A definition names no host path for its own data

Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
2026-09-30 21:10:18 +02:00
parent 12bbcafacf
commit eed5e8958a
28 changed files with 210 additions and 223 deletions
+9 -10
View File
@@ -12,13 +12,13 @@
"public-dns": {}
},
"grants": {
"public-dns": "/var/lib/cloudflare-dns/grants"
"public-dns": "${dir:grants}"
},
"receives": {
"public-dns": "/var/lib/cloudflare-dns/grants/mesh.json"
"public-dns": "${dir:grants}/mesh.json"
},
"own-secrets": {
"token": "/var/lib/cloudflare-dns/token",
"token": "${dir:state}/token",
"broker": "/var/lib/mesh/cloudflare-dns/broker"
},
"emits": [
@@ -35,19 +35,18 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/cloudflare-dns",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants",
"type": "directory",
"path": "/var/lib/cloudflare-dns/grants",
"mode": "0700"
},
{
"id": "config",
"type": "file",
"path": "/var/lib/cloudflare-dns/config.json",
"path": "${dir:state}/config.json",
"merge": "json",
"content": "{}",
"mode": "0600"
@@ -58,9 +57,9 @@
"name": "mesh-cloudflare-dns",
"network": "host",
"volumes": [
"/var/lib/cloudflare-dns/config.json:/run/config/config.json:ro",
"/var/lib/cloudflare-dns/grants:/grants",
"/var/lib/cloudflare-dns/token:/run/secrets/token:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:grants}:/grants",
"${dir:state}/token:/run/secrets/token:ro",
"/var/lib/mesh/cloudflare-dns/broker:/run/secrets/broker:ro"
],
"env": {