Files
mesh-catalog/modules/mesh-control
jschoubben 2c322cb2fb mesh-control: the control plane could not read its own connections
Its image is FROM scratch and runs as 65534. The host writes a sealed own-secret 0600,
owned by root, which is right — but the module then bind-mounted those three files into
the container and told the process to open them. It cannot:

  $ docker run --rm -v <0600 root file>:/run/secrets/inventory:ro \
      -e MESH_STORE_INVENTORY_FILE=/run/secrets/inventory mesh-control:development status
  MESH_STORE_INVENTORY_FILE names /run/secrets/inventory ... and it cannot be read:
  open /run/secrets/inventory: permission denied

Measured on a workstation, not reasoned about. Every other module in this catalogue gets
away with the same mount because its runtime container runs as root; this one does not,
and genesis (novox/hq ADR 0067) would have stopped at step 9 with a control-plane module
that starts and cannot open a context.

The connections go through the env file this module already has instead. That file is
mode 0600 and is read by the container runtime's client, which is root — the same reason
the broker's URL has always reached the process this way. It also sidesteps the inode
that a file bind mount pins (290be37, step-ca): --env-file is read afresh at create, and
restart-on names it.

The own-secrets stay exactly as they were, because the installer delivers the substrate's
real connection strings into them with `secret accept` before the first push — the mesh
did not make those credentials and cannot invent them.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-11 11:38:28 +02:00
..