influxdb: place its directories, hand secrets over as files, name its UI #152
Open
mesh-admin
wants to merge 2 commits from
feat/influxdb-for-ace into main
pull from: feat/influxdb-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/postgres-is-not-named-after-the-seat
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/jackett-for-ace
:feat/oidc-client-provision
:feat/mosquitto-placed
:feat/nodered-for-ace
:feat/influxdb-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/n8n-for-ace
:feat/letta-for-ace
:feat/baserow-for-ace
:feat/supabase-for-ace
:feat/nzbget-for-ace
:feat/matrix-for-ace
:feat/bazarr-for-ace
:feat/redis-for-ace
:feat/mssql-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/grafana-for-ace
:feat/unifi-for-ace
:feat/icecast-for-ace
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The manifest named /services/influxdb and /var/lib/influxdb-module — one
machine's paths — and passed the admin password and token through the
environment. ace is moving its 2022 instance onto the mesh, so the module
has to be what it is on any machine.
the image's influxdb user, which is who owns ace's data today.
DOCKER_INFLUXDB_INIT_{PASSWORD,ADMIN_TOKEN}_FILE; the vault's files are
mounted read-only. secrets-in-environment is gone.
added to client.ts) and reaches the server at its assigned machine port
(${port:8086}) instead of assuming 8086. The unused config-dir mount,
which held the CLI's copy of the admin token, is dropped.
and reach is the assignment's to say.
Verified: catalogue tests pass with MESH_CATALOGUE pointed at this tree.
The pinned 2.9.1 image, run on a scratch copy of ace's 2.4.0 data, opens
it, runs its metadata migrations (backing up the pre-upgrade bolt/sqlite)
and hashes the two stored tokens; /health passes. A fresh setup through
the _FILE variables, with dummy secrets as root-owned 0600 files, accepts
the token (200 on /api/v2/buckets) and the password (204 on /signin).
client.ts typechecks strict and reads the token file, tolerating the
endpoints key in its config.
The manifest named /services/influxdb and /var/lib/influxdb-module — one machine's paths — and passed the admin password and token through the environment. ace is moving its 2022 instance onto the mesh, so the module has to be what it is on any machine. - data, config and state are placed directories; the data keeps 1000:1000, the image's influxdb user, which is who owns ace's data today. - the init secrets reach the image through its own DOCKER_INFLUXDB_INIT_{PASSWORD,ADMIN_TOKEN}_FILE; the vault's files are mounted read-only. secrets-in-environment is gone. - the sidecar reads its token from the same file (MESH_INFLUXDB_TOKEN_FILE, added to client.ts) and reaches the server at its assigned machine port (${port:8086}) instead of assuming 8086. The unused config-dir mount, which held the CLI's copy of the admin token, is dropped. - the api endpoint contributes a route: the web UI is how people use it, and reach is the assignment's to say. Verified: catalogue tests pass with MESH_CATALOGUE pointed at this tree. The pinned 2.9.1 image, run on a scratch copy of ace's 2.4.0 data, opens it, runs its metadata migrations (backing up the pre-upgrade bolt/sqlite) and hashes the two stored tokens; /health passes. A fresh setup through the _FILE variables, with dummy secrets as root-owned 0600 files, accepts the token (200 on /api/v2/buckets) and the password (204 on /signin). client.ts typechecks strict and reads the token file, tolerating the endpoints key in its config.New on this branch (
323ef9e): influxdb providesinfluxdb-apiinfluxdb-api(scope mesh). It servesschemehttp,port(8086, which the mesh redirects to the machine port),organdbucket.organdbucketdefault tomesh/defaultand are set by the assignment's settings, which reach both the served facts and the provisioner's config.json. On ace that isorg: zurag, bucket: zurag.provisioner/index.ts,grants.ts) creates a v1-compatibility authorization. Its username is the consumer's identity (mesh_<node>_<module>) and its password is the pair credential the mesh minted. A v2 API token can't be used: InfluxDB 2.9.1 ignores atokensent toPOST /api/v2/authorizations(tested: the chosen token got 401), so a token could only be accepted by hand for each pair. A v1 authorization takes a password the caller chooses (8–72 characters; the mesh mints 40) and reads and writes every bucket as a database of the same name through/query(InfluxQL) and/write. No DBRP mapping is needed because InfluxDB maps each bucket virtually. Nosecret acceptis needed for any consumer.access(read, the default, orwriteorread-write) andbuckets. A reader that names no buckets may read every bucket in the org. A writer has to name its buckets, and system buckets are refused. If a named bucket is missing it is created with infinite retention, and it is never deleted.mesh_*whose description starts with[mesh]are updated or removed. One with the same name that isn't marked is refused and left exactly as it is. No other token, user or bucket is touched.holdsonly reads, andensurewrites only what differs: the password is tried first and set only if it fails.mesh-influxdbsidecar (MESH_TOOL_MODULES). It reads its grants from the placed directory${dir:grants}throughMESH_RECEIVES.Tests
npm testpattern (compiled in the mesh-tools build image, node 22): typecheck and build pass, and 11/11 tests intest/grants.test.tspass against a fake InfluxDB that mirrors 2.9.1's status codes.MESH_CATALOGUE=<#152+#155 merged> go test ./internal/catalogue/passes, including the real-catalogue parse (73 manifests).atace.internal,port8086,org/bucketzurag andasmesh_ace_grafana. The provider getsgrants/ace.grafana.secretand amesh.jsonwith{access: read}. Every${bound:…}and${dir:…}fills.mesh_ace_grafanawith read access to every bucket, and grafana's own data source health check returned "datasource is working".mesh_ace_nodered, write onzurag) wrote line protocol with a 204 and got a 404 on_monitoring. When it was withdrawn, its authorization was removed and the bucket stayed.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.