A definition names no host path for its own data
Twenty-eight modules' data directories are placed: the root as place ".", a sub-directory named by
its id, and every host-side reference — binds, secrets, own secrets, grants, receives, file paths,
mounts, env-files — as ${dir:<id>}. Resolved on the default root every path is the one the manifest
named before, which the controller's TestPlacedDirectoriesKeepTheirPaths proves over both checkouts;
so no data moves and no machine sees a change. Five directories whose id is not their last segment
keep their path as a placement (novox/hq issue 119, ADR 0112, design 27).
This commit is contained in:
@@ -46,9 +46,9 @@
|
||||
{
|
||||
"id": "home",
|
||||
"type": "directory",
|
||||
"path": "/var/lib/step-ca",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
"owner": "1000:1000",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
@@ -80,7 +80,7 @@
|
||||
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false"
|
||||
},
|
||||
"volumes": [
|
||||
"/var/lib/step-ca:/home/step",
|
||||
"${dir:home}:/home/step",
|
||||
"/var/lib/mesh/step-ca:/run/mesh:ro"
|
||||
],
|
||||
"secrets-in-environment": "the entrypoint honours DOCKER_STEPCA_INIT_PASSWORD_FILE; convertible, awaiting a bed that proves it"
|
||||
|
||||
Reference in New Issue
Block a user