baserow: placed directories, the database password from a file, and the build ace runs #170

Open
mesh-admin wants to merge 1 commits from feat/baserow-for-ace into main
Contributor

The module named /var/lib/baserow and /services/baserow/data, a layout no
definition may carry (ADR 0112). State and data are now placed directories;
bindings and the grant's secret live in the placed state.

The all-in-one image's entrypoint honours DATABASE_PASSWORD_FILE (file_env
in /baserow.sh), so the grant's password is mounted rather than put in an
env-file, and "secrets-in-environment" is gone (ADR 0086). SECRET_KEY is no
longer minted: the image keeps it, and its JWT signing key, in the data
directory (.secret, .jwt_signing_key) and imports them on start, so a moved
data directory carries the keys its sessions and tokens were made with.
DISABLE_EMBEDDED_PSQL makes a missing grant fail loudly instead of starting
an empty embedded database.

BASEROW_PUBLIC_URL was http://localhost. Baserow answers only the host of
that URL - any other Host is looked up as a published builder site and gets
404, /api/_health/ included - so it is now https://${bound:route:name}
(depends on mesh-controller #149).

The runtime's tools could never have worked: its config was "{}", and the
client's Host override was silently dropped by Node's fetch, so calls by
container name would 404 even with credentials. The client now uses
node:http (which sends the Host it is given, with a Content-Length -
Baserow reads a chunked body as empty) and re-authenticates once when a
cached JWT is refused (access tokens last minutes, the runtime weeks). The
password is the accepted admin secret; the email is an assignment
setting merged into the same file, the host is the route's name.

Image pinned to the develop-latest build ace runs today (Baserow 2.3.4,
built 2026-09-18). The old pin (built 2026-09-04) is older than ace's data.

Verified: catalogue tests with MESH_CATALOGUE set; tsc -p tsconfig.json in
the mesh-tools build image. In throwaway containers of the pinned image: a
fresh embedded-PG instance with a user, workspace and 5-row table; stopped,
copied, dumped from the copy (start-only-db); restored with --no-owner
--role into a grant-shaped database on the pgvector image the postgres
module pins (PG17); started with this shape (root 0600 password file,
embedded PSQL disabled, copied data dir without postgres/): health 200,
the user logs in, the 5 rows are there, SECRET_KEY and the JWT key are
imported from the data dir. The patched client lists applications and rows
through the container name with the public Host, and recovers from a
refused token. Test containers and data removed.

Depends on mesh-controller #149 for ${bound:route:name} (BASEROW_PUBLIC_URL and the runtime's Host). Prepared for ace's migration; nothing is assigned. Window plan and assignment draft: ace-plans in the migration repo (baserow).

The module named /var/lib/baserow and /services/baserow/data, a layout no definition may carry (ADR 0112). State and data are now placed directories; bindings and the grant's secret live in the placed state. The all-in-one image's entrypoint honours DATABASE_PASSWORD_FILE (file_env in /baserow.sh), so the grant's password is mounted rather than put in an env-file, and "secrets-in-environment" is gone (ADR 0086). SECRET_KEY is no longer minted: the image keeps it, and its JWT signing key, in the data directory (.secret, .jwt_signing_key) and imports them on start, so a moved data directory carries the keys its sessions and tokens were made with. DISABLE_EMBEDDED_PSQL makes a missing grant fail loudly instead of starting an empty embedded database. BASEROW_PUBLIC_URL was http://localhost. Baserow answers only the host of that URL - any other Host is looked up as a published builder site and gets 404, /api/_health/ included - so it is now https://${bound:route:name} (depends on mesh-controller #149). The runtime's tools could never have worked: its config was "{}", and the client's Host override was silently dropped by Node's fetch, so calls by container name would 404 even with credentials. The client now uses node:http (which sends the Host it is given, with a Content-Length - Baserow reads a chunked body as empty) and re-authenticates once when a cached JWT is refused (access tokens last minutes, the runtime weeks). The password is the accepted `admin` secret; the email is an assignment setting merged into the same file, the host is the route's name. Image pinned to the develop-latest build ace runs today (Baserow 2.3.4, built 2026-09-18). The old pin (built 2026-09-04) is older than ace's data. Verified: catalogue tests with MESH_CATALOGUE set; tsc -p tsconfig.json in the mesh-tools build image. In throwaway containers of the pinned image: a fresh embedded-PG instance with a user, workspace and 5-row table; stopped, copied, dumped from the copy (start-only-db); restored with --no-owner --role into a grant-shaped database on the pgvector image the postgres module pins (PG17); started with this shape (root 0600 password file, embedded PSQL disabled, copied data dir without postgres/): health 200, the user logs in, the 5 rows are there, SECRET_KEY and the JWT key are imported from the data dir. The patched client lists applications and rows through the container name with the public Host, and recovers from a refused token. Test containers and data removed. Depends on mesh-controller #149 for `${bound:route:name}` (BASEROW_PUBLIC_URL and the runtime's Host). Prepared for ace's migration; nothing is assigned. Window plan and assignment draft: ace-plans in the migration repo (baserow).
mesh-admin added 1 commit 2026-09-30 10:25:52 +00:00
The module named /var/lib/baserow and /services/baserow/data, a layout no
definition may carry (ADR 0112). State and data are now placed directories;
bindings and the grant's secret live in the placed state.

The all-in-one image's entrypoint honours DATABASE_PASSWORD_FILE (file_env
in /baserow.sh), so the grant's password is mounted rather than put in an
env-file, and "secrets-in-environment" is gone (ADR 0086). SECRET_KEY is no
longer minted: the image keeps it, and its JWT signing key, in the data
directory (.secret, .jwt_signing_key) and imports them on start, so a moved
data directory carries the keys its sessions and tokens were made with.
DISABLE_EMBEDDED_PSQL makes a missing grant fail loudly instead of starting
an empty embedded database.

BASEROW_PUBLIC_URL was http://localhost. Baserow answers only the host of
that URL - any other Host is looked up as a published builder site and gets
404, /api/_health/ included - so it is now https://${bound:route:name}
(depends on mesh-controller #149).

The runtime's tools could never have worked: its config was "{}", and the
client's Host override was silently dropped by Node's fetch, so calls by
container name would 404 even with credentials. The client now uses
node:http (which sends the Host it is given, with a Content-Length -
Baserow reads a chunked body as empty) and re-authenticates once when a
cached JWT is refused (access tokens last minutes, the runtime weeks). The
password is the accepted `admin` secret; the email is an assignment
setting merged into the same file, the host is the route's name.

Image pinned to the develop-latest build ace runs today (Baserow 2.3.4,
built 2026-09-18). The old pin (built 2026-09-04) is older than ace's data.

Verified: catalogue tests with MESH_CATALOGUE set; tsc -p tsconfig.json in
the mesh-tools build image. In throwaway containers of the pinned image: a
fresh embedded-PG instance with a user, workspace and 5-row table; stopped,
copied, dumped from the copy (start-only-db); restored with --no-owner
--role into a grant-shaped database on the pgvector image the postgres
module pins (PG17); started with this shape (root 0600 password file,
embedded PSQL disabled, copied data dir without postgres/): health 200,
the user logs in, the 5 rows are there, SECRET_KEY and the JWT key are
imported from the data dir. The patched client lists applications and rows
through the container name with the public Host, and recovers from a
refused token. Test containers and data removed.
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/baserow-for-ace:feat/baserow-for-ace
git checkout feat/baserow-for-ace
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#170