The provisioner derives a consumer's bucket from the login the mesh minted — 'derived from the login, so teardown recomputes it with nothing to persist' — and never reads the bucket a manifest contributed. Three modules contributed one anyway, and the value was decorative in two and wrong in the third: photos told its container MINIO_BUCKET=photos, the predecessor's bucket, while its minted key is scoped to mesh-novox-photos. Deployed as it stood, it would have authenticated and then been denied on every object. photos now names the bucket the mesh actually provisions, and the contributed bucket is gone from all three: a value nothing reads, that reads as though it decides. Verified against the live store before changing anything: the derived names are the populated ones — mesh-novox-ncloud (77,886 objects, 174.9 GiB), mesh-novox-photos and mesh-novox-invoice. Nothing has to move.
110 lines
2.9 KiB
JSON
110 lines
2.9 KiB
JSON
{
|
|
"module": "invoicing",
|
|
"version": "1",
|
|
"slug": "invoice",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"mongodb-database",
|
|
"s3-bucket",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"mongodb-database": {
|
|
"name": "invoicing"
|
|
},
|
|
"route": {
|
|
"site": {
|
|
"label": "invoicing",
|
|
"port": 80
|
|
},
|
|
"api": {
|
|
"label": "invoicing-api",
|
|
"port": 9000
|
|
}
|
|
}
|
|
},
|
|
"binds": {
|
|
"mongodb-database": "/var/lib/invoicing/database.json",
|
|
"s3-bucket": "/var/lib/invoicing/store.json",
|
|
"route": "/var/lib/invoicing/route.json"
|
|
},
|
|
"secrets": {
|
|
"mongodb-database": "/var/lib/invoicing/database.secret",
|
|
"s3-bucket": "/var/lib/invoicing/store.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the invoicing web frontend; a public name is a route grant later"
|
|
},
|
|
{
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the invoicing REST API the frontend and integrations call"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/invoicing",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/invoicing",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "api-env",
|
|
"type": "file",
|
|
"path": "/var/lib/invoicing/api.env",
|
|
"mode": "0600",
|
|
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=${bound:mongodb-database:as}\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_BUCKET=mesh-novox-invoice\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "invoicing"
|
|
},
|
|
{
|
|
"id": "app",
|
|
"type": "container",
|
|
"name": "invoicing-app",
|
|
"image": "registry-api.novox.be/novox/invoicing-app@sha256:1e6ed40822f07169b24867cbfe8fc1ab3ef6a15ad642f3b3a2882a8e15c3dbec",
|
|
"network": "invoicing",
|
|
"env": {
|
|
"UID": "2201",
|
|
"GID": "2201"
|
|
},
|
|
"ports": [
|
|
"80"
|
|
]
|
|
},
|
|
{
|
|
"id": "api",
|
|
"type": "container",
|
|
"name": "invoicing-api",
|
|
"image": "registry-api.novox.be/novox/invoicing-api@sha256:efa6fba1fa9ba78849e94e958d33793a76654df0468e3012da9c02c54c265354",
|
|
"network": "invoicing",
|
|
"env": {
|
|
"UID": "2201",
|
|
"GID": "2201"
|
|
},
|
|
"env-file": [
|
|
"/var/lib/invoicing/api.env"
|
|
],
|
|
"ports": [
|
|
"9000"
|
|
],
|
|
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (invoicing-app server/src/config.js); converting is that repository's change"
|
|
}
|
|
]
|
|
}
|