A definition names no host path for its own data
Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
@@ -42,13 +42,13 @@
|
||||
}
|
||||
},
|
||||
"receives": {
|
||||
"postgres-database": "/var/lib/postgres/grants/mesh.json"
|
||||
"postgres-database": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"grants": {
|
||||
"postgres-database": "/var/lib/postgres/grants"
|
||||
"postgres-database": "${dir:grants}"
|
||||
},
|
||||
"own-secrets": {
|
||||
"superuser": "/var/lib/postgres/superuser.secret",
|
||||
"superuser": "${dir:state}/superuser.secret",
|
||||
"broker": "/var/lib/mesh/postgres/broker"
|
||||
},
|
||||
"resources": [
|
||||
@@ -61,13 +61,12 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/postgres",
|
||||
"mode": "0700"
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "grants",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/postgres/grants",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
@@ -91,7 +90,7 @@
|
||||
],
|
||||
"volumes": [
|
||||
"/var/lib/mesh-store:/var/lib/postgresql/data",
|
||||
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
|
||||
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -101,15 +100,15 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/postgres/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/postgres/grants:/var/lib/postgres/grants:ro",
|
||||
"/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"
|
||||
"${dir:grants}:${dir:grants}:ro",
|
||||
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
|
||||
"MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}",
|
||||
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "/var/lib/postgres/grants/mesh.json"
|
||||
"MESH_RECEIVES": "${dir:grants}/mesh.json"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user