mssql: place its directories and name the software's port, not a machine's #160

Merged
mesh-admin merged 1 commits from feat/mssql-for-ace into main 2026-09-30 13:55:28 +00:00
Contributor

Places mssql's directories (state = the assignment's root, grants placed, every reference ${dir:…}) and declares the database endpoint on 1433, the software's port, instead of 4848, one machine's port.

novox is unaffected. Rendered with novox's own setting {"ports":{"1433":4848}} through the controller's Declaration and Rules, every resource (paths, container names, volumes, env-file, 4848:1433, owners, modes) is byte-identical to main. The only change is the firewall rule's comment text; the port stays 4848, open from the mesh. /var/lib/mssql/data stays where it is, and nothing moves.

ace will pin {"endpoints":{"database":{"port":4848,"reach":"internal"}}} so its existing clients keep the number they have.

Image pin unchanged: it is the digest ace runs (2022 CU27, 16.0.4295), the same one novox runs.

Verified: the catalogue tests pass with MESH_CATALOGUE set to this tree. A throwaway run of the pinned image, on a 0700 10001:0 dir with a root-owned 0600 env-file and a dummy SA, answers sqlcmd. A scratch database was stopped, copied with cp -a, checked with sha256 and restarted on the copy, and it kept its rows and CHECKSUM_AGG. That is the copy-first recipe for ace's window.

Not changed, and reported instead: the SA still reaches the process through the env-file (secrets-in-environment). Converting it needs a wrapper entrypoint and an extra mount, and that would change novox's container.

Places mssql's directories (state = the assignment's root, grants placed, every reference `${dir:…}`) and declares the `database` endpoint on 1433, the software's port, instead of 4848, one machine's port. **novox is unaffected.** Rendered with novox's own setting `{"ports":{"1433":4848}}` through the controller's `Declaration` and `Rules`, every resource (paths, container names, volumes, env-file, `4848:1433`, owners, modes) is byte-identical to main. The only change is the firewall rule's comment text; the port stays 4848, open from the mesh. `/var/lib/mssql/data` stays where it is, and nothing moves. **ace** will pin `{"endpoints":{"database":{"port":4848,"reach":"internal"}}}` so its existing clients keep the number they have. Image pin unchanged: it is the digest ace runs (2022 CU27, 16.0.4295), the same one novox runs. Verified: the catalogue tests pass with `MESH_CATALOGUE` set to this tree. A throwaway run of the pinned image, on a 0700 10001:0 dir with a root-owned 0600 env-file and a dummy SA, answers sqlcmd. A scratch database was stopped, copied with `cp -a`, checked with sha256 and restarted on the copy, and it kept its rows and CHECKSUM_AGG. That is the copy-first recipe for ace's window. Not changed, and reported instead: the SA still reaches the process through the env-file (`secrets-in-environment`). Converting it needs a wrapper entrypoint and an extra mount, and that would change novox's container.
mesh-admin added 1 commit 2026-09-30 09:58:02 +00:00
The manifest stated /var/lib/mssql, its grants and its SA file by path, and
declared it listens on 4848 - the port one machine's predecessor published,
which is an assignment's fact (ADR 0112, 0138). ace is moving its own
SQL Server (80 GB of work databases) onto the mesh, so the module has to be
the same on every machine.

- state is the assignment's root (place "."), grants is placed, and every
  reference (sa.env, the env-file, the SA and grants mounts, receives,
  grants, own-secrets) names them as ${dir:...}.
- the database endpoint listens on 1433, the port SQL Server uses; a machine
  that must keep an older number pins it in its assignment.
- the image pin is unchanged: it is the digest ace runs today (CU27,
  16.0.4295), the same as novox.

novox is untouched: rendered with novox's own setting ({"ports":{"1433":4848}})
through the controller's Declaration and Rules, every resource - paths,
container names, volumes, env-file, the 4848:1433 mapping, owners, modes - is
byte-identical to what main renders; the only difference is the firewall
rule's comment text (still port 4848, from the mesh).

Verified: catalogue tests pass with MESH_CATALOGUE on this tree. The pinned
image ran as a throwaway on a 0700 10001:0 data dir with a root-owned 0600
env-file (dummy SA), answered sqlcmd as sa; a scratch database stopped,
copied with cp -a, checksummed and started on the copy kept its rows and
CHECKSUM_AGG.
mesh-admin merged commit 4bf705fea7 into main 2026-09-30 13:55:26 +00:00
mesh-admin deleted branch feat/mssql-for-ace 2026-09-30 13:55:26 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#160