The provisioner derives a consumer's bucket from the login the mesh minted — 'derived from the login, so teardown recomputes it with nothing to persist' — and never reads the bucket a manifest contributed. Three modules contributed one anyway, and the value was decorative in two and wrong in the third: photos told its container MINIO_BUCKET=photos, the predecessor's bucket, while its minted key is scoped to mesh-novox-photos. Deployed as it stood, it would have authenticated and then been denied on every object. photos now names the bucket the mesh actually provisions, and the contributed bucket is gone from all three: a value nothing reads, that reads as though it decides. Verified against the live store before changing anything: the derived names are the populated ones — mesh-novox-ncloud (77,886 objects, 174.9 GiB), mesh-novox-photos and mesh-novox-invoice. Nothing has to move.
148 lines
4.3 KiB
JSON
148 lines
4.3 KiB
JSON
{
|
|
"module": "nextcloud",
|
|
"version": "1",
|
|
"slug": "ncloud",
|
|
"requires": [
|
|
"postgres-database",
|
|
"s3-bucket",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "nextcloud"
|
|
},
|
|
"route": {
|
|
"label": "drive",
|
|
"port": 80
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "/var/lib/nextcloud-module/database.json",
|
|
"s3-bucket": "/var/lib/nextcloud-module/store.json",
|
|
"route": "/var/lib/nextcloud-module/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "/var/lib/nextcloud-module/database.secret",
|
|
"s3-bucket": "/var/lib/nextcloud-module/store.secret"
|
|
},
|
|
"emits": [
|
|
"module.nextcloud.user.created",
|
|
"module.nextcloud.share.created"
|
|
],
|
|
"own-secrets": {
|
|
"admin": "/var/lib/nextcloud-module/admin.secret",
|
|
"broker": "/var/lib/mesh/nextcloud/broker"
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"listens": [
|
|
{
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "files and sync, over http; a public name is a route grant later"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/nextcloud",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/nextcloud-module",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "server-env",
|
|
"type": "file",
|
|
"path": "/var/lib/nextcloud-module/server.env",
|
|
"mode": "0600",
|
|
"content": "POSTGRES_HOST=${bound:postgres-database:at}:${bound:postgres-database:port}\nPOSTGRES_DB=${bound:postgres-database:as}\nPOSTGRES_USER=${bound:postgres-database:as}\nPOSTGRES_PASSWORD=${secret:postgres-database}\nNEXTCLOUD_ADMIN_USER=mesh-admin\nNEXTCLOUD_ADMIN_PASSWORD=${secret:admin}\nOBJECTSTORE_S3_HOST=${bound:s3-bucket:at}\nOBJECTSTORE_S3_PORT=${bound:s3-bucket:port}\nOBJECTSTORE_S3_BUCKET=mesh-novox-ncloud\nOBJECTSTORE_S3_KEY=${bound:s3-bucket:as}\nOBJECTSTORE_S3_SECRET=${secret:s3-bucket}\nOBJECTSTORE_S3_SSL=false\nOBJECTSTORE_S3_USEPATH_STYLE=true\nOBJECTSTORE_S3_REGION=${bound:s3-bucket:region}\n"
|
|
},
|
|
{
|
|
"id": "html",
|
|
"type": "directory",
|
|
"path": "/services/nextcloud/html",
|
|
"mode": "0750",
|
|
"owner": "33:33"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "nextcloud",
|
|
"image": "nextcloud@sha256:fb966733647ea03f0446b0c22eac9733c8eb616d37b960caca9d4c3010e14a08",
|
|
"env-file": [
|
|
"/var/lib/nextcloud-module/server.env"
|
|
],
|
|
"ports": [
|
|
"80"
|
|
],
|
|
"volumes": [
|
|
"/services/nextcloud/html:/var/www/html"
|
|
],
|
|
"secrets-in-environment": "the image honours POSTGRES_PASSWORD_FILE and NEXTCLOUD_ADMIN_PASSWORD_FILE (entrypoint file_env); OBJECTSTORE_S3_SECRET has none and needs a generated config fragment; convertible, awaiting a bed"
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/var/lib/mesh/nextcloud/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-nextcloud",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/nextcloud/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/nextcloud/config.json:/run/config/config.json:ro",
|
|
"/var/lib/nextcloud-module/admin.secret:/run/secrets/admin:ro",
|
|
"/var/run/docker.sock:/var/run/docker.sock"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}",
|
|
"MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin",
|
|
"MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
},
|
|
{
|
|
"arg": "DOCKER_CLI",
|
|
"image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|