The Dynamic Security plugin refuses to start the broker unless dynamic-security.json already holds an admin client, and no reconcile loop seeds it (novox/hq ADR 0052). Add a run-once init container, declared before the server container, that runs mosquitto's own bootstrap entrypoint in the runtime image: it seeds the store offline via mosquitto_ctrl and exits, and the host gates the broker on its completion. The bootstrap hands the seeded file to the broker's user (uid 1883, chown + 0600): the broker must read the seed at startup AND persist to it as clients come and go, but the init container runs as root and would otherwise leave a file the broker can neither read nor rewrite. This is the ownership question ADR 0052 left for the lab to settle. It seeds only when the file is absent, so what the running plugin grows is never clobbered (issue 035). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
13 lines
315 B
JSON
13 lines
315 B
JSON
{
|
|
"compilerOptions": {
|
|
"target": "ES2022",
|
|
"module": "NodeNext",
|
|
"moduleResolution": "NodeNext",
|
|
"strict": true,
|
|
"esModuleInterop": true,
|
|
"skipLibCheck": true,
|
|
"noEmit": true
|
|
},
|
|
"include": ["client.ts", "index.ts", "provisioner/index.ts", "tools/index.ts", "bootstrap/index.ts"]
|
|
}
|