A definition names no host path for its own data
Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
@@ -21,10 +21,10 @@
|
||||
"mesh-vault.secret.deprovisioned"
|
||||
],
|
||||
"receives": {
|
||||
"secret": "/var/lib/mesh-vault/grants/mesh.json"
|
||||
"secret": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"secret": "/var/lib/mesh-vault/grants"
|
||||
"secret": "${dir:grants}"
|
||||
},
|
||||
"keeps": "/var/lib/mesh-vault/root",
|
||||
"own-secrets": {
|
||||
@@ -40,25 +40,22 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh-vault",
|
||||
"mode": "0700"
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh-vault/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "ledger",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh-vault/ledger",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "root",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/mesh-vault/root",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
@@ -68,15 +65,15 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/mesh-vault/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh-vault/grants:/var/lib/mesh-vault/grants:ro",
|
||||
"/var/lib/mesh-vault/ledger:/var/lib/mesh-vault/ledger",
|
||||
"/var/lib/mesh-vault/root:/var/lib/mesh-vault/root:ro"
|
||||
"${dir:grants}:${dir:grants}:ro",
|
||||
"${dir:ledger}:${dir:ledger}",
|
||||
"${dir:root}:${dir:root}:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "/var/lib/mesh-vault/grants/mesh.json",
|
||||
"MESH_VAULT_LEDGER": "/var/lib/mesh-vault/ledger",
|
||||
"MESH_VAULT_ROOT": "/var/lib/mesh-vault/root"
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
||||
"MESH_VAULT_LEDGER": "${dir:ledger}",
|
||||
"MESH_VAULT_ROOT": "${dir:root}"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user