The lab named both failures in one run: the store restarted forever on a conf file it could not read, and the forge could not traverse into the directory that held its files. Both are the same fault — a file the mesh declares root-owned, consumed by a container process that dropped to a uid the machine has never heard of. The forge's data now belongs to 1000, the user its container runs as. The store's conf, ACL file and data belong to 999, which is what redis becomes after its entrypoint drops privileges. The package registry's conf directory belongs to 10001, which writes htpasswd into it. Made expressible by the host in the commit beside this one: an owner may be numeric, because a container's user has no name on the machine.
109 lines
2.5 KiB
JSON
109 lines
2.5 KiB
JSON
{
|
|
"module": "redis",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "redis-cache",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"serves": {
|
|
"redis-cache": {}
|
|
},
|
|
"receives": {
|
|
"redis-cache": "/var/lib/redis-module/grants/mesh.json"
|
|
},
|
|
"grants": {
|
|
"redis-cache": "/var/lib/redis-module/grants"
|
|
},
|
|
"own-secrets": {
|
|
"default": "/var/lib/redis-module/default.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 6379,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a cache"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/redis-module",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "grants-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/redis-module/grants",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/services/redis/data",
|
|
"mode": "0700",
|
|
"owner": "999:999"
|
|
},
|
|
{
|
|
"id": "server-conf",
|
|
"type": "file",
|
|
"path": "/var/lib/redis-module/redis.conf",
|
|
"mode": "0600",
|
|
"content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n",
|
|
"owner": "999:999"
|
|
},
|
|
{
|
|
"id": "acl-seed",
|
|
"type": "file",
|
|
"path": "/services/redis/data/users.acl",
|
|
"mode": "0600",
|
|
"content": "",
|
|
"owner": "999:999"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "redis"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "redis",
|
|
"image": "redis@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf",
|
|
"network": "redis",
|
|
"ports": [
|
|
"6379"
|
|
],
|
|
"volumes": [
|
|
"/services/redis/data:/data",
|
|
"/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro"
|
|
],
|
|
"args": [
|
|
"/etc/redis/redis.conf"
|
|
]
|
|
},
|
|
{
|
|
"id": "provisioner",
|
|
"type": "container",
|
|
"name": "mesh-provision-redis",
|
|
"image": "mesh-provision-redis@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "redis",
|
|
"env": {
|
|
"GRANTS": "/var/lib/redis-module/grants",
|
|
"MESH_PROVISION_REDIS": "redis:6379",
|
|
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
|
|
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
|
|
]
|
|
}
|
|
]
|
|
}
|