The module named /var/lib/baserow and /services/baserow/data, a layout no definition may carry (ADR 0112). State and data are now placed directories; bindings and the grant's secret live in the placed state. The all-in-one image's entrypoint honours DATABASE_PASSWORD_FILE (file_env in /baserow.sh), so the grant's password is mounted rather than put in an env-file, and "secrets-in-environment" is gone (ADR 0086). SECRET_KEY is no longer minted: the image keeps it, and its JWT signing key, in the data directory (.secret, .jwt_signing_key) and imports them on start, so a moved data directory carries the keys its sessions and tokens were made with. DISABLE_EMBEDDED_PSQL makes a missing grant fail loudly instead of starting an empty embedded database. BASEROW_PUBLIC_URL was http://localhost. Baserow answers only the host of that URL - any other Host is looked up as a published builder site and gets 404, /api/_health/ included - so it is now https://${bound:route:name} (depends on mesh-controller #149). The runtime's tools could never have worked: its config was "{}", and the client's Host override was silently dropped by Node's fetch, so calls by container name would 404 even with credentials. The client now uses node:http (which sends the Host it is given, with a Content-Length - Baserow reads a chunked body as empty) and re-authenticates once when a cached JWT is refused (access tokens last minutes, the runtime weeks). The password is the accepted `admin` secret; the email is an assignment setting merged into the same file, the host is the route's name. Image pinned to the develop-latest build ace runs today (Baserow 2.3.4, built 2026-09-18). The old pin (built 2026-09-04) is older than ace's data. Verified: catalogue tests with MESH_CATALOGUE set; tsc -p tsconfig.json in the mesh-tools build image. In throwaway containers of the pinned image: a fresh embedded-PG instance with a user, workspace and 5-row table; stopped, copied, dumped from the copy (start-only-db); restored with --no-owner --role into a grant-shaped database on the pgvector image the postgres module pins (PG17); started with this shape (root 0600 password file, embedded PSQL disabled, copied data dir without postgres/): health 200, the user logs in, the 5 rows are there, SECRET_KEY and the JWT key are imported from the data dir. The patched client lists applications and rows through the container name with the public Host, and recovers from a refused token. Test containers and data removed.
138 lines
3.3 KiB
JSON
138 lines
3.3 KiB
JSON
{
|
|
"module": "baserow",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"postgres-database",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "baserow"
|
|
},
|
|
"route": {
|
|
"label": "baserow",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:state}/database.json",
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:state}/database.secret"
|
|
},
|
|
"own-secrets": {
|
|
"admin": "${dir:state}/admin.secret",
|
|
"broker": "/var/lib/mesh/baserow/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/baserow",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"mode": "0755",
|
|
"owner": "9999:9999"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/server.env",
|
|
"mode": "0600",
|
|
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "baserow"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "baserow",
|
|
"image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080",
|
|
"network": "baserow",
|
|
"env-file": [
|
|
"${dir:state}/server.env"
|
|
],
|
|
"ports": [
|
|
"80"
|
|
],
|
|
"volumes": [
|
|
"${dir:data}:/baserow/data",
|
|
"${dir:state}/database.secret:/run/secrets/database:ro"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/baserow/config.json",
|
|
"mode": "0600",
|
|
"content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-baserow",
|
|
"network": "baserow",
|
|
"volumes": [
|
|
"/var/lib/mesh/baserow/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/baserow/config.json:/run/config/config.json:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_BASEROW_URL": "http://baserow:80",
|
|
"MESH_BASEROW_CONFIG_FILE": "/run/config/config.json"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|