The two-node bed's copies declare the secrets they take through the environment, as the catalogue does (ADR 0086)

This commit is contained in:
2026-09-22 13:30:01 +02:00
parent 3f71b91fb8
commit 3ce66e8369
@@ -232,6 +232,8 @@ test("consumers on a joined node get their databases from the one foundation sto
{
id: "server", type: "container", name: "baserow", image: pinned("baserow/baserow"), network: "baserow",
"env-file": ["/var/lib/baserow/server.env"],
// Declared as the catalogue declares it (novox/hq ADR 0086, issue 041).
"secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible",
volumes: ["/services/baserow/data:/baserow/data"],
},
{ id: "runtime-config", type: "file", path: "/var/lib/mesh/baserow/config.json", mode: "0600", content: "{}\n", merge: "json" },
@@ -276,6 +278,8 @@ test("consumers on a joined node get their databases from the one foundation sto
{
id: "server", type: "container", name: "letta", image: pinned("letta/letta"), network: "letta",
"env-file": ["/var/lib/letta/server.env"],
// Declared as the catalogue declares it (novox/hq ADR 0086, issue 041).
"secrets-in-environment": "the letta image is env-driven and its file-source support could not be verified; the mesh runtime can take its password from config.json (client.ts) \u2014 not yet converted",
},
{ id: "runtime-config", type: "file", path: "/var/lib/mesh/letta/config.json", mode: "0600", content: "{}\n", merge: "json" },
{ id: "runtime-env", type: "file", path: "/var/lib/letta/runtime.env", mode: "0600", content: "MESH_LETTA_PASSWORD=${secret:server-password}\n" },
@@ -292,6 +296,8 @@ test("consumers on a joined node get their databases from the one foundation sto
MESH_LETTA_CONFIG_FILE: "/run/config/config.json",
},
"env-file": ["/var/lib/letta/runtime.env"],
// Declared as the catalogue declares it (novox/hq ADR 0086, issue 041).
"secrets-in-environment": "the letta image is env-driven and its file-source support could not be verified; the mesh runtime can take its password from config.json (client.ts) \u2014 not yet converted",
"restart-on": ["runtime-config"],
},
],