Part of the migration-blockers feature (novox/hq ADR 0086 follow-through, issue 041).
Converted to file-delivered secrets and proven in a bed: amqp-ping, minio, mongodb, mesh-catalog, model-usage.
mongodb names its secrets' owner (999:999): the image drops to its own user before it reads the password file.
grafana stays a declared exception until a bed exercises its admin password.
Two dead deliveries removed (amqp-email-forwarder's broker password; mailu's secret env detached from containers that never read it), and every remaining env-file reference names a file that is still declared.
The 25 remaining exceptions carry the surveyed reason on the container.
Part of the migration-blockers feature (novox/hq ADR 0086 follow-through, issue 041).
- Converted to file-delivered secrets and proven in a bed: amqp-ping, minio, mongodb, mesh-catalog, model-usage.
- mongodb names its secrets' owner (`999:999`): the image drops to its own user before it reads the password file.
- grafana stays a declared exception until a bed exercises its admin password.
- Two dead deliveries removed (amqp-email-forwarder's broker password; mailu's secret env detached from containers that never read it), and every remaining env-file reference names a file that is still declared.
- The 25 remaining exceptions carry the surveyed reason on the container.
Merge order: mesh-controller → this → mesh-host → mesh-lab → hq.
From the survey of every env-file secret (ADR 0086, issue 041): amqp-ping,
minio, mongodb and grafana use the _FILE twin their software honours;
mesh-catalog and model-usage read DATABASE_URL_FILE (a file the mesh
templates, mounted where only the runtime reads it); grafana's secret files
belong to its own account. Two dead deliveries removed: a line nothing read
in amqp-email-forwarder, and mailu's secret.env on four containers that
never read it. The 25 exceptions that remain carry the surveyed reason —
convertible and awaiting a bed, convertible through a generated config file,
the application's own code, or not convertible.
The official entrypoint re-executes itself as mongodb (uid 999) and only then reads
MONGO_INITDB_ROOT_PASSWORD_FILE, so a root-owned 0600 file is 'Permission denied' at line 83 and
the server never starts. secrets-owner is the mechanism ADR 0086 gives for exactly this.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of the migration-blockers feature (novox/hq ADR 0086 follow-through, issue 041).
999:999): the image drops to its own user before it reads the password file.Merge order: mesh-controller → this → mesh-host → mesh-lab → hq.