From eed5e8958a10dd8989d807c296105c7a14fb89cd Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 30 Sep 2026 21:10:18 +0200 Subject: [PATCH] A definition names no host path for its own data MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths, mounts, env-files — as ${dir:}. Resolved on the default root every path is the one the manifest named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts; so no data moves and no machine sees a change. Five directories whose id is not their last segment keep their path as a placement (novox/hq issue 119, ADR 0112, design 27). --- modules/anthropic-consumer/module.json | 13 ++++----- modules/audit-logger/module.json | 11 ++++--- modules/builder/module.json | 5 ++-- modules/cloudflare-dns/module.json | 19 ++++++------ modules/confluence/module.json | 12 ++++---- modules/de-spiegel/module.json | 14 ++++----- modules/gitlab/module.json | 12 ++++---- modules/hello-web/module.json | 10 +++---- modules/invoicing/module.json | 18 ++++++------ modules/jira/module.json | 12 ++++---- modules/keycloak/module.json | 35 +++++++++++----------- modules/local-model-consumer/module.json | 9 +++--- modules/mesh-catalog/module.json | 14 ++++----- modules/mesh-vault/module.json | 23 +++++++-------- modules/minio/module.json | 23 +++++++-------- modules/model-usage/module.json | 14 ++++----- modules/n8n/module.json | 16 +++++----- modules/openai-consumer/module.json | 11 ++++--- modules/photos-eef/module.json | 6 ++-- modules/photos-filip/module.json | 6 ++-- modules/photos/module.json | 18 ++++++------ modules/postgres/module.json | 19 ++++++------ modules/records/module.json | 8 ++--- modules/route-adapter/module.json | 14 ++++----- modules/route-proxy/module.json | 32 ++++++++++---------- modules/showcase/module.json | 16 +++++----- modules/step-ca/module.json | 6 ++-- modules/umami/module.json | 37 ++++++++++++------------ 28 files changed, 210 insertions(+), 223 deletions(-) diff --git a/modules/anthropic-consumer/module.json b/modules/anthropic-consumer/module.json index 55754a7..fe0a2a1 100644 --- a/modules/anthropic-consumer/module.json +++ b/modules/anthropic-consumer/module.json @@ -9,10 +9,10 @@ "model-access" ], "binds": { - "model-access": "/var/lib/anthropic-consumer/model.json" + "model-access": "${dir:state}/model.json" }, "secrets": { - "model-access": "/var/lib/anthropic-consumer/access-token" + "model-access": "${dir:state}/access-token" }, "own-secrets": { "broker": "/var/lib/mesh/anthropic-consumer/broker" @@ -30,8 +30,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/anthropic-consumer", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "claude-home", @@ -42,7 +42,6 @@ { "id": "out", "type": "directory", - "path": "/var/lib/anthropic-consumer/out", "mode": "0700" }, { @@ -56,7 +55,7 @@ "/app/modules/anthropic-consumer/dist/apply/index.js" ], "volumes": [ - "/var/lib/anthropic-consumer:/run/state" + "${dir:state}:/run/state" ], "env": { "MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/access-token", @@ -78,7 +77,7 @@ ], "volumes": [ "/var/lib/mesh/anthropic-consumer/broker:/run/secrets/broker:ro", - "/var/lib/anthropic-consumer:/run/state" + "${dir:state}:/run/state" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", diff --git a/modules/audit-logger/module.json b/modules/audit-logger/module.json index 0fbae45..358dbcd 100644 --- a/modules/audit-logger/module.json +++ b/modules/audit-logger/module.json @@ -6,7 +6,7 @@ "**" ], "own-secrets": { - "broker": "/var/lib/audit-logger/broker" + "broker": "${dir:state}/broker" }, "build": { "on": [ @@ -33,13 +33,12 @@ { "id": "state", "type": "directory", - "path": "/var/lib/audit-logger", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "trail", "type": "directory", - "path": "/var/lib/audit-logger/trail", "mode": "0700" }, { @@ -48,8 +47,8 @@ "name": "mesh-audit-logger", "network": "host", "volumes": [ - "/var/lib/audit-logger/broker:/run/secrets/broker:ro", - "/var/lib/audit-logger/trail:/trail" + "${dir:state}/broker:/run/secrets/broker:ro", + "${dir:trail}:/trail" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", diff --git a/modules/builder/module.json b/modules/builder/module.json index 508852e..70147ad 100644 --- a/modules/builder/module.json +++ b/modules/builder/module.json @@ -33,7 +33,6 @@ { "id": "workspace", "type": "directory", - "path": "/var/lib/builder/workspace", "mode": "0700" }, { @@ -41,7 +40,7 @@ "type": "file", "path": "/var/lib/mesh/builder/builder.env", "mode": "0600", - "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=/var/lib/builder/workspace\n" + "content": "MESH_BROKER_FILE=/run/mesh/broker\nMESH_NODE=${machine:name}\nMESH_REGISTRY=${bound:artifact-store:at}:${bound:artifact-store:port}\nMESH_PACKAGE_BINDING=/run/mesh/package-registry.json\nMESH_NPM_TOKEN_FILE=/run/mesh/package-registry.secret\nMESH_WORKSPACE=${dir:workspace}\n" }, { "id": "server", @@ -53,7 +52,7 @@ ], "volumes": [ "/var/lib/mesh/builder:/run/mesh:ro", - "/var/lib/builder/workspace:/var/lib/builder/workspace", + "${dir:workspace}:${dir:workspace}", "/var/run/docker.sock:/var/run/docker.sock" ], "restart-on": [ diff --git a/modules/cloudflare-dns/module.json b/modules/cloudflare-dns/module.json index 9ce387f..6eb60a5 100644 --- a/modules/cloudflare-dns/module.json +++ b/modules/cloudflare-dns/module.json @@ -12,13 +12,13 @@ "public-dns": {} }, "grants": { - "public-dns": "/var/lib/cloudflare-dns/grants" + "public-dns": "${dir:grants}" }, "receives": { - "public-dns": "/var/lib/cloudflare-dns/grants/mesh.json" + "public-dns": "${dir:grants}/mesh.json" }, "own-secrets": { - "token": "/var/lib/cloudflare-dns/token", + "token": "${dir:state}/token", "broker": "/var/lib/mesh/cloudflare-dns/broker" }, "emits": [ @@ -35,19 +35,18 @@ { "id": "state", "type": "directory", - "path": "/var/lib/cloudflare-dns", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/cloudflare-dns/grants", "mode": "0700" }, { "id": "config", "type": "file", - "path": "/var/lib/cloudflare-dns/config.json", + "path": "${dir:state}/config.json", "merge": "json", "content": "{}", "mode": "0600" @@ -58,9 +57,9 @@ "name": "mesh-cloudflare-dns", "network": "host", "volumes": [ - "/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro", - "/var/lib/cloudflare-dns/grants:/grants", - "/var/lib/cloudflare-dns/token:/run/secrets/token:ro", + "${dir:state}/config.json:/run/config/config.json:ro", + "${dir:grants}:/grants", + "${dir:state}/token:/run/secrets/token:ro", "/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro" ], "env": { diff --git a/modules/confluence/module.json b/modules/confluence/module.json index b28168b..ffae1a9 100644 --- a/modules/confluence/module.json +++ b/modules/confluence/module.json @@ -3,7 +3,7 @@ "version": "1", "slug": "confl", "own-secrets": { - "token": "/var/lib/confluence/token", + "token": "${dir:state}/token", "broker": "/var/lib/mesh/confluence/broker" }, "resources": [ @@ -16,13 +16,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/confluence", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", "type": "file", - "path": "/var/lib/confluence/config.json", + "path": "${dir:state}/config.json", "merge": "json", "content": "{}", "mode": "0600" @@ -33,8 +33,8 @@ "name": "mesh-runtime-confluence", "network": "host", "volumes": [ - "/var/lib/confluence/config.json:/run/config/config.json:ro", - "/var/lib/confluence/token:/run/secrets/token:ro", + "${dir:state}/config.json:/run/config/config.json:ro", + "${dir:state}/token:/run/secrets/token:ro", "/var/lib/mesh/confluence/broker:/run/secrets/broker:ro" ], "env": { diff --git a/modules/de-spiegel/module.json b/modules/de-spiegel/module.json index 46f0ff7..6ace95e 100644 --- a/modules/de-spiegel/module.json +++ b/modules/de-spiegel/module.json @@ -15,11 +15,11 @@ } }, "binds": { - "route": "/var/lib/de-spiegel/route.json" + "route": "${dir:state}/route.json" }, "own-secrets": { - "smtp-user": "/var/lib/de-spiegel/smtp-user.secret", - "smtp-pass": "/var/lib/de-spiegel/smtp-pass.secret" + "smtp-user": "${dir:state}/smtp-user.secret", + "smtp-pass": "${dir:state}/smtp-pass.secret" }, "listens": [ { @@ -34,13 +34,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/de-spiegel", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "server-env", "type": "file", - "path": "/var/lib/de-spiegel/server.env", + "path": "${dir:state}/server.env", "mode": "0600", "content": "SMTP_AUTH_USER=${secret:smtp-user}\nSMTP_AUTH_PASS=${secret:smtp-pass}\n" }, @@ -56,7 +56,7 @@ "image": "registry-api.novox.be/novox/de-spiegel@sha256:e144b72ce9c145870470d765343549f2c60211728cd118b9ff0e4029f36342ba", "network": "de-spiegel", "env-file": [ - "/var/lib/de-spiegel/server.env" + "${dir:state}/server.env" ], "ports": [ "35621" diff --git a/modules/gitlab/module.json b/modules/gitlab/module.json index b082001..ac96364 100644 --- a/modules/gitlab/module.json +++ b/modules/gitlab/module.json @@ -2,7 +2,7 @@ "module": "gitlab", "version": "1", "own-secrets": { - "token": "/var/lib/gitlab/token", + "token": "${dir:state}/token", "broker": "/var/lib/mesh/gitlab/broker" }, "resources": [ @@ -15,13 +15,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/gitlab", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", "type": "file", - "path": "/var/lib/gitlab/config.json", + "path": "${dir:state}/config.json", "merge": "json", "content": "{}", "mode": "0600" @@ -32,8 +32,8 @@ "name": "mesh-runtime-gitlab", "network": "host", "volumes": [ - "/var/lib/gitlab/config.json:/run/config/config.json:ro", - "/var/lib/gitlab/token:/run/secrets/token:ro", + "${dir:state}/config.json:/run/config/config.json:ro", + "${dir:state}/token:/run/secrets/token:ro", "/var/lib/mesh/gitlab/broker:/run/secrets/broker:ro" ], "env": { diff --git a/modules/hello-web/module.json b/modules/hello-web/module.json index 55e1c10..1811a1f 100644 --- a/modules/hello-web/module.json +++ b/modules/hello-web/module.json @@ -15,7 +15,7 @@ } }, "binds": { - "route": "/var/lib/hello-web/route.json" + "route": "${dir:state}/route.json" }, "listens": [ { @@ -30,13 +30,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/hello-web", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "page", "type": "file", - "path": "/var/lib/hello-web/index.html", + "path": "${dir:state}/index.html", "mode": "0644", "content": "hello from hello-web, routed by the mesh\n" }, @@ -54,7 +54,7 @@ "8080" ], "volumes": [ - "/var/lib/hello-web/index.html:/www/index.html:ro" + "${dir:state}/index.html:/www/index.html:ro" ], "args": [ "sh", diff --git a/modules/invoicing/module.json b/modules/invoicing/module.json index f2eec75..de79397 100644 --- a/modules/invoicing/module.json +++ b/modules/invoicing/module.json @@ -26,13 +26,13 @@ } }, "binds": { - "mongodb-database": "/var/lib/invoicing/database.json", - "s3-bucket": "/var/lib/invoicing/store.json", - "route": "/var/lib/invoicing/route.json" + "mongodb-database": "${dir:state}/database.json", + "s3-bucket": "${dir:state}/store.json", + "route": "${dir:state}/route.json" }, "secrets": { - "mongodb-database": "/var/lib/invoicing/database.secret", - "s3-bucket": "/var/lib/invoicing/store.secret" + "mongodb-database": "${dir:state}/database.secret", + "s3-bucket": "${dir:state}/store.secret" }, "listens": [ { @@ -60,13 +60,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/invoicing", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "api-env", "type": "file", - "path": "/var/lib/invoicing/api.env", + "path": "${dir:state}/api.env", "mode": "0600", "content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=${bound:mongodb-database:as}\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_BUCKET=mesh-novox-invoice\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n" }, @@ -103,7 +103,7 @@ "GID": "2201" }, "env-file": [ - "/var/lib/invoicing/api.env" + "${dir:state}/api.env" ], "ports": [ "9000" diff --git a/modules/jira/module.json b/modules/jira/module.json index 62e6e64..d8ac539 100644 --- a/modules/jira/module.json +++ b/modules/jira/module.json @@ -2,7 +2,7 @@ "module": "jira", "version": "1", "own-secrets": { - "token": "/var/lib/jira/token", + "token": "${dir:state}/token", "broker": "/var/lib/mesh/jira/broker" }, "resources": [ @@ -15,13 +15,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/jira", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", "type": "file", - "path": "/var/lib/jira/config.json", + "path": "${dir:state}/config.json", "merge": "json", "content": "{}", "mode": "0600" @@ -32,8 +32,8 @@ "name": "mesh-runtime-jira", "network": "host", "volumes": [ - "/var/lib/jira/config.json:/run/config/config.json:ro", - "/var/lib/jira/token:/run/secrets/token:ro", + "${dir:state}/config.json:/run/config/config.json:ro", + "${dir:state}/token:/run/secrets/token:ro", "/var/lib/mesh/jira/broker:/run/secrets/broker:ro" ], "env": { diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 010a0a5..1afc95e 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -21,11 +21,11 @@ } }, "binds": { - "postgres-database": "/var/lib/keycloak/database.json", - "route": "/var/lib/keycloak/route.json" + "postgres-database": "${dir:state}/database.json", + "route": "${dir:state}/route.json" }, "secrets": { - "postgres-database": "/var/lib/keycloak/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "capabilities": [ "container-runtime" @@ -55,13 +55,13 @@ } }, "receives": { - "oidc-client": "/var/lib/keycloak/grants/mesh.json" + "oidc-client": "${dir:grants}/mesh.json" }, "grants": { - "oidc-client": "/var/lib/keycloak/grants" + "oidc-client": "${dir:grants}" }, "own-secrets": { - "admin": "/var/lib/keycloak/admin.secret", + "admin": "${dir:state}/admin.secret", "broker": "/var/lib/mesh/keycloak/broker" }, "resources": [ @@ -74,26 +74,25 @@ { "id": "state", "type": "directory", - "path": "/var/lib/keycloak", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/keycloak/grants", "mode": "0700" }, { "id": "admin-env", "type": "file", - "path": "/var/lib/keycloak/admin.env", + "path": "${dir:state}/admin.env", "mode": "0600", "content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n" }, { "id": "database-env", "type": "file", - "path": "/var/lib/keycloak/database.env", + "path": "${dir:state}/database.env", "mode": "0600", "content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n" }, @@ -105,7 +104,7 @@ { "id": "hostname", "type": "file", - "path": "/var/lib/keycloak/hostname.env", + "path": "${dir:state}/hostname.env", "mode": "0644", "content": "KC_HOSTNAME=https://${bound:route:name}\n" }, @@ -125,9 +124,9 @@ "KC_PROXY_HEADERS": "xforwarded" }, "env-file": [ - "/var/lib/keycloak/admin.env", - "/var/lib/keycloak/database.env", - "/var/lib/keycloak/hostname.env" + "${dir:state}/admin.env", + "${dir:state}/database.env", + "${dir:state}/hostname.env" ], "ports": [ "8080" @@ -153,15 +152,15 @@ "volumes": [ "/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro", "/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro", - "/var/lib/keycloak/admin.secret:/run/secrets/admin:ro", - "/var/lib/keycloak/grants:/var/lib/keycloak/grants:ro" + "${dir:state}/admin.secret:/run/secrets/admin:ro", + "${dir:grants}:${dir:grants}:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}", "MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json", "MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin", - "MESH_RECEIVES": "/var/lib/keycloak/grants/mesh.json" + "MESH_RECEIVES": "${dir:grants}/mesh.json" }, "restart-on": [ "runtime-config" diff --git a/modules/local-model-consumer/module.json b/modules/local-model-consumer/module.json index d432025..e90fbf5 100644 --- a/modules/local-model-consumer/module.json +++ b/modules/local-model-consumer/module.json @@ -6,25 +6,24 @@ "model-access" ], "binds": { - "model-access": "/var/lib/local-model-consumer/model.json" + "model-access": "${dir:state}/model.json" }, "resources": [ { "id": "state", "type": "directory", - "path": "/var/lib/local-model-consumer", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", "type": "directory", - "path": "/var/lib/local-model-consumer/config", "mode": "0700" }, { "id": "openai-env", "type": "file", - "path": "/var/lib/local-model-consumer/config/openai.env", + "path": "${dir:config}/openai.env", "mode": "0600", "content": "OPENAI_BASE_URL=http://${bound:model-access:at}:${bound:model-access:port}/v1\nOPENAI_MODEL=${bound:model-access:model}\nOPENAI_API_KEY=local\n" } diff --git a/modules/mesh-catalog/module.json b/modules/mesh-catalog/module.json index f6dd5c7..6afa050 100644 --- a/modules/mesh-catalog/module.json +++ b/modules/mesh-catalog/module.json @@ -20,10 +20,10 @@ } }, "binds": { - "postgres-database": "/var/lib/mesh-catalog/database.json" + "postgres-database": "${dir:state}/database.json" }, "secrets": { - "postgres-database": "/var/lib/mesh-catalog/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "own-secrets": { "broker": "/var/lib/mesh/mesh-catalog/broker" @@ -49,13 +49,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/mesh-catalog", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "database-url", "type": "file", - "path": "/var/lib/mesh-catalog/database.url", + "path": "${dir:state}/database.url", "mode": "0600", "content": "postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n" }, @@ -66,8 +66,8 @@ "network": "host", "volumes": [ "/var/lib/mesh/mesh-catalog/broker:/run/secrets/broker:ro", - "/var/lib/mesh-catalog:/run/state", - "/var/lib/mesh-catalog/database.url:/run/secrets/database-url:ro" + "${dir:state}:/run/state", + "${dir:state}/database.url:/run/secrets/database-url:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", diff --git a/modules/mesh-vault/module.json b/modules/mesh-vault/module.json index 70577e5..3d0e2fa 100644 --- a/modules/mesh-vault/module.json +++ b/modules/mesh-vault/module.json @@ -21,10 +21,10 @@ "mesh-vault.secret.deprovisioned" ], "receives": { - "secret": "/var/lib/mesh-vault/grants/mesh.json" + "secret": "${dir:grants}/mesh.json" }, "grants": { - "secret": "/var/lib/mesh-vault/grants" + "secret": "${dir:grants}" }, "keeps": "/var/lib/mesh-vault/root", "own-secrets": { @@ -40,25 +40,22 @@ { "id": "state", "type": "directory", - "path": "/var/lib/mesh-vault", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/mesh-vault/grants", "mode": "0700" }, { "id": "ledger", "type": "directory", - "path": "/var/lib/mesh-vault/ledger", "mode": "0700" }, { "id": "root", "type": "directory", - "path": "/var/lib/mesh-vault/root", "mode": "0700" }, { @@ -68,15 +65,15 @@ "network": "host", "volumes": [ "/var/lib/mesh/mesh-vault/broker:/run/secrets/broker:ro", - "/var/lib/mesh-vault/grants:/var/lib/mesh-vault/grants:ro", - "/var/lib/mesh-vault/ledger:/var/lib/mesh-vault/ledger", - "/var/lib/mesh-vault/root:/var/lib/mesh-vault/root:ro" + "${dir:grants}:${dir:grants}:ro", + "${dir:ledger}:${dir:ledger}", + "${dir:root}:${dir:root}:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/mesh-vault/grants/mesh.json", - "MESH_VAULT_LEDGER": "/var/lib/mesh-vault/ledger", - "MESH_VAULT_ROOT": "/var/lib/mesh-vault/root" + "MESH_RECEIVES": "${dir:grants}/mesh.json", + "MESH_VAULT_LEDGER": "${dir:ledger}", + "MESH_VAULT_ROOT": "${dir:root}" }, "artifact": "runtime" } diff --git a/modules/minio/module.json