a087..9f1dd2e 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -96,7 +96,8 @@ ], "ports": [ "8080" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/letta/module.json b/modules/letta/module.json index cdb419e..a5c31d1 100644 --- a/modules/letta/module.json +++ b/modules/letta/module.json @@ -66,7 +66,8 @@ ], "ports": [ "8283" - ] + ], + "secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041" }, { "id": "runtime-config", @@ -103,7 +104,8 @@ "restart-on": [ "runtime-config" ], - "artifact": "runtime" + "artifact": "runtime", + "secrets-in-environment": "the runtime reads its settings from the environment; converting is the per-module work of issue 041" } ], "build": { diff --git a/modules/mailu/module.json b/modules/mailu/module.json index 79a9c60..112beb5 100644 --- a/modules/mailu/module.json +++ b/modules/mailu/module.json @@ -217,7 +217,8 @@ "env-file": [ "/var/lib/mailu/mailu.env", "/var/lib/mailu/secret.env" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "redis", @@ -244,7 +245,8 @@ "volumes": [ "/services/mailu/data/data:/data", "/services/mailu/data/dkim:/dkim" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "imap", @@ -259,7 +261,8 @@ "volumes": [ "/services/mailu/data/mail:/mail", "/services/mailu/data/overrides/dovecot:/overrides:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "smtp", @@ -274,7 +277,8 @@ "volumes": [ "/services/mailu/data/mailqueue:/queue", "/services/mailu/data/overrides/postfix:/overrides:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "antispam", @@ -289,7 +293,8 @@ "volumes": [ "/services/mailu/data/filter:/var/lib/rspamd", "/services/mailu/data/overrides/rspamd:/etc/rspamd/override.d:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "antivirus", @@ -303,7 +308,8 @@ ], "volumes": [ "/services/mailu/data/filter:/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "webmail", @@ -318,7 +324,8 @@ "volumes": [ "/services/mailu/data/webmail:/data", "/services/mailu/data/overrides/roundcube:/overrides:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "webdav", @@ -332,7 +339,8 @@ ], "volumes": [ "/services/mailu/data/dav:/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "fetchmail", @@ -346,7 +354,8 @@ ], "volumes": [ "/services/mailu/data/data/fetchmail:/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "front", @@ -368,7 +377,8 @@ "volumes": [ "/services/mailu/data/certs:/certs", "/services/mailu/data/overrides/nginx:/overrides:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/mesh-catalog/module.json b/modules/mesh-catalog/module.json index ca6f283..67f8bd2 100644 --- a/modules/mesh-catalog/module.json +++ b/modules/mesh-catalog/module.json @@ -74,7 +74,8 @@ "artifact": "runtime", "restart-on": [ "db-env" - ] + ], + "secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041" } ], "build": { diff --git a/modules/mesh-controller/module.json b/modules/mesh-controller/module.json index 14da2d4..9b0d74f 100644 --- a/modules/mesh-controller/module.json +++ b/modules/mesh-controller/module.json @@ -19,6 +19,7 @@ "broker-management": "/var/lib/mesh/mesh-controller/broker-management", "broker-address": "/var/lib/mesh/mesh-controller/broker-address" }, + "secrets-owner": "65534:65534", "resources": [ { "id": "mesh-state", @@ -26,13 +27,6 @@ "path": "/var/lib/mesh/mesh-controller", "mode": "0700" }, - { - "id": "control-env", - "type": "file", - "path": "/var/lib/mesh/mesh-controller/control.env", - "mode": "0600", - "content": "MESH_STORE_INVENTORY=${secret:inventory}\nMESH_STORE_IDENTITY=${secret:identity}\nMESH_STORE_LICENCES=${secret:licences}\nMESH_BROKER_AMQP=${secret:broker}\nMESH_BROKER_MANAGEMENT=${secret:broker-management}\nMESH_BROKER_ADDRESS=${secret:broker-address}\n" - }, { "id": "server", "type": "container", @@ -42,14 +36,23 @@ "args": [ "serve" ], - "env-file": [ - "/var/lib/mesh/mesh-controller/control.env" - ], "env": { - "MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt" + "MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt", + "MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory", + "MESH_STORE_IDENTITY_FILE": "/run/secrets/identity", + "MESH_STORE_LICENCES_FILE": "/run/secrets/licences", + "MESH_BROKER_AMQP_FILE": "/run/secrets/broker", + "MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management", + "MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address" }, "volumes": [ - "mesh-broker-tls:/broker-tls:ro" + "mesh-broker-tls:/broker-tls:ro", + "/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro", + "/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro", + "/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro", + "/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro", + "/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro", + "/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro" ], "restart-on": [ "control-env" diff --git a/modules/minio/module.json b/modules/minio/module.json index b16fc77..484e777 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -96,7 +96,8 @@ ], "volumes": [ "/services/minio/data/data1-1:/data" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime", diff --git a/modules/model-usage/module.json b/modules/model-usage/module.json index d9cdba6..0c00dee 100644 --- a/modules/model-usage/module.json +++ b/modules/model-usage/module.json @@ -60,7 +60,8 @@ }, "env-file": [ "/var/lib/model-usage/db.env" - ] + ], + "secrets-in-environment": "the mesh's own runtime reads MESH_STORE_* from the environment; a file twin in the SDK is the per-module work of issue 041" } ] } diff --git a/modules/mongodb/module.json b/modules/mongodb/module.json index bcd49f4..fb24a99 100644 --- a/modules/mongodb/module.json +++ b/modules/mongodb/module.json @@ -95,7 +95,8 @@ ], "volumes": [ "/services/mongodb/db-data:/data/db" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime", diff --git a/modules/mssql/module.json b/modules/mssql/module.json index cb516bc..5709e5f 100644 --- a/modules/mssql/module.json +++ b/modules/mssql/module.json @@ -91,7 +91,8 @@ ], "volumes": [ "/services/mssql/db-data:/var/opt/mssql" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime", diff --git a/modules/n8n/module.json b/modules/n8n/module.json index 6d6b299..14fc4a1 100644 --- a/modules/n8n/module.json +++ b/modules/n8n/module.json @@ -78,7 +78,8 @@ ], "volumes": [ "/services/n8n/n8n-data:/home/node/.n8n" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" } ] } diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index ec67ae6..3a0c22a 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -87,7 +87,8 @@ ], "volumes": [ "/services/nextcloud/html:/var/www/html" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/only-office/module.json b/modules/only-office/module.json index c94de42..ffc2739 100644 --- a/modules/only-office/module.json +++ b/modules/only-office/module.json @@ -109,7 +109,8 @@ "/services/only-office/rabbitmq:/var/lib/rabbitmq", "/services/only-office/redis:/var/lib/redis", "/services/only-office/fonts:/usr/share/fonts/truetype/custom" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" } ] } diff --git a/modules/photos/module.json b/modules/photos/module.json index 29c826a..1d280d3 100644 --- a/modules/photos/module.json +++ b/modules/photos/module.json @@ -74,7 +74,8 @@ ], "ports": [ "9000" - ] + ], + "secrets-in-environment": "the server reads its settings from the environment; converting is the per-module work of issue 041" }, { "id": "admin-client", diff --git a/modules/searxng/module.json b/modules/searxng/module.json index 60a0951..76d2d41 100644 --- a/modules/searxng/module.json +++ b/modules/searxng/module.json @@ -70,7 +70,8 @@ ], "ports": [ "8080" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime-config", diff --git a/modules/step-ca/module.json b/modules/step-ca/module.json index 15df1c1..9d1b18c 100644 --- a/modules/step-ca/module.json +++ b/modules/step-ca/module.json @@ -103,7 +103,8 @@ "volumes": [ "/var/lib/step-ca:/home/step", "/var/lib/mesh/step-ca:/run/mesh:ro" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" } ] } diff --git a/modules/umami/module.json b/modules/umami/module.json index b7991e3..d27a6a9 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -101,7 +101,8 @@ ], "ports": [ "3000" - ] + ], + "secrets-in-environment": "the image reads its configuration from the environment only; converting to a file is the per-module work of issue 041" }, { "id": "runtime",