The lab's diagnostics said it in one line: AUTH called without any password configured for the default user. With an aclfile configured, redis takes the default user from the file and quietly ignores requirepass — so the empty seed this module shipped left the store without any password at all, politely refusing the credential the mesh had sealed for it. And the file could never have worked here anyway: it was host-declared content, which the host reconciles, so every re-apply would have wiped what ACL SAVE wrote — a fight between two reconcilers with the tenants as the ball. So no file. requirepass alone does what it says, and durability moves to the watch, which now checks the store and not only its inputs: a restarted store comes back empty and is re-granted within a tick, because reconciling is against reality, not against a diff of instructions. A run that failed leaves last empty, so the next tick retries instead of believing the inputs were handled.
101 lines
2.3 KiB
JSON
101 lines
2.3 KiB
JSON
{
|
|
"module": "redis",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "redis-cache",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"serves": {
|
|
"redis-cache": {}
|
|
},
|
|
"receives": {
|
|
"redis-cache": "/var/lib/redis-module/grants/mesh.json"
|
|
},
|
|
"grants": {
|
|
"redis-cache": "/var/lib/redis-module/grants"
|
|
},
|
|
"own-secrets": {
|
|
"default": "/var/lib/redis-module/default.secret"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 6379,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "modules on any machine that were granted a cache"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/redis-module",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "grants-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/redis-module/grants",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "data",
|
|
"type": "directory",
|
|
"path": "/services/redis/data",
|
|
"mode": "0700",
|
|
"owner": "999:999"
|
|
},
|
|
{
|
|
"id": "server-conf",
|
|
"type": "file",
|
|
"path": "/var/lib/redis-module/redis.conf",
|
|
"mode": "0600",
|
|
"content": "requirepass ${secret:default}\nappendonly yes\ndir /data\n",
|
|
"owner": "999:999"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "redis"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "redis",
|
|
"image": "redis@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf",
|
|
"network": "redis",
|
|
"ports": [
|
|
"6379"
|
|
],
|
|
"volumes": [
|
|
"/services/redis/data:/data",
|
|
"/var/lib/redis-module/redis.conf:/etc/redis/redis.conf:ro"
|
|
],
|
|
"args": [
|
|
"/etc/redis/redis.conf"
|
|
]
|
|
},
|
|
{
|
|
"id": "provisioner",
|
|
"type": "container",
|
|
"name": "mesh-provision-redis",
|
|
"image": "mesh-provision-redis@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "redis",
|
|
"env": {
|
|
"GRANTS": "/var/lib/redis-module/grants",
|
|
"MESH_PROVISION_REDIS": "redis:6379",
|
|
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/default"
|
|
},
|
|
"volumes": [
|
|
"/var/lib/redis-module/grants:/var/lib/redis-module/grants:ro",
|
|
"/var/lib/redis-module/default.secret:/run/secrets/default:ro"
|
|
]
|
|
}
|
|
]
|
|
}
|