The provisioner derives a consumer's bucket from the login the mesh minted — 'derived from the login, so teardown recomputes it with nothing to persist' — and never reads the bucket a manifest contributed. Three modules contributed one anyway, and the value was decorative in two and wrong in the third: photos told its container MINIO_BUCKET=photos, the predecessor's bucket, while its minted key is scoped to mesh-novox-photos. Deployed as it stood, it would have authenticated and then been denied on every object. photos now names the bucket the mesh actually provisions, and the contributed bucket is gone from all three: a value nothing reads, that reads as though it decides. Verified against the live store before changing anything: the derived names are the populated ones — mesh-novox-ncloud (77,886 objects, 174.9 GiB), mesh-novox-photos and mesh-novox-invoice. Nothing has to move.
89 lines
2.6 KiB
JSON
89 lines
2.6 KiB
JSON
{
|
|
"module": "photos",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"requires": [
|
|
"s3-bucket",
|
|
"mongodb-database",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"mongodb-database": {
|
|
"name": "photos"
|
|
},
|
|
"route": {
|
|
"label": "photos",
|
|
"port": 4001
|
|
}
|
|
},
|
|
"binds": {
|
|
"s3-bucket": "/var/lib/photos/store.json",
|
|
"mongodb-database": "/var/lib/photos/database.json",
|
|
"route": "/var/lib/photos/route.json"
|
|
},
|
|
"secrets": {
|
|
"s3-bucket": "/var/lib/photos/store.secret",
|
|
"mongodb-database": "/var/lib/photos/database.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 9000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the photos backend API; the client sites on the module network call it"
|
|
},
|
|
{
|
|
"port": 4001,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the admin client site over http; the public name photos.novox.be is a route grant, and route-proxy reaches it on this published port"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/photos",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/photos/server.env",
|
|
"mode": "0600",
|
|
"content": "NODE_ENV=production\nPORT=9000\nMONGO_URL=mongodb://${bound:mongodb-database:as}:${secret:mongodb-database}@${bound:mongodb-database:at}:${bound:mongodb-database:port}/${bound:mongodb-database:as}?authSource=admin\nMONGO_DB=${bound:mongodb-database:as}\nMINIO_ENDPOINT=${bound:s3-bucket:at}\nMINIO_PORT=${bound:s3-bucket:port}\nMINIO_BUCKET=mesh-novox-photos\nMINIO_ACCESSKEY=${bound:s3-bucket:as}\nMINIO_SECRET=${secret:s3-bucket}\nMINIO_USE_SSL=false\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "photos"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "photos-server",
|
|
"image": "registry-api.novox.be/novox/photos-server@sha256:3f165acbbd1fd731b12fe798c95879c081a44b00e2c569ef7f47165f6a527201",
|
|
"network": "photos",
|
|
"env-file": [
|
|
"/var/lib/photos/server.env"
|
|
],
|
|
"ports": [
|
|
"9000"
|
|
],
|
|
"secrets-in-environment": "the application's own code reads MONGO_URL and MINIO_SECRET from the environment (photos server/src/config.js); converting is that repository's change"
|
|
},
|
|
{
|
|
"id": "admin-client",
|
|
"type": "container",
|
|
"name": "photos-admin-client",
|
|
"image": "registry-api.novox.be/novox/photos-admin-client@sha256:f437fa9ed28b29a012f715fb8d9b809a15cff4a672794c620d5d400f57695580",
|
|
"network": "photos",
|
|
"ports": [
|
|
"80"
|
|
]
|
|
}
|
|
]
|
|
}
|