hq ADR 0107 / issue 115. HAL's own postgres and lavinmq both used a directory bind (./db-data, ./data) for exactly this data -- the mesh's adoption of them, three weeks ago, switched to a named Docker volume instead, and searxng/distribution followed the same pattern since. A named volume survives ordinary container recreation, same as a directory bind -- that was never the problem. The problem is everything else: docker rm -fv, docker volume rm, and docker system prune --volumes all target it (one flag away from the docker rm -f this migration already uses routinely); it is invisible to every tool this migration has used all night (ls, find, grep across /var/lib, /services); and nothing outside Docker's own volume machinery can back it up or notice it growing. mesh-store carries the sharpest version: every database migrated tonight, including keycloak's, live inside it. Data already copied and verified on novox before this merges: - mesh-registry-data -> /var/lib/mesh-registry (11G, diff -rq clean) - mesh-broker-data -> /var/lib/mesh-broker (37M, cp -a) - mesh-broker-tls -> /var/lib/mesh-broker-tls (12K, cp -a) - mesh-store-data -> /var/lib/mesh-store (1.7G) -- mesh-store stopped cleanly first, so the final copy is crash-consistent, not a live-file copy of a running postgres; diff -rq clean after. - searxng/valkey: not yet assigned anywhere, manifest-only fix, nothing to copy. Old named volumes left in place, not deleted, as the rollback path.
65 lines
1.2 KiB
JSON
65 lines
1.2 KiB
JSON
{
|
|
"module": "distribution",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "artifact-store",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "the-artifact-store",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.registry.image.pushed"
|
|
],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/registry/broker"
|
|
},
|
|
"serves": {
|
|
"artifact-store": {
|
|
"port": 5000
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 5000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "every machine pulls images and artifacts from here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/registry",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "registry-data",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh-registry",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "store",
|
|
"type": "container",
|
|
"name": "mesh-registry",
|
|
"image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373",
|
|
"ports": [
|
|
"5000:5000"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/mesh-registry:/var/lib/registry"
|
|
]
|
|
}
|
|
]
|
|
}
|