From 61eb201f8af38f45f60a9bac2134b6c4f666045c Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 16:39:11 +0200 Subject: [PATCH 1/3] postgres: declare the data directory's real owner; keycloak: use the port template postgres: mesh-store's data directory has always had split ownership -- everything inside pgdata/ is owned by UID 999 (the pgvector image's real runtime user), while only the top-level mount point happened to be 70:70. Invisible while the directory's mode was 1777 (world-accessible, from the named volume this replaced); broke the moment mode: 0700 was enforced, locking out the actual owning process. mesh-store crash-looped on Permission denied twice before this was found -- once at container creation, once mid-session on a checkpoint, after ownership looked correct by every check that didn't look inside pgdata/ specifically. keycloak: MESH_KEYCLOAK_URL was hardcoded to :8080, but the module's own port override (settings set keycloak {ports:{8080:28080}} on novox) means the real published port is 28080. Same bug class as the postgres connection-string fix earlier tonight -- now using the mesh's own template instead, which is exactly the mechanism internal/catalogue/port_into.go describes for a sidecar dialling its own server over the machine's loopback. --- modules/keycloak/module.json | 2 +- modules/postgres/module.json | 3 ++- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 919be3c..04e6341 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -118,7 +118,7 @@ ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_KEYCLOAK_URL": "http://127.0.0.1:8080", + "MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}", "MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json" }, "restart-on": [ diff --git a/modules/postgres/module.json b/modules/postgres/module.json index 3855f20..b543e5f 100644 --- a/modules/postgres/module.json +++ b/modules/postgres/module.json @@ -73,7 +73,8 @@ "id": "store-data", "type": "directory", "path": "/var/lib/mesh-store", - "mode": "0700" + "mode": "0700", + "owner": "999:70" }, { "id": "server", From 13d036164001a5ed148a4a5ca34ac169f2aa6a85 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:25:16 +0200 Subject: [PATCH 2/3] keycloak: carry over HAL's hostname/proxy settings, dropped during conversion Reported: files.novox.be's login button redirects to http://keycloak.novox.be, not https. HAL's original config (/services/keycloak/docker-compose.yml) set three settings the mesh's manifest never carried over: KC_HOSTNAME: keycloak.novox.be KC_HOSTNAME_STRICT_HTTPS: true KC_PROXY: edge Without KC_PROXY: edge, Keycloak has no way to know it sits behind a TLS-terminating reverse proxy (traefik) -- it generates URLs from what it directly sees, which is plain HTTP from traefik's backend connection. Same pattern as the named-volume conversion: the shape was rebuilt from general knowledge of what a keycloak container needs, not from what this installation's own working config actually had. --- modules/keycloak/module.json | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 04e6341..d65681a 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -88,7 +88,10 @@ "env": { "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", - "KC_HEALTH_ENABLED": "true" + "KC_HEALTH_ENABLED": "true", + "KC_HOSTNAME": "keycloak.novox.be", + "KC_HOSTNAME_STRICT_HTTPS": "true", + "KC_PROXY": "edge" }, "env-file": [ "/var/lib/keycloak/admin.env", From ed0f4602a68f1378b0cbe06239e14ae6d491f6e7 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:27:04 +0200 Subject: [PATCH 3/3] keycloak: use Hostname v2's actual config shape, not v1's deprecated flags The previous commit on this branch used KC_PROXY=edge and KC_HOSTNAME_STRICT_HTTPS=true, carried over from HAL's config -- but HAL ran an older Keycloak using the v1 hostname provider. This image (26.0.8) defaults to Hostname v2, which warned 'options [proxy, hostname-strict-https] are still in use, please review your configuration' and kept generating http:// URLs regardless -- verified against /realms/Novox/.well-known/openid-configuration directly, not just the login button, after the first fix deployed. v2's actual shape (keycloak.org/server/hostname): KC_HOSTNAME is a full URL, not a bare hostname -- the scheme in the URL is what tells Keycloak to generate https, not a separate strict-https flag. KC_PROXY_HEADERS replaces KC_PROXY: xforwarded to trust traefik's X-Forwarded-* headers, which it sends by default. --- modules/keycloak/module.json | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index d65681a..44e0d44 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -89,9 +89,8 @@ "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true", - "KC_HOSTNAME": "keycloak.novox.be", - "KC_HOSTNAME_STRICT_HTTPS": "true", - "KC_PROXY": "edge" + "KC_HOSTNAME": "https://keycloak.novox.be", + "KC_PROXY_HEADERS": "xforwarded" }, "env-file": [ "/var/lib/keycloak/admin.env",