b/modules/minio/module.json index 6a854bf..30976f9 100644 --- a/modules/minio/module.json +++ b/modules/minio/module.json @@ -53,13 +53,13 @@ } }, "receives": { - "s3-bucket": "/var/lib/minio/grants/mesh.json" + "s3-bucket": "${dir:grants}/mesh.json" }, "grants": { - "s3-bucket": "/var/lib/minio/grants" + "s3-bucket": "${dir:grants}" }, "own-secrets": { - "root": "/var/lib/minio/root.secret", + "root": "${dir:state}/root.secret", "broker": "/var/lib/mesh/minio/broker" }, "resources": [ @@ -72,19 +72,18 @@ { "id": "state", "type": "directory", - "path": "/var/lib/minio", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/minio/grants", "mode": "0700" }, { "id": "root-env", "type": "file", - "path": "/var/lib/minio/root.env", + "path": "${dir:state}/root.env", "mode": "0600", "content": "MINIO_ROOT_USER=meshroot\nMINIO_BROWSER_REDIRECT_URL=https://${bound:route:name-console}\n" }, @@ -112,7 +111,7 @@ ":9001" ], "env-file": [ - "/var/lib/minio/root.env" + "${dir:state}/root.env" ], "ports": [ "9000", @@ -120,7 +119,7 @@ ], "volumes": [ "/var/lib/minio-store:/data", - "/var/lib/minio/root.secret:/run/secrets/root:ro" + "${dir:state}/root.secret:/run/secrets/root:ro" ], "env": { "MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", @@ -134,8 +133,8 @@ "network": "minio-net", "volumes": [ "/var/lib/mesh/minio/broker:/run/secrets/broker:ro", - "/var/lib/minio/grants:/var/lib/minio/grants:ro", - "/var/lib/minio/root.secret:/run/secrets/root:ro" + "${dir:grants}:${dir:grants}:ro", + "${dir:state}/root.secret:/run/secrets/root:ro" ], "env": { "MESH_MINIO_ENDPOINT": "http://minio:9000", @@ -143,7 +142,7 @@ "MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root", "MESH_MINIO_REGION": "eu-west", "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/minio/grants/mesh.json" + "MESH_RECEIVES": "${dir:grants}/mesh.json" }, "artifact": "runtime" } diff --git a/modules/model-usage/module.json b/modules/model-usage/module.json index 60ec754..40df226 100644 --- a/modules/model-usage/module.json +++ b/modules/model-usage/module.json @@ -14,10 +14,10 @@ } }, "binds": { - "postgres-database": "/var/lib/model-usage/database.json" + "postgres-database": "${dir:state}/database.json" }, "secrets": { - "postgres-database": "/var/lib/model-usage/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "consumes": [ "*.usage.*" @@ -35,13 +35,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/model-usage", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "database-url", "type": "file", - "path": "/var/lib/model-usage/database.url", + "path": "${dir:state}/database.url", "mode": "0600", "content": "postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n" }, @@ -53,8 +53,8 @@ "network": "host", "volumes": [ "/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro", - "/var/lib/model-usage:/run/state", - "/var/lib/model-usage/database.url:/run/secrets/database-url:ro" + "${dir:state}:/run/state", + "${dir:state}/database.url:/run/secrets/database-url:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", diff --git a/modules/n8n/module.json b/modules/n8n/module.json index f3db82c..88d7bf5 100644 --- a/modules/n8n/module.json +++ b/modules/n8n/module.json @@ -18,14 +18,14 @@ } }, "binds": { - "postgres-database": "/var/lib/n8n/database.json", - "route": "/var/lib/n8n/route.json" + "postgres-database": "${dir:state}/database.json", + "route": "${dir:state}/route.json" }, "secrets": { - "postgres-database": "/var/lib/n8n/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "own-secrets": { - "basic-auth": "/var/lib/n8n/basic-auth.secret" + "basic-auth": "${dir:state}/basic-auth.secret" }, "listens": [ { @@ -40,8 +40,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/n8n", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "data", @@ -53,7 +53,7 @@ { "id": "server-env", "type": "file", - "path": "/var/lib/n8n/server.env", + "path": "${dir:state}/server.env", "mode": "0600", "content": "N8N_HOST=${bound:route:name}\nN8N_PORT=5678\nN8N_PROTOCOL=https\nWEBHOOK_URL=https://${bound:route:name}/\nN8N_BASIC_AUTH_ACTIVE=true\nN8N_BASIC_AUTH_USER=admin\nN8N_BASIC_AUTH_PASSWORD=${secret:basic-auth}\nNODE_FUNCTION_ALLOW_BUILTIN=*\nNODE_FUNCTION_ALLOW_EXTERNAL=*\nDB_TYPE=postgresdb\nDB_POSTGRESDB_HOST=${bound:postgres-database:at}\nDB_POSTGRESDB_PORT=${bound:postgres-database:port}\nDB_POSTGRESDB_DATABASE=${bound:postgres-database:as}\nDB_POSTGRESDB_USER=${bound:postgres-database:as}\nDB_POSTGRESDB_PASSWORD=${secret:postgres-database}\n" }, @@ -69,7 +69,7 @@ "image": "n8nio/n8n@sha256:4846eb2f4b874ab04cde7fc1e249d2ddaec66e9aea64439beb2972cfea88e3c0", "network": "n8n", "env-file": [ - "/var/lib/n8n/server.env" + "${dir:state}/server.env" ], "ports": [ "5678" diff --git a/modules/openai-consumer/module.json b/modules/openai-consumer/module.json