Compare commits

..
Author SHA1 Message Date
jschoubben 1247b8c27e redis: place its directories and run the build in use
The manifest stated /services/redis/data and /var/lib/redis-module - novox's
old layout, paths no definition may carry (ADR 0112). State is now the
assignment's root, grants and data are placed, and the config file, the
secret file, receives and grants all name them as ${dir:...}. Paths inside
the sidecar are its own view and are unchanged.

The data directory and config are owned 999:1000: the image's redis user is
uid 999 in gid 1000 (checked in both builds), which is who owns ace's data
today; 999:999 named a group the image does not use.

Image pinned to the 7.4.11-alpine build ace runs (2026-09-17); the old pin was
the same version, built in August. Older-than-running is never the pin.

Nothing is assigned it anywhere today, so no machine changes.

Verified: catalogue tests pass with MESH_CATALOGUE on this tree; the
declaration composes for ace with every path under /var/lib/redis. The pinned
image ran as a throwaway with a 0600 999:1000 config and a 0700 data dir:
unauthenticated PING is refused (NOAUTH), authenticated SET/GET works,
appendonly is on, the server runs as redis.
2026-09-30 11:57:46 +02:00
2 changed files with 30 additions and 30 deletions
+16 -14
View File
@@ -23,13 +23,13 @@
"mqtt-topic": {}
},
"receives": {
"mqtt-topic": "${dir:grants}/mesh.json"
"mqtt-topic": "/var/lib/mosquitto-module/grants/mesh.json"
},
"grants": {
"mqtt-topic": "${dir:grants}"
"mqtt-topic": "/var/lib/mosquitto-module/grants"
},
"own-secrets": {
"admin": "/var/lib/mesh/mosquitto/admin",
"admin": "/var/lib/mosquitto-module/admin.secret",
"broker": "/var/lib/mesh/mosquitto/broker"
},
"listens": [
@@ -58,24 +58,26 @@
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
"path": "/var/lib/mosquitto-module",
"mode": "0700"
},
{
"id": "grants",
"id": "grants-dir",
"type": "directory",
"path": "/var/lib/mosquitto-module/grants",
"mode": "0700"
},
{
"id": "data",
"type": "directory",
"path": "/services/mosquitto/data",
"mode": "0700",
"owner": "1883:1883"
},
{
"id": "server-conf",
"type": "file",
"path": "${dir:state}/mosquitto.conf",
"path": "/var/lib/mosquitto-module/mosquitto.conf",
"mode": "0600",
"owner": "1883:1883",
"content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n"
@@ -91,8 +93,8 @@
"name": "mosquitto-bootstrap",
"run-once": true,
"volumes": [
"${dir:data}:/mosquitto/data",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_PROVISION_MQTT": "mosquitto:1883",
@@ -110,15 +112,15 @@
"id": "server",
"type": "container",
"name": "mosquitto",
"image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408",
"image": "eclipse-mosquitto@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797",
"network": "mosquitto",
"ports": [
"1883",
"8081"
],
"volumes": [
"${dir:data}:/mosquitto/data",
"${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
]
},
{
@@ -128,8 +130,8 @@
"network": "mosquitto",
"volumes": [
"/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro",
"${dir:grants}:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
"/var/lib/mosquitto-module/grants:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+14 -16
View File
@@ -27,13 +27,13 @@
}
},
"receives": {
"redis-cache": "/var/lib/redis-module/grants/mesh.json"
"redis-cache": "${dir:grants}/mesh.json"
},
"grants": {
"redis-cache": "/var/lib/redis-module/grants"
"redis-cache": "${dir:grants}"
},
"secrets": {
"secret": "/var/lib/redis-module/default.secret"
"secret": "${dir:state}/default.secret"
},
"own-secrets": {
"broker": "/var/lib/mesh/redis/broker"
@@ -57,29 +57,27 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/redis-module",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants-dir",
"id": "grants",
"type": "directory",
"path": "/var/lib/redis-module/grants",
"mode": "0700"
},
{
"id": "data",
"type": "directory",
"path": "/services/redis/data",
"mode": "0700",
"owner": "999:999"
"owner": "999:1000"
},
{
"id": "server-conf",
"type": "file",
"path": "/var/lib/redis-module/redis.conf",
"path": "${dir:state}/redis.conf",
"mode": "0600",
"content": "requirepass ${secret:secret}\nappendonly yes\ndir /data\n",
"owner": "999:999"
"owner": "999:1000"
},
{
"id": "net",
@@ -90,14 +88,14 @@
"id": "server",
"type": "container",
"name": "redis",
"image": "redis@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf",
"image": "redis@sha256:520775a41a63e77e06c73e35d2fd9cc15921a609516818796b4ecbb813078bc7",
"network": "redis",
"ports": [
"6379"
],
"volumes": [
"/services/redis/data:/data",
"/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro"
"${dir:data}:/data",
"${dir:state}/redis.conf:/etc/redis/redis.conf:ro"
],
"args": [
"/etc/redis/redis.conf"
@@ -113,8 +111,8 @@
"network": "redis",
"volumes": [
"/var/lib/mesh/redis/broker:/run/secrets/broker:ro",
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
"${dir:grants}:/var/lib/redis-module/grants:ro",
"${dir:state}/default.secret:/run/secrets/default:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",