Compare commits

..
Author SHA1 Message Date
jschoubben a32394ec22 mosquitto: its directories are placed, not stated, and it runs the build in use
The module stated /var/lib/mosquitto-module and /services/mosquitto/data —
novox's layout, a path no definition may carry (ADR 0112). State, grants and
data are now placed directories (${dir:state}, ${dir:grants}, ${dir:data}),
the admin secret lives beside the broker account under the mesh's own state,
and the receives/grants maps follow the grants directory. Paths inside the
sidecar are its own view and are unchanged.

Image pinned to the 2.1.2 build ace's predecessor runs (2026-09-17); the old
pin was the same version, built in June.

Found preparing ace, whose broker carries a password-file user (an IoT switch
and home-assistant). Carrying it is a data step, not a manifest one: the
migration repo has scripts/mosquitto-pwdfile-to-dynsec.py, which moves $7$
PBKDF2 entries into the dynsec store hash-for-hash (tested end to end).
2026-09-29 23:05:41 +02:00
2 changed files with 35 additions and 57 deletions
+14 -16
View File
@@ -23,13 +23,13 @@
"mqtt-topic": {}
},
"receives": {
"mqtt-topic": "/var/lib/mosquitto-module/grants/mesh.json"
"mqtt-topic": "${dir:grants}/mesh.json"
},
"grants": {
"mqtt-topic": "/var/lib/mosquitto-module/grants"
"mqtt-topic": "${dir:grants}"
},
"own-secrets": {
"admin": "/var/lib/mosquitto-module/admin.secret",
"admin": "/var/lib/mesh/mosquitto/admin",
"broker": "/var/lib/mesh/mosquitto/broker"
},
"listens": [
@@ -58,26 +58,24 @@
{
"id": "state",
"type": "directory",
"path": "/var/lib/mosquitto-module",
"mode": "0700"
"mode": "0700",
"place": "."
},
{
"id": "grants-dir",
"id": "grants",
"type": "directory",
"path": "/var/lib/mosquitto-module/grants",
"mode": "0700"
},
{
"id": "data",
"type": "directory",
"path": "/services/mosquitto/data",
"mode": "0700",
"owner": "1883:1883"
},
{
"id": "server-conf",
"type": "file",
"path": "/var/lib/mosquitto-module/mosquitto.conf",
"path": "${dir:state}/mosquitto.conf",
"mode": "0600",
"owner": "1883:1883",
"content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n"
@@ -93,8 +91,8 @@
"name": "mosquitto-bootstrap",
"run-once": true,
"volumes": [
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
"${dir:data}:/mosquitto/data",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
],
"env": {
"MESH_PROVISION_MQTT": "mosquitto:1883",
@@ -112,15 +110,15 @@
"id": "server",
"type": "container",
"name": "mosquitto",
"image": "eclipse-mosquitto@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797",
"image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408",
"network": "mosquitto",
"ports": [
"1883",
"8081"
],
"volumes": [
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
"${dir:data}:/mosquitto/data",
"${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
]
},
{
@@ -130,8 +128,8 @@
"network": "mosquitto",
"volumes": [
"/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro",
"/var/lib/mosquitto-module/grants:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
"${dir:grants}:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
+21 -41
View File
@@ -10,35 +10,35 @@
"port": 8443,
"protocol": "tcp",
"from": "mesh",
"why": "the controller web UI and API, over its own self-signed tls; named through the proxy as an https route"
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
},
{
"name": "inform",
"port": 8080,
"protocol": "tcp",
"from": "mesh",
"why": "device inform, how APs and switches check in and are adopted; the controller tells devices this number, so the machine must publish it on the same one"
"why": "device inform \u2014 how APs and switches check in and are adopted"
},
{
"name": "stun",
"port": 3478,
"protocol": "udp",
"from": "mesh",
"why": "STUN for managed devices; the controller tells devices this number, so the machine must publish it on the same one"
"why": "STUN, so managed devices can find the controller through NAT"
},
{
"name": "discovery",
"port": 10001,
"protocol": "udp",
"from": "mesh",
"why": "device discovery broadcasts from unadopted devices and the UniFi apps"
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
},
{
"name": "discovery-l2",
"port": 1900,
"port": 1902,
"protocol": "udp",
"from": "mesh",
"why": "make-controller-discoverable-on-L2 (SSDP); the software listens on 1900, which machines commonly have taken by another SSDP speaker"
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
},
{
"name": "portal-tls",
@@ -76,15 +76,10 @@
"path": "/var/lib/mesh/unifi",
"mode": "0700"
},
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "data",
"type": "directory",
"path": "/services/unifi/data",
"mode": "0700",
"owner": "1000:1000"
},
@@ -92,17 +87,17 @@
"id": "server",
"type": "container",
"name": "unifi-controller",
"image": "lscr.io/linuxserver/unifi-controller@sha256:0ae315a3a45635e443899e30e86bd507c2c48922cb27f4bc7241777885f4650e",
"image": "lscr.io/linuxserver/unifi-controller@sha256:fcd5d8b13a77a588c79c1b49e5fc9ad08115aa3bb1a3576c589c64908a68845f",
"ports": [
"8443",
"8080",
"3478/udp",
"10001/udp",
"1900/udp",
"8843",
"8880",
"6789",
"5514/udp"
"8443:8443",
"8080:8080",
"3478:3478/udp",
"10001:10001/udp",
"1902:1900/udp",
"8843:8843",
"8880:8880",
"6789:6789",
"5514:5514/udp"
],
"env": {
"PUID": "1000",
@@ -112,7 +107,7 @@
"MEM_STARTUP": "1024"
},
"volumes": [
"${dir:data}:/config"
"/services/unifi/data:/config"
]
},
{
@@ -120,7 +115,7 @@
"type": "file",
"path": "/var/lib/mesh/unifi/config.json",
"mode": "0600",
"content": "{\n \"site\": \"default\",\n \"password\": \"${secret:controller}\"\n}\n",
"content": "{}\n",
"merge": "json"
},
{
@@ -134,7 +129,7 @@
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_UNIFI_URL": "https://127.0.0.1:${port:8443}",
"MESH_UNIFI_URL": "https://127.0.0.1:8443",
"MESH_UNIFI_CONFIG_FILE": "/run/config/config.json"
},
"restart-on": [
@@ -143,23 +138,8 @@
"artifact": "runtime"
}
],
"requires": [
"route"
],
"contributes": {
"route": {
"label": "unifi",
"endpoint": "web",
"scheme": "https",
"insecure": true
}
},
"binds": {
"route": "${dir:state}/route.json"
},
"own-secrets": {
"broker": "/var/lib/mesh/unifi/broker",
"controller": "/var/lib/mesh/unifi/controller"
"broker": "/var/lib/mesh/unifi/broker"
},
"build": {
"on": [