index fef8822..6d4a0b0 100644 --- a/modules/openai-consumer/module.json +++ b/modules/openai-consumer/module.json @@ -9,22 +9,21 @@ "model-access" ], "binds": { - "model-access": "/var/lib/openai-consumer/model.json" + "model-access": "${dir:state}/model.json" }, "secrets": { - "model-access": "/var/lib/openai-consumer/api-key" + "model-access": "${dir:state}/api-key" }, "resources": [ { "id": "state", "type": "directory", - "path": "/var/lib/openai-consumer", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", "type": "directory", - "path": "/var/lib/openai-consumer/config", "mode": "0700" }, { @@ -38,7 +37,7 @@ "/app/modules/openai-consumer/dist/apply/index.js" ], "volumes": [ - "/var/lib/openai-consumer:/run/state" + "${dir:state}:/run/state" ], "env": { "MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/api-key", diff --git a/modules/photos-eef/module.json b/modules/photos-eef/module.json index 96dd317..1a63d49 100644 --- a/modules/photos-eef/module.json +++ b/modules/photos-eef/module.json @@ -15,7 +15,7 @@ } }, "binds": { - "route": "/var/lib/photos-eef/route.json" + "route": "${dir:state}/route.json" }, "listens": [ { @@ -30,8 +30,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/photos-eef", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "net", diff --git a/modules/photos-filip/module.json b/modules/photos-filip/module.json index 9e0c286..daa58c6 100644 --- a/modules/photos-filip/module.json +++ b/modules/photos-filip/module.json @@ -15,7 +15,7 @@ } }, "binds": { - "route": "/var/lib/photos-filip/route.json" + "route": "${dir:state}/route.json" }, "listens": [ { @@ -30,8 +30,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/photos-filip", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "net", diff --git a/modules/photos/module.json b/modules/photos/module.json index fbfa007..8cc9c74 100644 --- a/modules/photos/module.json +++ b/modules/photos/module.json @@ -22,13 +22,13 @@ } }, "binds": { - "s3-bucket": "/var/lib/photos/store.json", - "mongodb-database": "/var/lib/photos/database.json", - "route": "/var/lib/photos/route.json" + "s3-bucket": "${dir:state}/store.json", + "mongodb-database": "${dir:state}/database.json", + "route": "${dir:state}/route.json" }, "secrets": { - "s3-bucket": "/var/lib/photos/store.secret", - "mongodb-database": "/var/lib/photos/database.secret" + "s3-bucket": "${dir:state}/store.secret", + "mongodb-database": "${dir:state}/database.secret" }, "listens": [ { @@ -50,13 +50,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/photos", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "server-env", "type": "file", - "path": "/var/lib/photos/server.env", + "path": "${dir:state}/server.env", "mode": "0600", "content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=admin\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_BUCKET=mesh-novox-photos\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\nMINIO_USE_SSL=false\n" }, @@ -72,7 +72,7 @@ "image": "registry-api.novox.be/novox/photos-server@sha256:3f165acbbd1fd731b12fe798c95879c081a44b00e2c569ef7f47165f6a527201", "network": "photos", "env-file": [ - "/var/lib/photos/server.env" + "${dir:state}/server.env" ], "ports": [ "9000" diff --git a/modules/postgres/module.json b/modules/postgres/module.json index fd9d186..76166a4 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -42,13 +42,13 @@ } }, "receives": { - "postgres-database": "/var/lib/postgres/grants/mesh.json" + "postgres-database": "${dir:grants}/mesh.json" }, "grants": { - "postgres-database": "/var/lib/postgres/grants" + "postgres-database": "${dir:grants}" }, "own-secrets": { - "superuser": "/var/lib/postgres/superuser.secret", + "superuser": "${dir:state}/superuser.secret", "broker": "/var/lib/mesh/postgres/broker" }, "resources": [ @@ -61,13 +61,12 @@ { "id": "state", "type": "directory", - "path": "/var/lib/postgres", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/postgres/grants", "mode": "0700" }, { @@ -91,7 +90,7 @@ ], "volumes": [ "/var/lib/mesh-store:/var/lib/postgresql/data", - "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro" + "${dir:state}/superuser.secret:/run/secrets/superuser:ro" ] }, { @@ -101,15 +100,15 @@ "network": "host", "volumes": [ "/var/lib/mesh/postgres/broker:/run/secrets/broker:ro", - "/var/lib/postgres/grants:/var/lib/postgres/grants:ro", - "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro" + "${dir:grants}:${dir:grants}:ro", + "${dir:state}/superuser.secret:/run/secrets/superuser:ro" ], "env": { "MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable", "MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}", "MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser", "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json" + "MESH_RECEIVES": "${dir:grants}/mesh.json" }, "artifact": "runtime" } diff --git a/modules/records/module.json b/modules/records/module.json index f5aebdc..296d7ee 100644 --- a/modules/records/module.json +++ b/modules/records/module.json @@ -34,8 +34,8 @@ { "id": "checkout", "type": "directory", - "path": "/var/lib/records", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "config", @@ -61,13 +61,13 @@ "/var/lib/mesh/records/broker:/run/secrets/broker:ro", "/var/lib/mesh/records/config.json:/run/config/config.json:ro", "/var/lib/mesh/records/origin:/run/config/origin:ro", - "/var/lib/records:/var/lib/records" + "${dir:checkout}:${dir:checkout}" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_RECORDS_CONFIG_FILE": "/run/config/config.json", "MESH_RECORDS_ORIGIN_FILE": "/run/config/origin", - "MESH_RECORDS_DIR": "/var/lib/records" + "MESH_RECORDS_DIR": "${dir:checkout}" }, "artifact": "runtime", "restart-on": [ diff --git a/modules/route-adapter/module.json b/modules/route-adapter/module.json index 8003fda..144019b 100644 --- a/modules/route-adapter/module.json +++ b/modules/route-adapter/module.json @@ -15,7 +15,7 @@ "route": {} }, "receives": { - "route": "/var/lib/route-adapter/routes/mesh.json" + "route": "${dir:routes-dir}/mesh.json" }, "accesses": [ { @@ -27,8 +27,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/route-adapter", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "routes-dir", @@ -39,7 +39,7 @@ { "id": "config", "type": "file", - "path": "/var/lib/route-adapter/config.json", + "path": "${dir:state}/config.json", "merge": "json", "mode": "0644", "content": "{\n \"dynamic\": \"/services/traefik/dynamic\",\n \"entrypoint\": \"websecure\",\n \"certificate-resolver\": \"le\",\n \"machine\": \"host.docker.internal\"\n}\n" @@ -51,12 +51,12 @@ "artifact": "runtime", "run-once": true, "volumes": [ - "/var/lib/route-adapter/routes/mesh.json:/var/lib/route-adapter/routes/mesh.json:ro", - "/var/lib/route-adapter/config.json:/run/config/config.json:ro", + "${dir:routes-dir}/mesh.json:${dir:routes-dir}/mesh.json:ro", + "${dir:state}/config.json:/run/config/config.json:ro", "/services/traefik/dynamic:/services/traefik/dynamic" ], "env": { - "MESH_RECEIVES": "/var/lib/route-adapter/routes/mesh.json", + "MESH_RECEIVES": "${dir:routes-dir}/mesh.json", "MESH_ROUTE_ADAPTER_CONFIG": "/run/config/config.json" }, "args": [ diff --git a/modules/route-proxy/module.json b/modules/route-proxy/module.json index 0285b38..488c63b 100644 --- a/modules/route-proxy/module.json +++ b/modules/route-proxy/module.json @@ -15,15 +15,15 @@ "route": {} }, "receives": { - "route": "/var/lib/route-proxy/routes/mesh.json" + "route": "${dir:routes-dir}/mesh.json" }, "requires": [ "acme-ca", "internal-acme-ca" ], "binds": { - "acme-ca": "/var/lib/route-proxy/acme-ca.json", - "internal-acme-ca": "/var/lib/route-proxy/internal-acme-ca.json" + "acme-ca": "${dir:state}/acme-ca.json", + "internal-acme-ca": "${dir:state}/internal-acme-ca.json" }, "listens": [ { @@ -45,8 +45,8 @@ { "id": "state", "type": "directory", - "path": "/var/lib/route-proxy", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "routes-dir", @@ -69,14 +69,14 @@ { "id": "acme-env", "type": "file", - "path": "/var/lib/route-proxy/acme.env", + "path": "${dir:state}/acme.env", "mode": "0600", "content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n" }, { "id": "internal-acme-env", "type": "file", - "path": "/var/lib/route-proxy/internal-acme.env", + "path": "${dir:state}/internal-acme.env", "mode": "0600", "content": "INTERNAL_ACME_DIRECTORY=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:path}\nINTERNAL_ACME_ROOTS=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}\nINTERNAL_ACME_ROOTS_PATH=${bound:internal-acme-ca:roots}\n" }, @@ -88,10 +88,10 @@ "run-once": true, "network": "host", "env-file": [ - "/var/lib/route-proxy/acme.env" + "${dir:state}/acme.env" ], "volumes": [ - "/var/lib/route-proxy/ca:/ca" + "${dir:ca-dir}:/ca" ], "args": [ "sh", @@ -110,10 +110,10 @@ "run-once": true, "network": "host", "env-file": [ - "/var/lib/route-proxy/internal-acme.env" + "${dir:state}/internal-acme.env" ], "volumes": [ - "/var/lib/route-proxy/ca:/ca" + "${dir:ca-dir}:/ca" ], "args": [ "sh", @@ -131,13 +131,13 @@ "artifact": "server", "network": "host", "env-file": [ - "/var/lib/route-proxy/acme.env", - "/var/lib/route-proxy/internal-acme.env" + "${dir:state}/acme.env", + "${dir:state}/internal-acme.env" ], "volumes": [ - "/var/lib/route-proxy/routes:/routes:ro", - "/var/lib/route-proxy/acme:/acme", - "/var/lib/route-proxy/ca:/ca:ro" + "${dir:routes-dir}:/routes:ro", + "${dir:acme-cache}:/acme", + "${dir:ca-dir}:/ca:ro" ], "env": { "ROUTES": "/routes/mesh.json", diff --git a/modules/showcase/module.json b/modules/showcase/module.json index 7936d5d..427eb69 100644 --- a/modules/showcase/module.json +++ b/modules/showcase/module.json @@ -20,10 +20,10 @@ "postgres-database" ], "binds": { - "postgres-database": "/var/lib/showcase/database.json" + "postgres-database": "${dir:state}/database.json" }, "secrets": { - "postgres-database": "/var/lib/showcase/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "own-secrets": { "broker": "/var/lib/mesh/showcase/broker" @@ -100,13 +100,13 @@ { "id": "state", "type": "directory", - "path": "/var/lib/showcase", - "mode": "0755" + "mode": "0755", + "place": "." }, { "id": "settings", "type": "file", - "path": "/var/lib/showcase/showcase.env", + "path": "${dir:state}/showcase.env", "mode": "0600", "content": "SHOWCASE_GREETING=hello\nSHOWCASE_EVERY_SECONDS=30\nSHOWCASE_STATE=/var/lib/showcase\nSHOWCASE_DATABASE=${bound:postgres-database:at}\nSHOWCASE_LISTEN=${port:8080}\n" }, @@ -137,7 +137,7 @@ ], "run-once": true, "env-file": [ - "/var/lib/showcase/showcase.env" + "${dir:state}/showcase.env" ] }, { @@ -151,7 +151,7 @@ ], "user": "showcase", "env-file": [ - "/var/lib/showcase/showcase.env" + "${dir:state}/showcase.env" ], "restart-on": [ "settings" @@ -168,7 +168,7 @@ ], "schedule": "0 3 * * *", "env-file": [ - "/var/lib/showcase/showcase.env" + "${dir:state}/showcase.env" ] }, { diff --git a/modules/step-ca/module.json b/modules/step-ca/module.json index 74d694e..0572640 100644 --- a/modules/step-ca/module.json +++ b/modules/step-ca/module.json @@ -46,9 +46,9 @@ { "id": "home", "type": "directory", - "path": "/var/lib/step-ca", "mode": "0700", - "owner": "1000:1000" + "owner": "1000:1000", + "place": "." }, { "id": "config", @@ -80,7 +80,7 @@ "DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false" }, "volumes": [ - "/var/lib/step-ca:/home/step", + "${dir:home}:/home/step", "/var/lib/mesh/step-ca:/run/mesh:ro" ], "secrets-in-environment": "the entrypoint honours DOCKER_STEPCA_INIT_PASSWORD_FILE; convertible, awaiting a bed that proves it" diff --git a/modules/umami/module.json b/modules/umami/module.json index 35c37c3..630d781 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -19,14 +19,14 @@ } }, "binds": { - "postgres-database": "/var/lib/umami/database.json", - "route": "/var/lib/umami/route.json" + "postgres-database": "${dir:state}/database.json", + "route": "${dir:state}/route.json" }, "secrets": { - "postgres-database": "/var/lib/umami/database.secret", + "postgres-database": "${dir:state}/database.secret", "secret": { - "app-secret": "/var/lib/umami/app.secret", - "admin": "/var/lib/umami/admin.secret" + "app-secret": "${dir:state}/app.secret", + "admin": "${dir:state}/admin.secret" } }, "provides": [ @@ -39,10 +39,10 @@ "analytics": {} }, "receives": { - "analytics": "/var/lib/umami/grants/mesh.json" + "analytics": "${dir:grants}/mesh.json" }, "grants": { - "analytics": "/var/lib/umami/grants" + "analytics": "${dir:grants}" }, "own-secrets": { "broker": "/var/lib/mesh/umami/broker" @@ -53,7 +53,7 @@ "port": 3000, "protocol": "tcp", "from": "mesh", - "why": "one port serves two surfaces \u2014 the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path" + "why": "one port serves two surfaces — the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path" } ], "resources": [ @@ -66,28 +66,27 @@ { "id": "state", "type": "directory", - "path": "/var/lib/umami", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "grants", "type": "directory", - "path": "/var/lib/umami/grants", "mode": "0700" }, { "id": "server-env", "type": "file", - "path": "/var/lib/umami/server.env", + "path": "${dir:state}/server.env", "mode": "0600", "content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n" }, { "id": "provisioner-env", "type": "file", - "path": "/var/lib/umami/provisioner.env", + "path": "${dir:state}/provisioner.env", "mode": "0600", - "content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=/var/lib/umami/grants\n" + "content": "MESH_PROVISION_UMAMI_URL=http://umami:3000\nGRANTS=${dir:grants}\n" }, { "id": "net", @@ -101,7 +100,7 @@ "image": "ghcr.io/umami-software/umami@sha256:85909afc45bdcda1917394594a087421fdbb05610fded0fa9f6fb861abb2f367", "network": "umami", "env-file": [ - "/var/lib/umami/server.env" + "${dir:state}/server.env" ], "ports": [ "3000" @@ -115,16 +114,16 @@ "network": "umami", "volumes": [ "/var/lib/mesh/umami/broker:/run/secrets/broker:ro", - "/var/lib/umami/grants:/var/lib/umami/grants", - "/var/lib/umami/admin.secret:/run/secrets/admin:ro" + "${dir:grants}:${dir:grants}", + "${dir:state}/admin.secret:/run/secrets/admin:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_RECEIVES": "/var/lib/umami/grants/mesh.json", + "MESH_RECEIVES": "${dir:grants}/mesh.json", "MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin" }, "env-file": [ - "/var/lib/umami/provisioner.env" + "${dir:state}/provisioner.env" ], "artifact": "runtime" }