Three fixes, all learned in the photos cutover hours ago:
authSource is the granted database, and so is the database in the URL: the provisioner creates the user inside mesh_novox_invoice (dbOwner) and ignores the contributed name.
MINIO_BUCKET is the derived bucket (mesh-novox-invoice): the provisioner seals the key to bucketFor(grant account) by design; the objects mirror in during the window and the old invoicing bucket stays as rollback.
The api contributes its route.invoicing-api.novox.be is today a traefik container label — invisible to every survey of dynamic/ — and both names must be grants before the edge can flip.
Image pins verified at parity with the running containers (:latest repo-digests match). ADR-0015 from-source conversion stays future work, tracked in the repo's own note.
Three fixes, all learned in the photos cutover hours ago:
- **`authSource` is the granted database**, and so is the database in the URL: the provisioner creates the user inside `mesh_novox_invoice` (dbOwner) and ignores the contributed name.
- **`MINIO_BUCKET` is the derived bucket** (`mesh-novox-invoice`): the provisioner seals the key to `bucketFor(grant account)` by design; the objects mirror in during the window and the old `invoicing` bucket stays as rollback.
- **The api contributes its route.** `invoicing-api.novox.be` is today a traefik container label — invisible to every survey of `dynamic/` — and both names must be grants before the edge can flip.
Image pins verified at parity with the running containers (`:latest` repo-digests match). ADR-0015 from-source conversion stays future work, tracked in the repo's own note.
The mongo credential authenticates against its own database and the
database is the granted one (mesh_novox_invoice), not the contributed
name the provisioner ignores. Same for the store: the key is sealed to
the derived bucket (mesh-novox-invoice) — the data mirrors in during the
window, the ncloud/photos pattern. And the api gets the route
contribution it always needed: invoicing-api.novox.be is today a traefik
container label, invisible to every file survey, and it must be a grant
before the edge can ever flip.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Three fixes, all learned in the photos cutover hours ago:
authSourceis the granted database, and so is the database in the URL: the provisioner creates the user insidemesh_novox_invoice(dbOwner) and ignores the contributed name.MINIO_BUCKETis the derived bucket (mesh-novox-invoice): the provisioner seals the key tobucketFor(grant account)by design; the objects mirror in during the window and the oldinvoicingbucket stays as rollback.invoicing-api.novox.beis today a traefik container label — invisible to every survey ofdynamic/— and both names must be grants before the edge can flip.Image pins verified at parity with the running containers (
:latestrepo-digests match). ADR-0015 from-source conversion stays future work, tracked in the repo's own note.