Declare the broker's TLS directory as an access, not an undeclared bind

The swap from a named volume to the host directory left the mount undeclared, which main's own
manifest check now refuses: a bind the module did not declare is created by the runtime as root, so
the module's owner and mode never reach it and ADR 0030's data rule does not cover it.

The directory is the broker's — lavinmq declares it as its own, mode 0700 — so from here it is an
access, read-only: a pre-existing path this module is granted use of and does not own.
This commit is contained in:
jochen
2026-09-26 14:55:04 +02:00
parent cc86f8b433
commit 71c8080359
+6
View File
@@ -11,6 +11,12 @@
"scope": "mesh"
}
],
"accesses": [
{
"path": "/var/lib/mesh-broker-tls",
"mode": "read"
}
],
"own-secrets": {
"inventory": "/var/lib/mesh/mesh-controller/inventory",
"identity": "/var/lib/mesh/mesh-controller/identity",