A definition names no host path for its own data

Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
2026-09-30 21:10:18 +02:00
parent 12bbcafacf
commit eed5e8958a
28 changed files with 210 additions and 223 deletions
+5 -6
View File
@@ -6,7 +6,7 @@
"**"
],
"own-secrets": {
"broker": "/var/lib/audit-logger/broker"
"broker": "${dir:state}/broker"
},
"build": {
"on": [
@@ -33,13 +33,12 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/audit-logger",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "trail",
"type": "directory",
"path": "/var/lib/audit-logger/trail",
"mode": "0700"
},
{
@@ -48,8 +47,8 @@
"name": "mesh-audit-logger",
"network": "host",
"volumes": [
"/var/lib/audit-logger/broker:/run/secrets/broker:ro",
"/var/lib/audit-logger/trail:/trail"
"${dir:state}/broker:/run/secrets/broker:ro",
"${dir:trail}:/trail"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",