Five modules keep their own secrets from the vault, under local names; route-proxy declares its bases

gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs
under a local name (novox/hq ADR 0094); the broker account stays their own. The
route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
This commit is contained in:
2026-09-21 22:16:10 +02:00
parent 126969a829
commit facd41806d
7 changed files with 58 additions and 21 deletions
+7 -4
View File
@@ -3,7 +3,8 @@
"version": "1", "version": "1",
"requires": [ "requires": [
"postgres-database", "postgres-database",
"route" "route",
"secret"
], ],
"contributes": { "contributes": {
"postgres-database": { "postgres-database": {
@@ -19,7 +20,11 @@
"route": "/var/lib/gitea/route.json" "route": "/var/lib/gitea/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "/var/lib/gitea/database.secret" "postgres-database": "/var/lib/gitea/database.secret",
"secret": {
"internal-token": "/var/lib/gitea/internal-token.secret",
"admin": "/var/lib/gitea/admin.secret"
}
}, },
"capabilities": [ "capabilities": [
"container-runtime" "container-runtime"
@@ -57,8 +62,6 @@
"package-registry": "/var/lib/gitea/grants" "package-registry": "/var/lib/gitea/grants"
}, },
"own-secrets": { "own-secrets": {
"internal-token": "/var/lib/gitea/internal-token.secret",
"admin": "/var/lib/gitea/admin.secret",
"broker": "/var/lib/mesh/gitea/broker" "broker": "/var/lib/mesh/gitea/broker"
}, },
"resources": [ "resources": [
+10 -3
View File
@@ -9,9 +9,6 @@
"module.icecast.stream.stopped" "module.icecast.stream.stopped"
], ],
"own-secrets": { "own-secrets": {
"source": "/var/lib/icecast-module/source.secret",
"admin": "/var/lib/icecast-module/admin.secret",
"relay": "/var/lib/icecast-module/relay.secret",
"broker": "/var/lib/mesh/icecast/broker" "broker": "/var/lib/mesh/icecast/broker"
}, },
"listens": [ "listens": [
@@ -103,5 +100,15 @@
"from": "Dockerfile" "from": "Dockerfile"
} }
] ]
},
"requires": [
"secret"
],
"secrets": {
"secret": {
"source": "/var/lib/icecast-module/source.secret",
"admin": "/var/lib/icecast-module/admin.secret",
"relay": "/var/lib/icecast-module/relay.secret"
}
} }
} }
+9 -2
View File
@@ -5,8 +5,6 @@
"container-runtime" "container-runtime"
], ],
"own-secrets": { "own-secrets": {
"admin": "/var/lib/influxdb-module/admin.secret",
"admin-token": "/var/lib/influxdb-module/admin-token.secret",
"broker": "/var/lib/mesh/influxdb/broker" "broker": "/var/lib/mesh/influxdb/broker"
}, },
"listens": [ "listens": [
@@ -118,5 +116,14 @@
"from": "Dockerfile" "from": "Dockerfile"
} }
] ]
},
"requires": [
"secret"
],
"secrets": {
"secret": {
"admin": "/var/lib/influxdb-module/admin.secret",
"admin-token": "/var/lib/influxdb-module/admin-token.secret"
}
} }
} }
+8 -5
View File
@@ -6,7 +6,8 @@
], ],
"requires": [ "requires": [
"postgres-database", "postgres-database",
"route" "route",
"secret"
], ],
"contributes": { "contributes": {
"postgres-database": { "postgres-database": {
@@ -22,7 +23,12 @@
"route": "/var/lib/mailu/route.json" "route": "/var/lib/mailu/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "/var/lib/mailu/database.secret" "postgres-database": "/var/lib/mailu/database.secret",
"secret": {
"secret-key": "/var/lib/mailu/secret-key.secret",
"admin": "/var/lib/mailu/admin.secret",
"api-token": "/var/lib/mailu/api-token.secret"
}
}, },
"emits": [ "emits": [
"module.mailu.user.created", "module.mailu.user.created",
@@ -67,9 +73,6 @@
} }
], ],
"own-secrets": { "own-secrets": {
"secret-key": "/var/lib/mailu/secret-key.secret",
"admin": "/var/lib/mailu/admin.secret",
"api-token": "/var/lib/mailu/api-token.secret",
"broker": "/var/lib/mesh/mailu/broker" "broker": "/var/lib/mesh/mailu/broker"
}, },
"resources": [ "resources": [
+4 -2
View File
@@ -1,3 +1,5 @@
ARG ALPINE_BASE=alpine:3.20
ARG GO_BASE=golang:1.25
# The route-proxy module's runtime image: the reference reverse proxy compiled into a container. # The route-proxy module's runtime image: the reference reverse proxy compiled into a container.
# #
# **The proxy source is not vendored here.** The canonical proxy — the contract written as something # **The proxy source is not vendored here.** The canonical proxy — the contract written as something
@@ -10,7 +12,7 @@
# #
# The mesh pins the digest of what this produces; the committed module.json carries the placeholder # The mesh pins the digest of what this produces; the committed module.json carries the placeholder
# digest every mesh-built image does, replaced at publish. # digest every mesh-built image does, replaced at publish.
FROM golang:1.25 AS build FROM ${GO_BASE} AS build
WORKDIR /src WORKDIR /src
COPY go.mod go.sum ./ COPY go.mod go.sum ./
RUN go mod download RUN go mod download
@@ -19,7 +21,7 @@ RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-route-proxy ./examples/
# A small runtime with the public CA roots the ACME client needs to reach a real authority, and run # A small runtime with the public CA roots the ACME client needs to reach a real authority, and run
# as root so it can bind :80 and :443 — the two privileged ports a public front door listens on. # as root so it can bind :80 and :443 — the two privileged ports a public front door listens on.
FROM alpine:3.20 FROM ${ALPINE_BASE}
RUN apk add --no-cache ca-certificates RUN apk add --no-cache ca-certificates
COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy
ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"] ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"]
+13 -1
View File
@@ -98,5 +98,17 @@
"ACME_CA_BUNDLE": "/ca/root.crt" "ACME_CA_BUNDLE": "/ca/root.crt"
} }
} }
] ],
"build": {
"on": [
{
"arg": "GO_BASE",
"image": "golang@sha256:699337d620559a59b4a2bb298ad59611e535d2ee755a34cf2d2a98f37578dc80"
},
{
"arg": "ALPINE_BASE",
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
}
]
}
} }
+7 -4
View File
@@ -6,7 +6,8 @@
], ],
"requires": [ "requires": [
"postgres-database", "postgres-database",
"route" "route",
"secret"
], ],
"contributes": { "contributes": {
"postgres-database": { "postgres-database": {
@@ -22,7 +23,11 @@
"route": "/var/lib/umami/route.json" "route": "/var/lib/umami/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "/var/lib/umami/database.secret" "postgres-database": "/var/lib/umami/database.secret",
"secret": {
"app-secret": "/var/lib/umami/app.secret",
"admin": "/var/lib/umami/admin.secret"
}
}, },
"provides": [ "provides": [
{ {
@@ -40,8 +45,6 @@
"analytics": "/var/lib/umami/grants" "analytics": "/var/lib/umami/grants"
}, },
"own-secrets": { "own-secrets": {
"app-secret": "/var/lib/umami/app.secret",
"admin": "/var/lib/umami/admin.secret",
"broker": "/var/lib/mesh/umami/broker" "broker": "/var/lib/mesh/umami/broker"
}, },
"listens": [ "listens": [