From caf97467597abc33e71f3247fd38f11b7d18f6b6 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:19:48 +0200 Subject: [PATCH 1/2] mesh-controller: mount the broker TLS directory bind, not the old named volume Found checking whether the named volumes mesh-catalog PR #54/#55 replaced are actually unused before considering them safe to remove -- this repo has its own independent volumes declaration for the same TLS material (mesh-controller reads it directly, not through lavinmq's own resource), and it still named the old mesh-broker-tls volume. Right now the content is identical -- copied once during the conversion. If the cert ever rotates, lavinmq writes the new directory and this would keep reading stale content from the volume nothing else updates. Checked both repos for any other reference to the four converted volume names (mesh-store-data, mesh-broker-data, mesh-broker-tls, mesh-registry-data): this was the only one. --- module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/module.json b/module.json index 936ca87..f46b1d1 100644 --- a/module.json +++ b/module.json @@ -51,7 +51,7 @@ "MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}" }, "volumes": [ - "mesh-broker-tls:/broker-tls:ro", + "/var/lib/mesh-broker-tls:/broker-tls:ro", "/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro", "/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro", "/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro", -- 2.54.0 From 71c8080359a712c545438c494dc332bf66576bb9 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 26 Sep 2026 14:55:04 +0200 Subject: [PATCH 2/2] Declare the broker's TLS directory as an access, not an undeclared bind MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The swap from a named volume to the host directory left the mount undeclared, which main's own manifest check now refuses: a bind the module did not declare is created by the runtime as root, so the module's owner and mode never reach it and ADR 0030's data rule does not cover it. The directory is the broker's — lavinmq declares it as its own, mode 0700 — so from here it is an access, read-only: a pre-existing path this module is granted use of and does not own. --- module.json | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/module.json b/module.json index f46b1d1..1694a31 100644 --- a/module.json +++ b/module.json @@ -11,6 +11,12 @@ "scope": "mesh" } ], + "accesses": [ + { + "path": "/var/lib/mesh-broker-tls", + "mode": "read" + } + ], "own-secrets": { "inventory": "/var/lib/mesh/mesh-controller/inventory", "identity": "/var/lib/mesh/mesh-controller/identity", -- 2.54.0