The lab named both failures in one run: the store restarted forever on a conf file it could not read, and the forge could not traverse into the directory that held its files. Both are the same fault — a file the mesh declares root-owned, consumed by a container process that dropped to a uid the machine has never heard of. The forge's data now belongs to 1000, the user its container runs as. The store's conf, ACL file and data belong to 999, which is what redis becomes after its entrypoint drops privileges. The package registry's conf directory belongs to 10001, which writes htpasswd into it. Made expressible by the host in the commit beside this one: an owner may be numeric, because a container's user has no name on the machine.
examples
Things that run, kept here because a contract is easier to read as working code than as prose.
Nothing here is part of the control plane. The control plane decides and never touches a machine (README); everything in this directory runs on a machine and touches it. These are reference implementations of contracts the control plane defines, and a real one ships with the module that ships the software it configures.
postgres-provisioner |
the last step of a credential: reads what the mesh delivered and makes PostgreSQL accept it |
Running the provisioner
--watch reconciles now and again whenever what the mesh delivered changes. That is what lets it
be a module: an ordinary long-running service the host supervises, rather than something that has
to be invoked after every declaration by a timer or a unit wired to a file.
It polls rather than watching the filesystem, because the host writes atomically — the file is replaced, so a watch on the path stops seeing anything after the first replacement. A watcher that silently stops working is worse than a poll.
Credentials are compared by digest and never by content. This runs for as long as the machine is up, and a secret does not belong in a long-lived variable when a hash answers the same question.