The example modules put their credentials where the programs read them
Every one of these declared `own-secrets` pointing at a path called
`.env` and then mounted it as `env-file`. The file's whole content is
the password. Docker reads that as a malformed line and the container
starts with no password set — which is not a failure to start, it is a
service running with the wrong credential.
They parsed, they resolved, and none of them could ever have worked.
That is what a manifest checked only by the parser buys.
Each now keeps the sealed file as what it is — a password, alone — and
declares a file beside it whose content says ${secret:name}. The host
fills the hole on the machine, which is the only place both halves
exist. The provisioners mount the bare file, because they read a
password file and always did.
Two tests, both driven from the manifests on disk rather than from
fixtures: every ${secret:x} must name something the module declared, and
nothing may read a bare password file as an env file. Injecting the
shipped bug reproduces it word for word.
Keycloak, Gitea and Mailu still cannot connect to their databases, for
the reason in 04-ISSUES/023 — the user name is the provisioner's
invention and the bound values cannot reach a config file. Their own
credentials are right now; that half was independent and is done.
This commit is contained in:
@@ -16,12 +16,15 @@
|
||||
"receives": {"s3-bucket": "/var/lib/minio/grants/mesh.json"},
|
||||
"grants": {"s3-bucket": "/var/lib/minio/grants"},
|
||||
|
||||
"own-secrets": {"root": "/var/lib/minio/root.env"},
|
||||
"own-secrets": {"root": "/var/lib/minio/root.secret"},
|
||||
|
||||
"resources": [
|
||||
{"id": "state", "type": "directory", "path": "/var/lib/minio", "mode": "0700"},
|
||||
{"id": "grants", "type": "directory", "path": "/var/lib/minio/grants", "mode": "0700"},
|
||||
|
||||
{"id": "root-env", "type": "file", "path": "/var/lib/minio/root.env", "mode": "0600",
|
||||
"content": "MINIO_ROOT_USER=meshroot\nMINIO_ROOT_PASSWORD=${secret:root}\n"},
|
||||
|
||||
{"id": "net", "type": "network", "name": "minio"},
|
||||
|
||||
{"id": "server", "type": "container", "name": "minio",
|
||||
@@ -30,7 +33,8 @@
|
||||
"args": ["server", "/data", "--console-address", ":9001"],
|
||||
"env-file": ["/var/lib/minio/root.env"],
|
||||
"ports": ["9000:9000"],
|
||||
"volumes": ["/services/minio/data/data1-1:/data"]},
|
||||
"volumes": ["/services/minio/data/data1-1:/data"],
|
||||
"restart-on": ["root-env"]},
|
||||
|
||||
{"id": "provisioner", "type": "container", "name": "mesh-provision-objectstore",
|
||||
"image": "mesh-provision-objectstore@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
||||
@@ -43,8 +47,8 @@
|
||||
},
|
||||
"volumes": [
|
||||
"/var/lib/minio/grants:/var/lib/minio/grants:ro",
|
||||
"/var/lib/minio/root.env:/run/secrets/root:ro"
|
||||
"/var/lib/minio/root.secret:/run/secrets/root:ro"
|
||||
],
|
||||
"restart-on": ["grants"]}
|
||||
"restart-on": ["grants", "root-env"]}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user