From d301e057948f46897882f56694b363024dea76dc Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 6 Sep 2026 13:47:16 +0200 Subject: [PATCH] fix: postgres consumers connect to the db the mesh named (the login), not a hardcoded app name The postgres provisioner creates each consumer a database named after the login the mesh minted (mesh__), per ADR 0048 -- 'a same-named database under exactly that login'. But baserow, letta, umami, gitea, keycloak and nextcloud each hardcoded their app db name (DATABASE_NAME=baserow, /letta, /umami, NAME=gitea, /keycloak, POSTGRES_DB=nextcloud), so the service connected to a database that does not exist ('database letta does not exist'). Each now uses ${bound:postgres-database:as} as the db name -- the login, which is also the db name -- matching the working meshboard pattern and the provisioner's actual behaviour. Found by the two-node DB-consumer lab install (mesh-lab assigned-two-node-db); baserow is proven connecting and running there. The S3 bucket name is the same class of assumption and is a separate follow-up (s3 identity has its own length bound). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/baserow/module.json | 2 +- modules/gitea/module.json | 2 +- modules/keycloak/module.json | 2 +- modules/letta/module.json | 2 +- modules/nextcloud/module.json | 2 +- modules/umami/module.json | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/modules/baserow/module.json b/modules/baserow/module.json index 6ff5b54..06538df 100644 --- a/modules/baserow/module.json +++ b/modules/baserow/module.json @@ -58,7 +58,7 @@ "type": "file", "path": "/var/lib/baserow/server.env", "mode": "0600", - "content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=baserow\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nREDIS_HOST=${bound:redis-cache:at}\nREDIS_PORT=${bound:redis-cache:port}\nREDIS_PROTOCOL=redis\nREDIS_PASSWORD=${secret:redis-cache}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n" + "content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nREDIS_HOST=${bound:redis-cache:at}\nREDIS_PORT=${bound:redis-cache:port}\nREDIS_PROTOCOL=redis\nREDIS_PASSWORD=${secret:redis-cache}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n" }, { "id": "net", diff --git a/modules/gitea/module.json b/modules/gitea/module.json index f539bd9..e1c8563 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -59,7 +59,7 @@ "type": "file", "path": "/var/lib/gitea/server.env", "mode": "0600", - "content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=gitea\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n" + "content": "GITEA__security__INTERNAL_TOKEN=${secret:internal-token}\nGITEA__database__DB_TYPE=postgres\nGITEA__database__HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nGITEA__database__NAME=${bound:postgres-database:as}\nGITEA__database__USER=${bound:postgres-database:as}\nGITEA__database__PASSWD=${secret:postgres-database}\n" }, { "id": "data", diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 4d4c4b0..5796049 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -63,7 +63,7 @@ "type": "file", "path": "/var/lib/keycloak/database.env", "mode": "0600", - "content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/keycloak\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n" + "content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n" }, { "id": "net", diff --git a/modules/letta/module.json b/modules/letta/module.json index 6dd5afa..5774538 100644 --- a/modules/letta/module.json +++ b/modules/letta/module.json @@ -48,7 +48,7 @@ "type": "file", "path": "/var/lib/letta/server.env", "mode": "0600", - "content": "LETTA_PG_URI=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/letta\nLETTA_SERVER_PASSWORD=${secret:server-password}\nSECURE=true\nTZ=Europe/Brussels\n" + "content": "LETTA_PG_URI=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nLETTA_SERVER_PASSWORD=${secret:server-password}\nSECURE=true\nTZ=Europe/Brussels\n" }, { "id": "net", diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index 1544b10..3502446 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -58,7 +58,7 @@ "type": "file", "path": "/var/lib/nextcloud-module/server.env", "mode": "0600", - "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=nextcloud\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=nextcloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\n" + "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=nextcloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\n" }, { "id": "html", diff --git a/modules/umami/module.json b/modules/umami/module.json index 022da13..e18e025 100644 --- a/modules/umami/module.json +++ b/modules/umami/module.json @@ -70,7 +70,7 @@ "type": "file", "path": "/var/lib/umami/server.env", "mode": "0600", - "content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/umami\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n" + "content": "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nDATABASE_TYPE=postgresql\nAPP_SECRET=${secret:app-secret}\n" }, { "id": "provisioner-env", -- 2.54.0