mesh-minio's s3-bucket provisioner shells out to mc to create buckets and service accounts on the live server, but mc was never in this module's own runtime image, only in minio's own. It's been silently retrying 'spawn mc ENOENT' forever, so every s3-bucket grant reached the control-plane layer (store.json, sealed secret) without the credential ever actually existing on minio — nextcloud's live instance just hit this as InvalidAccessKeyId on a real user session. Copies mc from minio's own image (docker.io/pgsty/minio, already pinned and pulled as this module's server container) rather than introducing a new base — mc there is a working, already-verified binary. /usr/bin/mc is a symlink to mcli; both are copied so it resolves.
151 lines
3.2 KiB
JSON
151 lines
3.2 KiB
JSON
{
|
|
"module": "minio",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "s3-bucket",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.minio.bucket.created",
|
|
"module.minio.bucket.removed"
|
|
],
|
|
"listens": [
|
|
{
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the S3 endpoint"
|
|
}
|
|
],
|
|
"serves": {
|
|
"s3-bucket": {
|
|
"scheme": "http",
|
|
"region": "us-east-1",
|
|
"port": 9000
|
|
}
|
|
},
|
|
"receives": {
|
|
"s3-bucket": "/var/lib/minio/grants/mesh.json"
|
|
},
|
|
"grants": {
|
|
"s3-bucket": "/var/lib/minio/grants"
|
|
},
|
|
"own-secrets": {
|
|
"root": "/var/lib/minio/root.secret",
|
|
"broker": "/var/lib/mesh/minio/broker"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/minio",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/minio",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"path": "/var/lib/minio/grants",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "root-env",
|
|
"type": "file",
|
|
"path": "/var/lib/minio/root.env",
|
|
"mode": "0600",
|
|
"content": "MINIO_ROOT_USER=meshroot\n"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/var/lib/minio-store",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "minio"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "minio",
|
|
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372",
|
|
"network": "minio",
|
|
"args": [
|
|
"server",
|
|
"/data",
|
|
"--console-address",
|
|
":9001"
|
|
],
|
|
"env-file": [
|
|
"/var/lib/minio/root.env"
|
|
],
|
|
"ports": [
|
|
"9000"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/minio-store:/data",
|
|
"/var/lib/minio/root.secret:/run/secrets/root:ro"
|
|
],
|
|
"env": {
|
|
"MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root"
|
|
}
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-minio",
|
|
"network": "minio",
|
|
"volumes": [
|
|
"/var/lib/mesh/minio/broker:/run/secrets/broker:ro",
|
|
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
|
|
"/var/lib/minio/root.secret:/run/secrets/root:ro"
|
|
],
|
|
"env": {
|
|
"MESH_MINIO_ENDPOINT": "http://minio:9000",
|
|
"MESH_MINIO_ROOT_USER": "meshroot",
|
|
"MESH_MINIO_ROOT_PASSWORD_FILE": "/run/secrets/root",
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_RECEIVES": "/var/lib/minio/grants/mesh.json"
|
|
},
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
},
|
|
{
|
|
"arg": "MC_CLI",
|
|
"image": "docker.io/pgsty/minio@sha256:b6bfe7239bfc83fb90d31612d9704d86039dd714f7904b3f1ad68f211e602372"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|