invoicing: the photos lessons, applied before its window #86

Merged
jschoubben merged 1 commits from fix/invoicing-learns-the-photos-lessons into main 2026-09-26 01:15:38 +00:00
Owner

Three fixes, all learned in the photos cutover hours ago:

  • authSource is the granted database, and so is the database in the URL: the provisioner creates the user inside mesh_novox_invoice (dbOwner) and ignores the contributed name.
  • MINIO_BUCKET is the derived bucket (mesh-novox-invoice): the provisioner seals the key to bucketFor(grant account) by design; the objects mirror in during the window and the old invoicing bucket stays as rollback.
  • The api contributes its route. invoicing-api.novox.be is today a traefik container label — invisible to every survey of dynamic/ — and both names must be grants before the edge can flip.

Image pins verified at parity with the running containers (:latest repo-digests match). ADR-0015 from-source conversion stays future work, tracked in the repo's own note.

Three fixes, all learned in the photos cutover hours ago: - **`authSource` is the granted database**, and so is the database in the URL: the provisioner creates the user inside `mesh_novox_invoice` (dbOwner) and ignores the contributed name. - **`MINIO_BUCKET` is the derived bucket** (`mesh-novox-invoice`): the provisioner seals the key to `bucketFor(grant account)` by design; the objects mirror in during the window and the old `invoicing` bucket stays as rollback. - **The api contributes its route.** `invoicing-api.novox.be` is today a traefik container label — invisible to every survey of `dynamic/` — and both names must be grants before the edge can flip. Image pins verified at parity with the running containers (`:latest` repo-digests match). ADR-0015 from-source conversion stays future work, tracked in the repo's own note.
jschoubben added 1 commit 2026-09-26 01:15:34 +00:00
The mongo credential authenticates against its own database and the
database is the granted one (mesh_novox_invoice), not the contributed
name the provisioner ignores. Same for the store: the key is sealed to
the derived bucket (mesh-novox-invoice) — the data mirrors in during the
window, the ncloud/photos pattern. And the api gets the route
contribution it always needed: invoicing-api.novox.be is today a traefik
container label, invisible to every file survey, and it must be a grant
before the edge can ever flip.
jschoubben merged commit 511200ed9c into main 2026-09-26 01:15:38 +00:00
jschoubben deleted branch fix/invoicing-learns-the-photos-lessons 2026-09-26 01:15:39 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#86