A definition names no host path for its own data
Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
@@ -21,11 +21,11 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"postgres-database": "/var/lib/keycloak/database.json",
|
||||
"route": "/var/lib/keycloak/route.json"
|
||||
"postgres-database": "${dir:state}/database.json",
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "/var/lib/keycloak/database.secret"
|
||||
"postgres-database": "${dir:state}/database.secret"
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
@@ -55,13 +55,13 @@
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"oidc-client": "/var/lib/keycloak/grants/mesh.json"
|
||||
"oidc-client": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"oidc-client": "/var/lib/keycloak/grants"
|
||||
"oidc-client": "${dir:grants}"
|
||||
},
|
||||
"own-secrets": {
|
||||
"admin": "/var/lib/keycloak/admin.secret",
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"broker": "/var/lib/mesh/keycloak/broker"
|
||||
},
|
||||
"resources": [
|
||||
@@ -74,26 +74,25 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/keycloak",
|
||||
"mode": "0700"
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/keycloak/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "admin-env",
|
||||
"type": "file",
|
||||
"path": "/var/lib/keycloak/admin.env",
|
||||
"path": "${dir:state}/admin.env",
|
||||
"mode": "0600",
|
||||
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"
|
||||
},
|
||||
{
|
||||
"id": "database-env",
|
||||
"type": "file",
|
||||
"path": "/var/lib/keycloak/database.env",
|
||||
"path": "${dir:state}/database.env",
|
||||
"mode": "0600",
|
||||
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"
|
||||
},
|
||||
@@ -105,7 +104,7 @@
|
||||
{
|
||||
"id": "hostname",
|
||||
"type": "file",
|
||||
"path": "/var/lib/keycloak/hostname.env",
|
||||
"path": "${dir:state}/hostname.env",
|
||||
"mode": "0644",
|
||||
"content": "KC_HOSTNAME=https://${bound:route:name}\n"
|
||||
},
|
||||
@@ -125,9 +124,9 @@
|
||||
"KC_PROXY_HEADERS": "xforwarded"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/keycloak/admin.env",
|
||||
"/var/lib/keycloak/database.env",
|
||||
"/var/lib/keycloak/hostname.env"
|
||||
"${dir:state}/admin.env",
|
||||
"${dir:state}/database.env",
|
||||
"${dir:state}/hostname.env"
|
||||
],
|
||||
"ports": [
|
||||
"8080"
|
||||
@@ -153,15 +152,15 @@
|
||||
"volumes": [
|
||||
"/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro",
|
||||
"/var/lib/keycloak/admin.secret:/run/secrets/admin:ro",
|
||||
"/var/lib/keycloak/grants:/var/lib/keycloak/grants:ro"
|
||||
"${dir:state}/admin.secret:/run/secrets/admin:ro",
|
||||
"${dir:grants}:${dir:grants}:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
||||
"MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin",
|
||||
"MESH_RECEIVES": "/var/lib/keycloak/grants/mesh.json"
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"restart-on": [
|
||||
"runtime-config"
|
||||
|
||||
Reference in New Issue
Block a user