Group 8: minio declares the bucket it derives (hq ADR 0201), and the store collects nightly (hq ADR 0189) #229

Merged
mesh-admin merged 3 commits from feat/the-store-keeps-what-the-records-name into main 2026-10-04 01:47:49 +00:00
Contributor

Merge LAST of everything in group 8 — after mesh-host #77, mesh-controller #227 and mesh-sdk #10.

Rebased onto today's main. Both of group 8's changes are here; #228 is closed in favour of this.

ADR 0201 (was 0188 — the bundles refactor took that number). minio's serves.s3-bucket gains "bucket": "${consumer:as:dns}"; nextcloud, invoicing and photos ask for ${bound:s3-bucket:bucket} instead of writing mesh-novox-* literals that also named this installation's node; bucketFor and the long-dead accessKeyFor are gone. minio moves to the sdk at ^0.1.7, which is where #10 lands it.

No bucket changes name. The derived value equals what bucketFor computed for the same login — verified against the live store's bucket list.

ADR 0189. REGISTRY_STORAGE_DELETE_ENABLED on the server, and a collect step at 03:30 running the registry's own collector over the volume with the server held still by while-stopped: ["store"]. Plain garbage-collect, not --delete-untagged: what the mesh keeps is still a manifest and so still referenced, and the dangerous flag would delete images machines are running.

Why it must be last: merged before mesh-controller #227, ${consumer:as:dns} reaches three consumers' configuration as a literal; merged before mesh-host #77, a host that does not know while-stopped refuses the store's whole declaration and takes the store down with it.

tsc --noEmit clean for minio, and the controller's catalogue-wide manifest test passes against this branch.

**Merge LAST of everything in group 8** — after mesh-host #77, mesh-controller #227 and mesh-sdk #10. Rebased onto today's main. Both of group 8's changes are here; #228 is closed in favour of this. **ADR 0201 (was 0188 — the bundles refactor took that number).** `minio`'s `serves.s3-bucket` gains `"bucket": "${consumer:as:dns}"`; `nextcloud`, `invoicing` and `photos` ask for `${bound:s3-bucket:bucket}` instead of writing `mesh-novox-*` literals that also named this installation's node; `bucketFor` and the long-dead `accessKeyFor` are gone. minio moves to the sdk at `^0.1.7`, which is where #10 lands it. **No bucket changes name.** The derived value equals what `bucketFor` computed for the same login — verified against the live store's bucket list. **ADR 0189.** `REGISTRY_STORAGE_DELETE_ENABLED` on the server, and a `collect` step at 03:30 running the registry's own collector over the volume with the server held still by `while-stopped: ["store"]`. Plain `garbage-collect`, not `--delete-untagged`: what the mesh keeps is still a manifest and so still referenced, and the dangerous flag would delete images machines are running. **Why it must be last:** merged before mesh-controller #227, `${consumer:as:dns}` reaches three consumers' configuration as a literal; merged before mesh-host #77, a host that does not know `while-stopped` refuses the store's whole declaration and takes the store down with it. `tsc --noEmit` clean for minio, and the controller's catalogue-wide manifest test passes against this branch.
jschoubben added 3 commits 2026-10-04 00:45:52 +00:00
serves.s3-bucket.bucket is ${consumer:as:dns}; the provisioner uses what it
is given. nextcloud, invoicing and photos ask for ${bound:s3-bucket:bucket}
instead of naming mesh-novox-* literals, which also named this node.
bucketFor and the long-dead accessKeyFor are gone.
REGISTRY_STORAGE_DELETE_ENABLED on the server — the door already accepts a
push — and a scheduled step running the registry's own collector over the
volume at 03:30 with the server held still. Plain garbage-collect: what the
mesh keeps is still a manifest, so --delete-untagged is not needed and would
delete images machines are running.
The bundles refactor took ADR 0188 on main, so minio's comments cite 0201.
The sdk is 0.1.7 after the same rebase, and minio needs the `derived` field
it carries.
jschoubben force-pushed feat/the-store-keeps-what-the-records-name from 80be455830 to 159ed53103 2026-10-04 00:45:52 +00:00 Compare
mesh-admin changed title from The store enables deletion and collects nightly (hq ADR 0189, issue 108) to Group 8: minio declares the bucket it derives (hq ADR 0201), and the store collects nightly (hq ADR 0189) 2026-10-04 00:47:39 +00:00
Author
Contributor

HELD — do not merge yet. hq #305 is merged (ADRs 0201 and 0189 are on main). This stays last.

Order once the 213/223 cutover has rolled: mesh-host #77 → mesh-controller #227 → mesh-sdk #10 → this. Merged before the controller, ${consumer:as:dns} reaches three consumers' configuration as a literal; merged before the host, a host that does not know while-stopped refuses the store's whole declaration and takes the store down with it.

Two things worth knowing before this one rolls:

  • The three consumers' env files are byte-identical after substitution. ${bound:s3-bucket:bucket} renders to mesh-novox-ncloud, mesh-novox-invoice, mesh-novox-photos — the names already in the live store, confirmed against its bucket list. So nextcloud, invoicing and photos are not recreated by this and no data moves. The change is in who says the name, not what it is.
  • The registry container is recreated, because REGISTRY_STORAGE_DELETE_ENABLED is a new env key and that moves its spec. A brief store outage on the apply that lands it. Everything that pulls retries.

After it rolls, ADR 0189's live check is the one thing still outstanding: watch the first 03:30 collection and read the store's size on the control node before and after.

**HELD — do not merge yet.** hq #305 is merged (ADRs 0201 and 0189 are on main). This stays **last**. Order once the 213/223 cutover has rolled: mesh-host #77 → mesh-controller #227 → mesh-sdk #10 → **this**. Merged before the controller, `${consumer:as:dns}` reaches three consumers' configuration as a literal; merged before the host, a host that does not know `while-stopped` refuses the store's whole declaration and takes the store down with it. **Two things worth knowing before this one rolls:** - **The three consumers' env files are byte-identical after substitution.** `${bound:s3-bucket:bucket}` renders to `mesh-novox-ncloud`, `mesh-novox-invoice`, `mesh-novox-photos` — the names already in the live store, confirmed against its bucket list. So nextcloud, invoicing and photos are not recreated by this and no data moves. The change is in who says the name, not what it is. - **The registry container *is* recreated**, because `REGISTRY_STORAGE_DELETE_ENABLED` is a new `env` key and that moves its spec. A brief store outage on the apply that lands it. Everything that pulls retries. After it rolls, ADR 0189's live check is the one thing still outstanding: watch the first 03:30 collection and read the store's size on the control node before and after.
mesh-admin merged commit c0159ca0a1 into main 2026-10-04 01:47:49 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#229