The cache keeps no ACL file, and the watch keeps the cache

The lab's diagnostics said it in one line: AUTH called without any
password configured for the default user. With an aclfile configured,
redis takes the default user from the file and quietly ignores
requirepass — so the empty seed this module shipped left the store
without any password at all, politely refusing the credential the mesh
had sealed for it.

And the file could never have worked here anyway: it was host-declared
content, which the host reconciles, so every re-apply would have wiped
what ACL SAVE wrote — a fight between two reconcilers with the tenants
as the ball.

So no file. requirepass alone does what it says, and durability moves
to the watch, which now checks the store and not only its inputs: a
restarted store comes back empty and is re-granted within a tick,
because reconciling is against reality, not against a diff of
instructions. A run that failed leaves last empty, so the next tick
retries instead of believing the inputs were handled.
This commit is contained in:
2026-09-02 01:23:38 +02:00
parent 1b63e21c0f
commit 1c4e10e0d8
2 changed files with 57 additions and 17 deletions
+1 -9
View File
@@ -55,15 +55,7 @@
"type": "file",
"path": "/var/lib/redis-module/redis.conf",
"mode": "0600",
"content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n",
"owner": "999:999"
},
{
"id": "acl-seed",
"type": "file",
"path": "/services/redis/data/users.acl",
"mode": "0600",
"content": "",
"content": "requirepass ${secret:default}\nappendonly yes\ndir /data\n",
"owner": "999:999"
},
{