A definition names no host path for its own data

Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
2026-09-30 21:10:18 +02:00
parent 12bbcafacf
commit eed5e8958a
28 changed files with 210 additions and 223 deletions
+6 -7
View File
@@ -9,10 +9,10 @@
"model-access"
],
"binds": {
"model-access": "/var/lib/anthropic-consumer/model.json"
"model-access": "${dir:state}/model.json"
},
"secrets": {
"model-access": "/var/lib/anthropic-consumer/access-token"
"model-access": "${dir:state}/access-token"
},
"own-secrets": {
"broker": "/var/lib/mesh/anthropic-consumer/broker"
@@ -30,8 +30,8 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/anthropic-consumer",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "claude-home",
@@ -42,7 +42,6 @@
{
"id": "out",
"type": "directory",
"path": "/var/lib/anthropic-consumer/out",
"mode": "0700"
},
{
@@ -56,7 +55,7 @@
"/app/modules/anthropic-consumer/dist/apply/index.js"
],
"volumes": [
"/var/lib/anthropic-consumer:/run/state"
"${dir:state}:/run/state"
],
"env": {
"MESH_MODEL_ACCESS_SECRET_FILE": "/run/state/access-token",
@@ -78,7 +77,7 @@
],
"volumes": [
"/var/lib/mesh/anthropic-consumer/broker:/run/secrets/broker:ro",
"/var/lib/anthropic-consumer:/run/state"
"${dir:state}:/run/state"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",