Found while checking whether the named volumes mesh-catalog #54/#55 replaced are actually unused before treating them as safe to remove — this repo has its own independent volumes declaration for the broker's TLS material, read directly rather than through lavinmq's own resource, and it still named the old mesh-broker-tls volume.
Content is identical right now (copied once during the conversion). If the cert ever rotates, lavinmq writes the new directory and this container would keep reading stale content from a volume nothing else updates.
Checked both mesh-controller and mesh-catalog for any other reference to the four converted volume names (mesh-store-data, mesh-broker-data, mesh-broker-tls, mesh-registry-data) — this was the only straggler.
Found while checking whether the named volumes `mesh-catalog` #54/#55 replaced are actually unused before treating them as safe to remove — this repo has its own independent `volumes` declaration for the broker's TLS material, read directly rather than through `lavinmq`'s own resource, and it still named the old `mesh-broker-tls` volume.
Content is identical right now (copied once during the conversion). If the cert ever rotates, `lavinmq` writes the new directory and this container would keep reading stale content from a volume nothing else updates.
Checked both `mesh-controller` and `mesh-catalog` for any other reference to the four converted volume names (`mesh-store-data`, `mesh-broker-data`, `mesh-broker-tls`, `mesh-registry-data`) — this was the only straggler.
Found checking whether the named volumes mesh-catalog PR #54/#55 replaced
are actually unused before considering them safe to remove -- this repo
has its own independent volumes declaration for the same TLS material
(mesh-controller reads it directly, not through lavinmq's own resource),
and it still named the old mesh-broker-tls volume.
Right now the content is identical -- copied once during the conversion.
If the cert ever rotates, lavinmq writes the new directory and this would
keep reading stale content from the volume nothing else updates.
Checked both repos for any other reference to the four converted volume
names (mesh-store-data, mesh-broker-data, mesh-broker-tls,
mesh-registry-data): this was the only one.
The swap from a named volume to the host directory left the mount undeclared, which main's own
manifest check now refuses: a bind the module did not declare is created by the runtime as root, so
the module's owner and mode never reach it and ADR 0030's data rule does not cover it.
The directory is the broker's — lavinmq declares it as its own, mode 0700 — so from here it is an
access, read-only: a pre-existing path this module is granted use of and does not own.
Reviewed with main merged in (28 commits had landed since this was cut), and the swap was incomplete as written — main's own manifest check refuses it:
mesh-controller mounts "/var/lib/mesh-broker-tls" into server, and nothing in mesh-controller declares it. A bind mount the module did not declare is created by the container runtime as root, so the module's own owner and mode do not reach the directory that holds its data, and the rule that keeps data when a module goes away (ADR 0030) does not cover it.
Two tests failed on it: TestTheControllersOwnManifestClaimsItsSeat and TestTheControlPlanesOwnAddressesFollowTheNodesPorts, both because the manifest no longer parses.
Fixed here by declaring it as an access, read-only, which is what it actually is: lavinmq declares that directory as its own (mode: 0700), so from the controller's side it is "a pre-existing path this module is granted use of and does not own" — not a directory resource, which would claim ownership of the broker's data. mode: "read" matches the mount's :ro.
go build ./... clean, go test ./...19 packages, exit 0, no failures.
The change itself is right and matches what already landed elsewhere — named volumes replaced by directory binds (hq issue 115: a named volume is invisible to the operator and one flag from gone), and the broker module already owns this path.
Reviewed with `main` merged in (28 commits had landed since this was cut), and the swap was incomplete as written — `main`'s own manifest check refuses it:
> mesh-controller mounts "/var/lib/mesh-broker-tls" into server, and nothing in mesh-controller declares it. A bind mount the module did not declare is created by the container runtime as root, so the module's own owner and mode do not reach the directory that holds its data, and the rule that keeps data when a module goes away (ADR 0030) does not cover it.
Two tests failed on it: `TestTheControllersOwnManifestClaimsItsSeat` and `TestTheControlPlanesOwnAddressesFollowTheNodesPorts`, both because the manifest no longer parses.
Fixed here by declaring it as an **access**, read-only, which is what it actually is: `lavinmq` declares that directory as its own (`mode: 0700`), so from the controller's side it is "a pre-existing path this module is granted use of and does not own" — not a directory resource, which would claim ownership of the broker's data. `mode: "read"` matches the mount's `:ro`.
`go build ./...` clean, `go test ./...` **19 packages, exit 0, no failures**.
The change itself is right and matches what already landed elsewhere — named volumes replaced by directory binds (hq issue 115: a named volume is invisible to the operator and one flag from gone), and the broker module already owns this path.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while checking whether the named volumes
mesh-catalog#54/#55 replaced are actually unused before treating them as safe to remove — this repo has its own independentvolumesdeclaration for the broker's TLS material, read directly rather than throughlavinmq's own resource, and it still named the oldmesh-broker-tlsvolume.Content is identical right now (copied once during the conversion). If the cert ever rotates,
lavinmqwrites the new directory and this container would keep reading stale content from a volume nothing else updates.Checked both
mesh-controllerandmesh-catalogfor any other reference to the four converted volume names (mesh-store-data,mesh-broker-data,mesh-broker-tls,mesh-registry-data) — this was the only straggler.Reviewed with
mainmerged in (28 commits had landed since this was cut), and the swap was incomplete as written —main's own manifest check refuses it:Two tests failed on it:
TestTheControllersOwnManifestClaimsItsSeatandTestTheControlPlanesOwnAddressesFollowTheNodesPorts, both because the manifest no longer parses.Fixed here by declaring it as an access, read-only, which is what it actually is:
lavinmqdeclares that directory as its own (mode: 0700), so from the controller's side it is "a pre-existing path this module is granted use of and does not own" — not a directory resource, which would claim ownership of the broker's data.mode: "read"matches the mount's:ro.go build ./...clean,go test ./...19 packages, exit 0, no failures.The change itself is right and matches what already landed elsewhere — named volumes replaced by directory binds (hq issue 115: a named volume is invisible to the operator and one flag from gone), and the broker module already owns this path.