From 107090310d20d9dce57eb68d608790e7a4758fed Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 14:42:57 +0200 Subject: [PATCH] nextcloud: point S3 config at the bucket the mesh actually provisioned MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit OBJECTSTORE_S3_BUCKET=nextcloud was a leftover from before the module existed — that bucket was created by hand during tonight's earlier HAL credential stopgap. The mesh's own minio provisioner derives its own bucket name from the consumer's access-key identity (bucketFor(as) in minio/client.ts) rather than honouring contributes.s3-bucket.bucket — by design, so teardown can recompute the name with nothing persisted — and minted mesh-novox-ncloud, a different bucket. mesh_novox_ncloud's scoped policy only covers that bucket, so every S3 write 403'd with AccessDenied trying to touch the old one. Pointed both the request hint and the real env var at the bucket that's actually there. --- modules/nextcloud/module.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index 621edeb..1b86bea 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -12,7 +12,7 @@ "name": "nextcloud" }, "s3-bucket": { - "bucket": "nextcloud" + "bucket": "mesh-novox-ncloud" }, "route": { "label": "drive", @@ -65,7 +65,7 @@ "type": "file", "path": "/var/lib/nextcloud-module/server.env", "mode": "0600", - "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=mesh-admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=nextcloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\nOBJECTSTORE_S3_REGION=${bound:s3-bucket:region}\n" + "content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=mesh-admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=mesh-novox-ncloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\nOBJECTSTORE_S3_REGION=${bound:s3-bucket:region}\n" }, { "id": "html", -- 2.54.0